MH-3541SEO & Search
Shopify Opens Checkout to Browser Agents With WebMCP
Shopify's WebMCP tools now let browser agents complete orders on eligible checkouts once buyers confirm — no merchant setup required, the company's changelog says.
Wire notes
- Shopify expanded WebMCP into checkout on Sept. 28, enabling browser agents to update checkout details and place orders after buyer confirmation, with no new API or merchant configuration.
- In Shopify's test using GPT-6 Sol, WebMCP completed 60 of 60 checkout attempts at 10.3 seconds each, versus 56 of 60 at 27.4 seconds for browser automation, with 58% lower cost per attempt.
- WebMCP checkout tools are excluded from B2B, embedded and mobile SDK checkouts, and Shopify's standard three-page checkout gets them only when buyers use Shop Pay.

Shopify expanded its WebMCP tools into checkout on Sept. 28, letting browser agents read and update the checkout open in a shopper's tab and submit the order once the buyer confirms it.
The move extends the storefront tools Shopify rolled out in August, which allowed agents to search for products and manage the cart, then guide shoppers to checkout without placing the order. The new checkout tools use the same state as the checkout page the shopper sees. Shopify's developer changelog says they "don't expose a new API or require merchant configuration."
What Agents Can Do at Checkout
Eligible Shopify checkouts now register four WebMCP tools, according to the company's Checkout WebMCP docs:
- get_checkout reads the checkout and, after purchase, the order details.
- update_checkout changes contact details, shipping or pickup, discount codes, payment, and extra fields such as a tax number.
- complete_checkout places the order.
- navigate_to_storefront returns the tab to the store.
Checkout runs its own validation on each update, and agents can't change the items in the order.
The tools don't accept new card details. An agent can select a saved card from Shop Pay or, if guest checkout allows, use a Shop Pay approval the agent has on file. Any other payment options stay with the buyer on the checkout page.
Agents must sign their browser requests using Web Bot Auth, which Shopify relies on to recognize agents. Without it, their requests might be deprioritized or blocked by bot detection systems.
Where the Buyer Takes Over
Shopify's documentation tells agents to display the current order and total to the buyer before calling complete_checkout, and to "get their permission to place it." A Web Bot Auth signature, a Shop Pay approval, or a ready-to-complete status does not qualify as that consent.
Shop Pay login and payment challenges, like 3D Secure, return control to the buyer on the page, along with blocking UI extensions and review steps. The buyer also manages interactions with app-defined checkout extensions.
Which Checkouts Get the Tools
Shopify's standard three-page checkout gets no WebMCP tools unless the buyer checks out with Shop Pay. B2B checkout, embedded checkout, and checkouts inside mobile checkout SDKs are excluded. Checkouts with merchandise from another shop, draft orders, order edits, and payment collection are excluded too.
For now, Shopify's storefront docs say agents can use WebMCP only in Chromium-based browsers.
Checkout WebMCP Versus Checkout MCP
Shopify documents two routes for agents at checkout and recommends the server-based one, Checkout MCP, where an agent manages a checkout session from its own server. Shopify says to use Checkout WebMCP "only when your agent is already operating in the buyer's browser."
Both options rely on the checkout capability of the Universal Commerce Protocol and use the same checkout object. Checkout WebMCP operates through tools the checkout page registers in the buyer's browser; Checkout MCP handles requests on the server side. In both cases, Shopify says, the merchant stays the merchant of record.
Shopify's Test Against Browser Automation
Gil Greenberg, part of the team at Shopify working on agentic commerce, shared results of a company test comparing WebMCP with browser automation, where an agent reads the page and clicks through it. Both methods ran on GPT-6 Sol "with the same prompts and starting conditions."
Across ten checkout tasks in two test shops, WebMCP succeeded in all 60 attempts, while browser automation succeeded in 56 out of 60. Excluding page setup time, the time per attempt was 10.3 seconds with WebMCP versus 27.4 seconds with browser automation. WebMCP's cost per attempt was 58% lower at OpenAI's list prices. One line in Greenberg's post, however, states a total for the test that doesn't align with the 60 attempts listed per method.
The results come from Shopify's test shops and a single model. The changelog and checkout documentation don't include real-world data, such as orders made by agents or conversion rates.
Why This Matters
In August, Shopify limited its browser tools to getting shoppers to the checkout page. Now an agent can complete the order on eligible checkouts once the buyer confirms, with no need for the merchant to enable anything.
A merchant's checkout setup controls when a browser agent returns the order to the shopper. With a three-page checkout, tools are available only when the buyer uses Shop Pay. Blocking UI extensions let the buyer regain control, and payments outside a saved Shop Pay card or approval are processed directly on the page.
What's Still Open
As of publication, Shopify's storefront and checkout WebMCP docs don't say whether merchants can switch off individual tools or separate agent-placed orders in their reports. Shopify's WebMCP docs also don't name which agents call the checkout tools; ChatGPT's desktop browser added WebMCP site tools in August, but OpenAI's help page for those tools doesn't mention Shopify's checkout tools. Watch Shopify's developer changelog for both.
via shopify.dev (Original)
More from Tom Whitfield
Show full bio
Staff writer covering consumer brands and retail at Marketing Herald.
67 articles
More on the wire
- Google UCP Update Lets Merchants Enable Cart Transfer to Site
- Walmart Expands Scintilla With Marketplace Data and Deeper AI
- Walmart Adds Marketplace Data, Deeper AI to Scintilla Platform
- Amazon Blocks Meta's Muse With Terms of Service, Not Robots.txt
- Agentic Commerce Isn't Voice Shopping 2.0, But It Remains Unproven