Shopify opened checkout to browser agents. What WebMCP means for every other store
Since 28 September 2026, an AI agent in the shopper's browser can read, fill in and submit a Shopify checkout through WebMCP tools, with the buyer's confirmation. What changed, what still needs a human, and what stores on other platforms can do now.
On 28 September 2026, Shopify added WebMCP tools to its checkout. An AI agent running in the shopper's own browser can now read the checkout, fill in the address and delivery option, and place the order once the buyer has confirmed it. Until then, agents on Shopify stores could search the catalogue and build a cart through WebMCP, but the last step still meant pressing buttons on a page built for people.
The same month showed the other approach. According to Bloomberg, Amazon began blocking Meta's new Muse agent from its site on 20 September, after Meta declined to remove it; Amazon said the agent did not identify itself while browsing. One company blocks agents at the door, the other gives them a dedicated entrance. For a store owner, the useful question is what that entrance looks like and whether your store has one.
What WebMCP is, in one paragraph
WebMCP is a draft specification from the W3C Web Machine Learning Community Group (a community group draft, not a W3C standard) that lets a page register "tools" with the browser. Instead of reading the screen and guessing which button means "add to cart", an agent calls a tool such as update_cart with structured inputs and gets a structured answer back. Chrome describes it as a progressive enhancement: the page works for people exactly as before, and agents get a cleaner path on top. Chrome opened an origin trial in version 149 (announced 9 June 2026), and the draft's implementation tracker lists an origin trial in Edge 150 and support in ChatGPT Desktop. Firefox and Safari have not announced support.
There are two ways to add tools. The imperative API registers them in JavaScript through document.modelContext.registerTool(). The declarative API turns an ordinary HTML form into a tool with a few attributes: toolname and tooldescription on the form, toolparamdescription on each field.
What Shopify actually shipped
Shopify rolled this out in two steps, and in both cases the changelog says merchants have nothing to install or configure.
Storefront and cart (5 August 2026). Every Liquid storefront and the Hydrogen developer preview now exposes WebMCP tools: search_catalog, browse_store, get_product and show_variant for the catalogue; get_cart, update_cart and cancel_cart for the cart; proceed_to_checkout and manage_orders; and search_shop_policies_and_faqs for policy and FAQ content.
Checkout (28 September 2026). Four tools appear on eligible checkouts:
get_checkoutreads the current checkout, its messages and, after purchase, the order receipt.update_checkoutreplaces contact details, delivery, discount codes and payment selection. It does not change items; the buyer does that on the page.complete_checkoutplaces the order, or opens a review step if the store has one.navigate_to_storefrontleaves checkout without placing an order.
The tools run inside the same checkout the buyer sees and share its state. In practice, that means a tool call and a click lead to the same result.
What still needs a human
Shopify's developer documentation is unusually explicit about the limits, and they are worth knowing because they show where the industry is drawing the line:
- The buyer confirms the order. Before calling
complete_checkout, the agent must show the buyer the current order and total and get permission, and ask again if the total changes. Shopify notes that a technical "ready" status does not count as consent. - Payment challenges stay with the buyer. 3D Secure, Shop Pay login and similar steps are completed by the person on the page; the agent waits and re-reads the checkout.
- No new card numbers. The tools do not accept card details. The buyer picks or enters payment methods on the page.
- Only "completed" means completed. An order exists only when the checkout status says so, which matters for anyone measuring agent conversions.
- Tool output is data, not instructions. Shopify tells agent builders to treat merchant and third-party text in tool responses as checkout data. That is a defence against prompt injection through product descriptions or notes.
- Signed agents get better treatment. Agents are expected to sign requests with Web Bot Auth and register their keys with Shopify; without that, Shopify says bot detection might deprioritise or block them.
The pattern is the same one the card networks and Cloudflare have been building towards: let identified agents do the routine work, keep the human on consent and payment.
Why this matters beyond Shopify
Most agent traffic a store sees comes from agents inside the shopper's browser: Comet, Claude in Chrome, Gemini in Chrome and similar tools. These agents carry the shopper's own session and usually cannot be told apart from a person. Until now, their only option on any store was to read the page and click. That works on some sites and fails on others, depending on how the page is built: a hidden checkout button, an unlabeled form field or a price that only appears after JavaScript runs can stop an agent cold.
WebMCP gives those agents a second path that does not depend on the layout. On a Shopify store, an agent that supports it no longer has to guess. On a store without tools, it still has to read and click. If agents keep moving in this direction, stores that expose tools will be easier for them to finish a purchase on, and that is likely to show up in which stores they recommend and complete orders with.
It is early. The origin trial is time-limited, browser support is effectively Chromium-only, and the specification is still a draft that has already changed its API shape. None of this replaces a page that works well for people and for agents that read the screen.
What to do now, depending on your platform
If you are on Shopify: there is no switch to flip, but there are things to check.
- Make sure your policy pages and FAQ actually answer the questions an agent will ask: delivery times, return windows, costs.
search_shop_policies_and_faqscan only return what you have written. - Check what your theme does when the cart changes. Shopify notes that agent cart updates trigger the same theme behaviour as a click, so a cart drawer will open for agents too.
- Review your bot protection and any checkout apps or extensions that block the page. Shopify says blocking UI extensions hand control back to the buyer, which is safe but slower.
- Keep product data consistent across the product page, feed and structured data. Tools return what is in your store; they do not fix it.
If you are on WooCommerce: some community plugins already add WebMCP tools to WordPress and WooCommerce. They are third-party and experimental, like the draft itself, so test them on staging before putting them in front of checkout.
If you are on ikas, Ticimax, IdeaSoft, T-Soft or another hosted platform: as of this writing we have not found public WebMCP announcements from these platforms. Because hosted checkouts are controlled by the platform, this is a question to put to your provider's roadmap rather than something to build yourself. In the meantime, the declarative API is the lowest-effort experiment for pages you do control, such as a store search or a stock-check form, but only if your platform lets you add an origin-trial token and edit form markup.
On any platform: the screen-reading path is not going away. Clear form labels, a visible and reachable checkout button, guest checkout, and prices and stock that appear without waiting on scripts still decide whether most agents get through today.
The bottom line
Shopify has made agent checkout a structured, consent-based step instead of a sequence of guessed clicks, and it did it for every eligible store at once. Other platforms will have to answer the same question. Until they do, the store that works for an agent reading the page is the store that keeps the sale.
Specoria's agent simulation sends Claude, GPT and Gemini model families through real shopping tasks in a real browser and shows step by step where they stop, whether or not your store exposes tools. Start with a free readiness test.
Sources
- Shopify Developer Changelog, WebMCP support for checkout, September 28, 2026.
- Shopify Developer Changelog, WebMCP support for Liquid and Hydrogen storefronts, August 5, 2026.
- Shopify Developer Docs, Checkout WebMCP.
- Shopify Developer Docs, WebMCP tools.
- TechCrunch, Shopify opens checkout to browser-based AI agents, September 28, 2026.
- Chrome for Developers, Join the WebMCP origin trial, June 9, 2026.
- Chrome for Developers, WebMCP.
- W3C Web Machine Learning Community Group, WebMCP explainer, Declarative API explainer and Implementation status.
- Bloomberg via The Star, Amazon blocks Meta's Muse AI agent from its retail site, September 22, 2026.