Short answer: Safari 27 ships a Model Context Protocol (MCP) server that lets any MCP-compatible agent connect to a Safari window, load pages, click, type and take screenshots. WebKit built it for debugging your own site, but the same 17 tools work on any site, including your store’s checkout.

What WebKit shipped

WebKit’s announcement of the Safari MCP server (posted 1 July 2026) says it arrives “in Safari 27 and Safari Technology Preview 247”. In its words, “Any MCP-compatible client can connect to the Safari MCP server,” giving the agent access to “the DOM, network requests, screenshots, and console output.”

The post lists 17 tools. The ones that matter for commerce:

  • navigate_to_url: load a URL and return the page’s content
  • page_interactions: click, type, scroll, hover and press keys in sequence
  • get_page_content: extract page text as markdown, HTML or JSON
  • evaluate_javascript: run JavaScript in the page
  • list_network_requests and get_network_request: inspect every request the page makes
  • screenshot, create_tab, switch_tab, wait_for_navigation

The setup is two switches plus one command. In Safari’s settings you enable web developer features, then “Allow remote automation and external agents.” The post’s example for Claude is claude mcp add safari-mcp -- "/usr/bin/safaridriver" --mcp, with an equivalent for Codex and a generic mcp.json entry for other agents.

Why a store owner should care

WebKit pitches this at developers, and one of its listed use cases is to “show different states of a checkout flow.” An agent that can do that on your site can do it on anyone’s. Three things follow.

  • It runs a real browser. Pages are rendered by Safari’s engine, not fetched as raw HTML. That is a different access pattern from the crawlers that read your static markup. Client-rendered price and stock still matter, but a browser-driven agent will see what a shopper sees. See our piece on whether AI shopping agents render JavaScript.
  • The privacy boundary sits on the shopper’s side. Per WebKit, the server “runs entirely on your local machine and makes no network calls of its own” and “does not have access to your personal information in Safari (e.g. AutoFill or other browser activity).” An agent driving Safari this way is not documented to reuse a shopper’s saved cards or logins.
  • Nothing in the announcement gives merchants a handle to identify it. The post describes no distinct user agent or header for these sessions. We found none in it, and we have not tested live traffic. If that holds, rules keyed to declared bot names in robots.txt will not see this traffic as an agent. That is our inference, not something Apple states.

What to check on your store

  • Guest checkout works in a real browser. If an agent starts from a clean automation window, a mandatory-login checkout stops it.
  • Forms are labelled and predictable. page_interactions drives the DOM by selectors and text. Unlabelled fields and custom widgets are where agents stall.
  • Price and availability are visible after load. Screenshots and extracted text both come from the rendered page.
  • Your analytics can tell the difference. WebKit says the agent’s data goes “directly to the agent you’re running,” which suggests your logs are your only view of it.

FAQ

What is the Safari MCP server?

It is a Model Context Protocol server built into Safari 27 and Safari Technology Preview 247, launched through safaridriver --mcp. It connects an MCP-compatible agent to a Safari window so the agent can read the DOM, network requests, console and screenshots, and interact with the page.

Can an AI agent buy things on my store through Safari?

Apple’s announcement frames the tool as a developer debugging aid, not a shopping product. Its toolset can navigate to pages, click, type and inspect forms, and Apple’s own use case list mentions checking checkout flow states. Whether a given agent completes a purchase depends on the agent and on how friction-free your checkout is.

Does the Safari MCP server have access to a shopper’s saved cards and logins?

WebKit says it does not have access to personal information in Safari such as AutoFill or other browser activity, and that it makes no network calls of its own. The post also warns to “only use [agents] you trust,” because what happens to captured content depends on the agent and model.

Sources

Agents are gaining new ways into your store faster than anyone labels them, which is why AgentReady tests the transaction itself: whether a browser-driven agent can actually get from product page to paid.