Shopify extended WebMCP into checkout on September 28, allowing browser agents to work with the checkout already open in a shopper's tab and place an order after obtaining approval, according to Search Engine Journal. The tools share the page's visible checkout state and require no merchant configuration. The change extends August's storefront and cart tools beyond their previous endpoint of taking the shopper to checkout.
Four tools divide the work. An agent can read the checkout and subsequent order through get_checkout, make permitted changes with update_checkout, submit the purchase through complete_checkout, and return the tab to the shop through navigate_to_storefront. Updates cover contact information, shipping or pickup, discounts, payment selection and additional fields such as tax numbers. Checkout validates each change, and the agent cannot alter the merchandise in the order.
Payment support has explicit limits. The tools cannot receive new card details. An agent can select an existing Shop Pay card or, where guest checkout permits it, use a Shop Pay approval already held by the agent. Other payment choices remain on the page for the buyer. Shop Pay sign-in, challenges such as 3D Secure, blocking interface extensions and review steps hand control back to the shopper, who also handles app-defined checkout extensions.
Permission to place the order is a separate requirement. The reported documentation tells agents to show the current order and total before seeking the buyer's approval. An authentication signature, stored payment approval or checkout status indicating readiness does not replace that consent. Web Bot Auth helps Shopify recognize browser agents; unsigned requests may face deprioritization or blocking by bot detection.
Coverage depends on the checkout configuration. Standard three-page checkout exposes the tools only when Shop Pay is used. B2B, embedded and mobile SDK checkouts are excluded, as are cross-shop merchandise, draft orders, order editing and payment collection. The storefront documentation currently limits WebMCP to Chromium-based browsers. Shopify recommends server-based Checkout MCP unless an agent is already operating in the buyer's browser. Both routes use the UCP checkout object, with the merchant retaining merchant-of-record status.
The report also describes a Shopify test using GPT-6 Sol on ten tasks across two test shops. WebMCP completed 60 of 60 attempts, compared with 56 of 60 for page-reading and clicking automation. Excluding page setup, attempts took 10.3 seconds versus 27.4 seconds, and WebMCP cost 58% less at OpenAI's list prices. Search Engine Journal flags an inconsistent aggregate attempt count in the underlying post. The test covers one model and test stores, and the cited documentation supplies no live order-volume or conversion-rate results.



