Short answer: an AI shopping agent needs to do five things on your store: get in, read the page, understand the product, find the rest of your catalog, and reach checkout. You can test each one yourself with a browser and, for two of them, one terminal command. Below is the order that matters, because a failure early on makes everything after it irrelevant.

1. Can an agent get in?

Open https://yourstore.com/robots.txt. Look for two things: a blanket Disallow: / under User-agent: *, and AI agents named explicitly with a Disallow. Either one tells a well-behaved agent to stay out. Our robots.txt copy-paste block lists the tokens that need allowing and what each one does.

robots.txt is only the stated policy. A firewall or CDN bot rule can still turn agents away at the edge whatever robots.txt says. To see what an agent actually receives, request a product page with an agent’s user agent:

curl -s -o /dev/null -w "%{http_code}\n" \
  -A "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot" \
  https://yourstore.com/products/your-product

200 means the door is open. 403, 429 or a challenge page means it isn’t, and this is the one failure that outweighs everything else: our own scoring caps a store that blocks agents at the door, however good the rest is. The exact user-agent string and how to verify the real crawler are in our GPTBot user agent guide.

2. Can it read the page without JavaScript?

Many agents read the HTML your server sends, not what a browser paints after scripts run. Fetch the same product page and look for its price:

curl -s https://yourstore.com/products/your-product | grep -i "your price, e.g. 24.90"

If the price, the stock status or the add-to-cart action only appears after JavaScript runs, an agent reading raw HTML can describe the product but cannot buy it. In a controlled test of 19 page configurations, JavaScript-only rendering was one of only two things that stopped a plain fetch from succeeding; outright blocking was the other (the data).

3. Does the page say what the product is, in a format machines read?

In your browser, open the product page, view the source, and search for application/ld+json. You are looking for a Product block with an Offer inside it that carries at least the price, the currency and the availability, plus the brand and an identifier such as a GTIN or SKU. Without them, an agent has to guess these from the page layout, and guesses break. Shipping cost and return policy belong in the offer too, or an agent can’t tell a shopper what the order will really cost. The full field list, with examples, is in our Product JSON-LD guide.

4. Can it find the rest of your catalog?

Open https://yourstore.com/sitemap.xml. An agent uses it, like a search engine does, to find product pages it wasn’t linked to directly. Then check a product that comes in sizes or colours: each variant should carry its own price and availability in the structured data, not only the default one, or an agent may quote a shopper the wrong option. An llms.txt file is optional here: it doesn’t make pages more reachable, but agents that find it use it as a map (what to put in one).

5. Can it reach checkout?

Add a product to the cart in a private browser window, without logging in, and go to checkout. Note anything that stops you before the payment step: a forced account creation, a captcha, a pop-up that must be closed. Each of these is where an agent gives up. Then repeat the curl command from step 1 on /cart and /checkout: those paths are sometimes blocked for bots even when product pages are open. Seven common ways agents fail at this stage are in why AI shopping agents abandon your checkout.

You don’t need the new agent-commerce protocols (UCP, ACP, x402) to pass these five checks. They matter for what comes next, and our two-rails breakdown explains them, but a store that fails step 1 or 2 gains nothing from adding them.

Or run all five at once

The free AgentReady scan runs these checks, and a few more, and returns a score out of 100 with the fixes ranked by impact. It is deterministic: no AI grades your store, every point traces back to a fact on a fetched page, and the same store gets the same score twice. It follows the buying path up to the checkout boundary and never places an order or enters payment details. How the score is built is public in our methodology.

FAQ

How can I check whether AI shopping agents can find, understand and buy on my online store?

Run five checks in order: robots.txt and a request with an agent’s user agent (can it get in), a plain fetch of a product page (can it read the price without JavaScript), the page’s Product structured data (can it understand the offer), the sitemap and variant data (can it find the catalog), and a logged-out trip to checkout (can it reach the payment step). A free scan at agentready.market runs all five and stops before placing any order.

Do I need llms.txt for AI agents to buy on my store?

No. It doesn’t make your pages more reachable; access and server-side rendering do. Agents that find an llms.txt do use it to navigate, so it is worth adding once the basics pass.

Will checking my store place a test order?

No. Neither the manual checks above nor the AgentReady scan place an order or enter payment details. The scan stops at the checkout boundary.

Does a high Cloudflare Agent Readiness Score mean agents can buy on my store?

Not on its own. Cloudflare’s score covers the access and discovery layer; it does not test whether an agent can reach checkout. See what Cloudflare’s score actually checks.

Sources

AgentReady at agentready.market, operated by Villepinte Studio; unaffiliated with other AgentReady-named products.