/ai-search763 words

Shopify Lets Browser Agents Complete Checkout Orders via WebMCP

Shopify extended WebMCP into checkout on Sept. 28, letting browser agents place orders once buyers confirm. Internal tests show 60/60 success vs. 56/60 for browser automation.

Shopify Extends WebMCP Into Checkout For Browser Agents via @sejournal, @MattGSouthern
Shopify Extends WebMCP Into Checkout For Browser Agents via @sejournal, @MattGSouthernAI-generated
  • Shopify expanded WebMCP into checkout on Sept. 28; agents can complete orders after buyer confirmation, with no merchant configuration required.
  • In Shopify's internal test on GPT-6 Sol, WebMCP succeeded in 60/60 checkout attempts versus 56/60 for browser automation, averaging 10.3 seconds per attempt versus 27.4 seconds, at 58% lower cost per attempt.
  • Coverage limits: standard three-page checkout gets tools only with Shop Pay; B2B, embedded, and mobile SDK checkouts are excluded; agents must sign requests with Web Bot Auth and cannot enter new card details.

Shopipfy expanded its WebMCP tools into checkout on Sept. 28, moving browser agents from guiding shoppers to the checkout page to actually placing the order once the buyer confirms it. The rollout requires no merchant action: Shopify's developer changelog states the tools "don't expose a new API or require merchant configuration."

When Shopify first rolled out WebMCP storefront tools in August, agents could search products and manage carts but had to hand off at checkout. That boundary is gone on eligible checkouts.

Four tools registered at checkout

According to Shopify's Checkout WebMCP docs, eligible checkouts register four tools:

  • get_checkout reads the checkout and, after purchase, the order details.
  • update_checkout changes contact details, shipping or pickup, discount codes, payment, and extra fields such as a tax number.
  • complete_checkout places the order.
  • navigate_to_storefront returns the tab to the store.

The tools share state with the checkout page the shopper sees. Checkout runs its own validation on every update, and agents cannot change the items in the order.

Payment handling stays deliberately narrow. The tools do not accept new card details. An agent can select a saved card from Shop Pay or, where guest checkout allows, use a Shop Pay approval the agent holds on file. Any other payment option remains the buyer's to choose on the checkout page.

Agents must sign their browser requests with Web Bot Auth, which Shopify uses to recognize them. Unsigned requests risk deprioritization or blocking by bot detection systems.

Where the buyer takes over

Shopify's documentation instructs agents to show the buyer the current order and total before calling complete_checkout and to "get their permission to place it." A Web Bot Auth signature, a Shop Pay approval, or a ready-to-complete status does not count as that consent.

Shop Pay login and payment challenges such as 3D Secure return control to the buyer on the page, along with blocking UI extensions and review steps. The buyer also handles interactions with app-defined checkout extensions.

Coverage gaps

Not every checkout gets the tools. Shopify's standard three-page checkout registers no WebMCP tools unless the buyer checks out with Shop Pay. B2B checkout, embedded checkout, and checkouts inside mobile checkout SDKs are excluded, as are cross-shop merchandise, draft orders, order edits, and payment collection. For now, agents can use WebMCP only in Chromium-based browsers.

Two routes: WebMCP versus Checkout MCP

Shopify documents two agent paths to checkout and recommends the server-based Checkout MCP, where an agent manages a checkout session from its own server. Checkout WebMCP applies "only when your agent is already operating in the buyer's browser," the company says.

Both options rely on the checkout capability of the Universal Commerce Protocol and use the same checkout object. In every case, Shopify says, the merchant remains the merchant of record.

Shopify's benchmark: WebMCP beats browser automation

Gil Greenberg, part of Shopify's agentic commerce team, shared results from an internal test comparing WebMCP against browser automation, where an agent reads the page and clicks through it. Both methods ran on GPT-6 Sol "with the same prompts and starting conditions."

Across ten checkout tasks in two test shops, WebMCP succeeded in all 60 attempts; browser automation succeeded in 56 of 60. Excluding page setup time, each attempt took 10.3 seconds with WebMCP versus 27.4 seconds with browser automation, and WebMCP's cost per attempt was 58% lower at OpenAI's list prices. One figure in Greenberg's post totals the test in a way that doesn't align with the 60 attempts listed per method.

These results come from Shopify's test shops and a single model — tool-signal data, not a platform-wide statement. The changelog and checkout documentation include no real-world data, such as agent-placed order volumes or conversion rates.

What it means for merchants

A merchant's checkout configuration now determines when a browser agent can complete an order. Three-page checkout exposes tools only through Shop Pay. Blocking UI extensions let buyers regain control, and payments outside a saved Shop Pay card or approval process directly on the page.

As of publication, Shopify's docs don't say whether merchants can disable individual tools or separate agent-placed orders in their reporting. Watch the developer changelog for either. Also unclear: which agents actually call the checkout tools. ChatGPT's desktop browser added WebMCP site tools in August, but OpenAI's help page for those tools doesn't mention Shopify's checkout tools — a gap worth monitoring as agentic checkout adoption develops.

via shopify.dev (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Senior reporter covering consumer brands and retail at SERP Journal.

41 articles