Browser agents can now complete Shopify checkouts via four new WebMCP tools

On September 28, 2026, Shopify expanded its WebMCP agent tools to cover checkout itself: browser-based AI agents can now read, update, and complete checkouts — but only after the buyer has confirmed the order, and only if the agent signs…

Illustration: A small brass checkout key rests on an empty shop counter, separated from the viewer by a panel of frosted glass – evoking AI agents that can now complete purchases, but only behind a confirmation barrier.
Illustration
Gift article

Browser agents can now complete Shopify checkouts via four new WebMCP tools

On September 28, 2026, Shopify expanded its WebMCP agent tools to cover checkout itself: browser-based AI agents can now read, update, and complete checkouts — but only after the buyer has confirmed the order, and only if the agent signs its requests with registered keys.

Shopify announced the change in a developer changelog entry dated September 28, 2026 on its changelog index, according to a review by Unite.AI ([sourceId 3ff589d3]). The change means that AI agents operating in a browser no longer have to stop at the storefront: they can work directly in checkout on the same terms as any other shopper — reading state, editing fields, and placing the order. But the tools come with strict rules for consent and identification, and they have clear limits: no new card details and no way to abandon a checkout.

Four tools at checkout

According to the changelog entry, the announcement lists four tools agents can call at checkout ([sourceId 3ff589d3]):

  • get_checkout – reads the checkout's state, messages, and order details after completion.
  • update_checkout – updates supported fields in the checkout.
  • complete_checkout – submits the checkout, but only after the buyer has confirmed.
  • navigate_to_storefront – sends the tab back to the storefront.

The tools run inside checkout-web, Shopify's checkout application in the browser. That means store owners don't need any new API or configuration to allow agent traffic — according to the documentation, everything goes through the same interface as before.

Layer on layer: UCP over WebMCP

Technically, Checkout WebMCP implements the UCP checkout capability (dev.ucp.shopping.checkout) over browser-registered WebMCP tools, rather than over server-side JSON-RPC. According to the documentation, it shares the checkout object, statuses, and messages with Checkout MCP, Shopify's server-side counterpart ([sourceId 3ff589d3]). That means an agent working in the browser and an agent talking to Shopify's API can see the same checkout state.

The rules: keys, consent, and injection risk

Shopify sets three requirements for agents that want to use the tools.

Web Bot Auth with registered Ed25519 keys. Agents must sign their browser requests with Web Bot Auth, not with tool arguments. Shopify only verifies registered keys: registration requires the agent developer to generate an Ed25519 signing key, host the public key in a key directory, and publish that directory to Shopify. Without Web Bot Auth, Shopify's bot detection can deprioritize or block an agent's requests ([sourceId 3ff589d3]).

Explicit buyer consent. The documentation instructs the agent to obtain the buyer's permission before the order is placed: "Before calling complete_checkout, show the buyer the current order and total, and obtain their permission to place it," it states. The documentation specifies that neither Web Bot Auth, a Shop Pay approval, nor a ready_for_complete status counts as that permission — and that the agent must ask again if the total changes ([sourceId 3ff589d3]). It is a notable distinction: technically successful authentication is not the same as the buyer consenting.

Prompt injection warning. The documentation cautions agents to treat commerce and third-party text in tool responses as checkout data, not as instructions, because such text can contain prompt injection attempts. Agents are also told never to bypass the tools by operating the page controls themselves ([sourceId 3ff589d3]). That is an indication that Shopify sees manipulation attempts through checkout text as a real risk in agent flows.

The limits in the design

The documentation also sets two clear constraints: Checkout WebMCP does not accept new card details, and there is no cancel_checkout counterpart — the checkout status is never cancelled ([sourceId 3ff589d3]). That means the agent in practice cannot introduce new payment methods or clean up a checkout it has started.

In addition, the documentation points to a browser-specific challenge: Chrome 153 rejects object arguments in executeTool, but Chrome plans to accept objects from Chrome 155 ([sourceId 3ff589d3]). That means agent developers testing against older Chrome versions may find that tool calls don't work as expected.

The context: the Muse partnership and "exact economics"

The WebMCP news comes just days after Shopify on September 22 went the opposite way of Amazon and accepted Meta's Muse agent. CEO Tobi Lütke said that Monday that the company is "partnering deeply with Muse to enable agentic checkout with Shop Pay on all Shopify stores," after Amazon had blocked Muse the day before ([sourceId 97ad7b83]).

President Harley Finkelstein said at the company's August earnings call that "[a]gentic transactions carry the exact economics as an online store transaction" ([sourceId 97ad7b83]). That, then, is Shopify's own characterization of what agent transactions mean economically — the same revenue model as ordinary online store sales.

The connection between the Muse partnership and the September 28 WebMCP expansion is nonetheless not confirmed in the sources. The two stories point in the same direction — Shopify wants agent traffic into checkout — but that is an analytical interpretation, not something the documentation itself says.

What remains unclear

Several important details are missing from the available material. It does not say whether the WebMCP checkout tools are generally available or in developer preview, nor what "qualified checkouts" concretely means or how the rollout will proceed. Moreover, the details above are based on a review by Unite.AI — a description of Shopify's changelog and Checkout WebMCP documentation, not the sources themselves — and those articles are partially truncated. The details should therefore be verified against Shopify's own documentation before being treated as definitive.

It is nonetheless clear that Shopify has now deployed technical infrastructure that lets agents complete purchases at checkout — and that the company is simultaneously building in mechanisms (key registration, explicit consent, injection vigilance) meant to keep that from happening without control.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.