Shopify shipped Checkout WebMCP on 2026-09-28: browser agents can now read and update Shopify checkouts with structured tools through order confirmation, instead of scraping the page (changelog; docs).
This is merchant-side Shopify checkout in the buyer’s browser—not a Cloudflare browser WebMCP surface, and not a Meta personal-agent Shopify connector story.
The four tools
| Tool | Role (as Shopify states) |
|---|---|
get_checkout |
Read current checkout state, messages, and post-completion order details on the Thank you page |
update_checkout |
Replace supported fields (buyer contact, fulfillment, discounts, declared fields, payment); PUT semantics; ignores line_items and attribution (buyers still change items on the page) |
complete_checkout |
Place the order after the buyer confirms |
navigate_to_storefront |
Leave checkout / return to the storefront (registered only when the store has an online storefront) |
The tools run inside checkout-web and use the same state as the checkout UI. Shopify says they do not expose a new API or require merchant configuration—still limited to eligible checkouts below (changelog).
Buyer confirmation before place-order
Before calling complete_checkout, the agent must show the buyer the current order and total and get permission to place it. Web Bot Auth (WBA), a Shop Pay approval, and ready_for_complete do not grant that permission. If the total changes, ask again (docs).
Shopify also expects page handoff for Shop Pay login, payment challenges (for example 3D Secure), blocking UI extensions, and configured review steps—the agent does not bypass those flows.
Eligible checkouts only
Tools register on eligible checkouts. Shopify does not register them for:
- Standard three-page checkout, unless the buyer checks out with Shop Pay
- B2B checkout
- Embedded checkout and mobile checkout SDKs
- Merchandise from another shop
- Draft orders, order edits, and payment collection
Shopify has not published a merchant count or an “all stores” GA claim—stick to eligible checkouts as documented (eligibility).
Payments and Web Bot Auth
Checkout WebMCP does not accept new card details. Allowed instrument paths via tools: a saved Shop Pay card (by id from get_checkout), a Shop Pay approval, or billing address only. Any other method stays on the checkout page (docs).
Web Bot Auth (WBA) signs browser requests (not tool arguments). Shopify uses WBA to identify the agent; without it, bot detection may deprioritize or block requests. Only registered WBA keys verify.
For context, Shopify also documents hosted Checkout MCP (server-side JSON-RPC) alongside browser WebMCP—same checkout object family, different transport (carts and checkout).
Who should care
Teams building browser shopping agents on Shopify should start at the changelog and Checkout WebMCP guide—lead with the four tools, keep buyer confirmation and eligible checkouts explicit, and treat no new card entry plus WBA as first-class constraints.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.