NEWS · SEPTEMBER 28, 2026 · E-COMMERCE

Shopify opens checkout to AI agents in the browser through WebMCP tools

On September 28, 2026 Shopify announced that AI agents working inside a shopper's browser can now see and edit a Shopify checkout through WebMCP tools and place the order after the shopper approves it. The tools operate on the checkout session already open in that browser, and Shopify says merchants get no new API to integrate and nothing to configure.

01 · WHAT HAPPENED?

After the storefront and the cart, the checkout

Shopify's developer changelog, in an entry dated September 28, 2026, says agents running in the browser can now work with the checkout itself, acting on the session the shopper already has open. With the storefront and cart tools already live, Shopify says an agent can now help from the first product search all the way to a confirmed order. In a follow-up report published on September 29, Search Engine Journal (SEJ) recalls how far the August release went: agents could find products, fill the cart and bring the shopper to the checkout page, but the order itself stayed with the shopper.

Four tools are available at checkout. get_checkout reports where the checkout stands, any messages on it and, once the purchase is done, the order details; update_checkout edits the fields the checkout supports; complete_checkout places the order after the buyer says yes; and navigate_to_storefront takes the agent back to the store. The tools live inside checkout-web and draw on the same state that the checkout interface uses. In the changelog's words, "They don't expose a new API or require merchant configuration." TechCrunch reports that Gil Greenberg, a staff product manager working on agentic commerce at Shopify, announced in a September 28 post on X that checkout support, Shop Pay included, was launching for every eligible Shopify merchant. His post opened with the line "Shopping with an agent shouldn’t feel like watching paint dry."

02 · DETAILS

The agent fills in the form, the buyer approves the order

According to Shopify's Checkout WebMCP documentation, update_checkout can swap out the buyer's contact details, the shipping or pickup choice, discount codes, declared fields and payment. It ignores line items and attribution, so only the shopper can change what is in the order, directly on the page. The changelog adds that the shopper takes over whenever their own input is needed, for example a 3D Secure check, and also when a blocking UI extension appears. Before complete_checkout is called, the agent must first walk the buyer through the latest order and total and get a clear yes. SEJ stresses that neither a Web Bot Auth signature on the agent's traffic, an existing Shop Pay approval nor a ready-to-complete checkout status counts as that yes. SEJ also reports that the tools will not take a new card number: an agent can choose a card already saved in Shop Pay or, if the store allows guest checkout, rely on a Shop Pay approval it holds, while every other payment method is left for the shopper to pick on the page.

Coverage is narrow. On Shopify's classic three-page checkout, SEJ reports, the tools show up only for shoppers paying with Shop Pay. B2B checkouts, embedded checkouts and checkouts running inside mobile SDKs are left out, and so are draft orders, order edits, payment collection and any checkout carrying goods from a different shop. SEJ, pointing to Shopify's storefront docs, says Chromium browsers are the only ones supported for the moment. The docs add two more rules. An agent is expected to sign the requests it makes from the browser with Web Bot Auth (WBA); unsigned traffic may be pushed down or stopped by bot detection. And any merchant or third-party text that comes back in a tool response is to be handled as checkout data, never as instructions, because it may hide prompt-injection attempts.

03 · WHY IT MATTERS

Calling structured tools instead of reading the page

Shopify describes two routes to checkout, and the docs put the split plainly: "Use Checkout WebMCP when your agent runs in the buyer's browser." An agent that can work from a server is sent to Checkout MCP instead, which SEJ notes is the route Shopify recommends. Both build on the checkout capability defined by the Universal Commerce Protocol (UCP) and work with one shared checkout object, and according to SEJ, Shopify says the merchant remains the merchant of record on either route. The only performance figures come from an internal test that Greenberg shared and SEJ summarized. Shopify ran ten checkout tasks in two test stores: WebMCP got through all 60 attempts, while browser automation, where the agent reads the page and clicks its way through, managed 56. Leaving out page setup, an attempt took 10.3 seconds with WebMCP and 27.4 seconds with automation, and cost 58 percent less at OpenAI's list prices. GPT-6 Sol powered both methods. SEJ cautions that the figures reflect Shopify's own test stores and one model, and that one line of the post gives a total that does not square with the 60 attempts per method.

The timing stands out too. TechCrunch notes that some retailers, Amazon among them and apparently Adidas as well, are blocking AI agents from buying on users' behalf, while Shopify is moving the other way. The same report says both Muse and Instinct have their own direct agentic commerce partnerships with Shopify, with the Instinct deal announced on September 28. PYMNTS notes that a week before this launch, Shopify CEO Tobias Lütke had announced a tie-up with Meta that lets Meta's Muse agent buy from Shopify stores using Shop Pay, a partnership we covered on September 22. The practical takeaway, as SEJ frames it, is that the way a store configures its checkout determines the point at which an agent gives the order back to the shopper.

04 · TÜRKİYE

The sources say nothing about Türkiye, so this section is commentary

None of the five sources mentions Türkiye. The group Greenberg calls all eligible merchants is not defined by country or region anywhere in the sources; eligibility is described only through which checkout types are excluded. What follows is therefore not drawn from the sources but is explicitly UNALSOFT commentary.

The unknowns are these. It is unclear whether Shopify stores in Türkiye count as eligible merchants, and the sources give no fee or commission figure for merchants or agents. SEJ found nothing in the docs, at the time it published, on whether a merchant can turn off single tools or tell agent orders apart in its reports, and it notes that the changelog and docs offer no real-world figures such as agent order volumes or conversion rates. Our reading: for a business selling on Shopify from Türkiye, the practical question today is at which step the checkout hands control back to the buyer. Where Shop Pay sits in the flow, and which blocking extensions are in place, will decide where an agent stops.

The UNALSOFT view

We read this as a sales channel story. TechCrunch reports that agents can now work with the checkout screen directly instead of leaning on screenshots or page scraping, which makes the clarity of contact, delivery, discount and payment steps matter directly. The lesson applies beyond Shopify: order and payment data that machines can read may soon become a channel question in its own right. That is why in our e-commerce panel work we treat clear, consistent product, delivery and payment fields as a step of their own. Because the sources carry no data about Türkiye, this article draws no conclusion about local availability.

How open is your checkout to an AI agent?

A short conversation is enough to move your product, delivery and payment steps into a structure that both people and machines can read.

Message on WhatsApp