Shopify's AI shopping tools now extend past the cart and into checkout. In a September 28 developer changelog, the company said a browser agent can read and update the checkout open in a buyer's tab, then submit it after the buyer confirms the order. Its earlier storefront tools could take a shopper to checkout. The new tools let the agent work with checkout fields.

The big change

  • What changed: A browser agent can now work with the checkout the buyer sees, including contact details, delivery choices and discounts. Shopify's August storefront tools stopped at navigation to checkout; the September release adds checkout tools in the same tab.
  • Why it matters: A shopper can delegate more of the form work while retaining control over the order and total. Shopify requires the agent to show both and get permission before submission. Login, payment challenges and some review steps still belong to the buyer on the page.
  • What to watch: The useful boundary for developers is eligibility. Shopify excludes several checkout types and says browser agent support remains limited to Chromium. Those conditions determine whether an agent can use the new tools for a given purchase.

From storefront to checkout

Shopify's August 5 release put WebMCP tools on every Liquid storefront and on Hydrogen storefronts in developer preview. A compatible agent in the shopper's browser can search products, inspect variants, read and update the live cart, and call proceed_to_checkout. Shopify says the storefront tools need no merchant installation or configuration. Cart changes use the store's standard storefront actions, so the shopper sees them in the active session.

The September addition operates on the checkout page. The agent discovers registered tools through document.modelContext.getTools() and calls them through document.modelContext.executeTool(). Shopify says the checkout tool list can change as the buyer moves through the flow, so agents should refresh it when toolchange fires. The tools work on the checkout open in that tab. They do not take a checkout ID and they are separate from Shopify's server-side Checkout MCP endpoint.

The checkout tools have distinct jobs. get_checkout reads the current state, including totals, messages and, on the Thank you page, an order receipt. update_checkout can change buyer contact details, fulfillment, discount codes, declared fields and supported payment choices. It uses replacement semantics: an agent should read the current state first and send the complete state it wants to keep. It cannot change line items or attribution through this checkout tool; the buyer changes items on the page. navigate_to_storefront returns the tab to the store when an online storefront exists.

Shopify's examples identify the UCP checkout version as 2026-08-25. That is the protocol version in the documented responses, while September 28 is the date of the browser checkout release. A response includes both a UCP result status and a checkout lifecycle status. For example, ready_for_complete means the checkout is prepared for a completion attempt. It does not mean the buyer has approved the purchase. Shopify says only completed confirms an order.

The buyer controls submission

Before complete_checkout, Shopify instructs the agent to show the current order and total and obtain the buyer's permission to place it. A changed total requires another confirmation. A ready status, Web Bot Auth signature or Shop Pay approval does not supply that permission.

Even after the call, the page may need the buyer. A configured review step returns requires_escalation; the agent calls complete_checkout again only after the buyer authorizes submission there. For a payment challenge or other buyer action, the buyer finishes on the checkout page and the agent checks the resulting status. Shopify also leaves Shop Pay login and app-defined checkout extension interactions to the buyer. This is an assisted checkout, with a real approval boundary at order submission.

Access and limits

Checkout WebMCP is for agents running in the buyer's browser. Shopify recommends its separate Checkout MCP route for agents that can run on a server. The browser route uses Web Bot Auth signatures on requests. Shopify says an agent should register and publish an Ed25519 public-key directory to receive verified-bot treatment; without that identification, bot detection may deprioritize or block requests. The merchant does not configure a new checkout API for this release.

The tools do not register on standard three-page checkout unless the buyer uses Shop Pay. They also exclude B2B checkout, embedded checkout, mobile checkout SDKs, checkouts containing another shop's merchandise, draft orders, order edits and payment collection. Browser agent support for WebMCP is currently limited to Chromium-based browsers. Shopify's checkout reference also calls out a browser detail that can change: in Chrome 153, executeTool() arguments must be JSON strings, while Chrome plans to accept objects in Chrome 155.

Shopify's cited WebMCP pages do not list a separate price for these tools. The checkout itself still displays the purchase total for the buyer to review. BIG CHANGE reviewed Shopify's release notes and documentation; it did not run a live storefront or purchase test.

Sources & further reading