Is a Shopify store ready for AI agents? Shopify’s developer docs describe what an agent actually does on a store: search the catalog, build a cart, then either hand the buyer to checkout or, if the agent is trusted, complete it. Readiness is therefore a question about three surfaces, not one score. This piece walks through them using only what Shopify’s own pages say.

The three calls an agent makes

Shopify’s agent overview says its MCP tools implement the Universal Commerce Protocol (UCP) at each step of the buyer journey: negotiate and authenticate, discover products, build carts and checkout, monitor orders.

On a single store, that becomes three concrete surfaces:

  • Catalog. The Storefront Catalog MCP lets an agent search one merchant’s products. Its tools are search_catalog, lookup_catalog and get_product.
  • Cart. The cart and checkout docs list create_cart, get_cart and cancel_cart, plus cart permalinks that send a buyer to a prefilled checkout.
  • Checkout. Checkout MCP creates and updates a checkout session; Checkout WebMCP does the same from inside the buyer’s browser.

What the catalog call returns

Per the Storefront Catalog page, the store’s endpoint is /api/ucp/mcp, and every request must carry a URL pointing to the calling agent’s UCP profile. The response contains products with title, description, a price range in minor units, media and variants, with cursor-based pagination (default 10 results, maximum 250).

The page’s example also shows category entries under several taxonomies, including google_product_category.

Those are fields that come from your product data. Shopify’s page does not grade them, but an agent can only compare what the response contains.

Who controls the purchase

Shopify’s checkout page is explicit about the split:

  • Merchant of record. “The merchant always remains the merchant of record.”
  • Carts are open, checkouts are not. Cart tools “accept unauthenticated requests”; checkout tools “require authentication or a signed request.”
  • Handoff by default. The standard flow ends by directing the buyer to a continue_url to finish on the merchant’s storefront. When eligible, an agent can complete checkout directly; when a purchase needs review, the buyer is redirected to the prefilled checkout.
  • Trust tiers. The overview says higher trust tiers “unlock broader access, including direct checkout completion.”

The browser path differs: Checkout WebMCP is registered on the checkout page and authenticates with Web Bot Auth on the browser’s requests. We covered what that does and doesn’t permit in Shopify WebMCP checkout.

A practical checklist

  1. Look at your own catalog data. Are descriptions, variants and prices complete? Those are what search_catalog and get_product hand to an agent.
  2. Know that most agent purchases hand off to your checkout. Anything that breaks the page at continue_url breaks the sale.
  3. Check the Shopify admin for your agent-related sales-channel settings. The help-center pages that explain them could not be retrieved for this article, so we don’t describe them here.
  4. Run a neutral test. Our free scan and checklist check the same surfaces from the outside.

FAQ

Does a Shopify store need an app to work with AI agents?

Shopify’s developer docs describe agent access through MCP endpoints on the store itself (/api/ucp/mcp), not through an app the merchant installs. Which settings in your Shopify admin decide what is exposed is not covered by those pages, so check there.

Can an AI agent complete a Shopify order without the buyer?

Per Shopify’s docs, the default is a handoff: the agent directs the buyer to the merchant’s checkout via continue_url. Only an eligible, trusted agent can complete a checkout directly, and the merchant stays the merchant of record either way.

What data does an agent read from my Shopify products?

In Shopify’s example response, a catalog search returns title, description, price range, media, variants and category taxonomy values. Incomplete product data means an incomplete answer to the agent.

Sources

For an agent, a Shopify store is only as ready as the catalog it can read and the checkout it can reach, which is the transaction AgentReady audits.