Skip to content
ShopifyAug 27, 202615 min

Agentic Commerce on Shopify: What Your Store Already Does Without You

Send one HTTP request to any of five well-known Shopify storefronts, allbirds.com, gymshark.com, fentybeauty.com, stevemadden.com or brooklinen.com, and you get back a live agentic commerce capability document at /.well-known/ucp. All five declare protocol version 2026-08-25, the same ten capabilities, and the same three payment handlers. None of those merchants built any of it.

The protocol layer, which looks like an engineering project, already shipped platform-wide with no merchant action required. What’s left is product data, published policy pages, a handful of channel toggles, and a robots file somebody on your team may have edited two years ago.

Every direct agentic checkout surface we could verify is gated to buyers in the United States, or on Meta to the United States, Canada and Mexico. Microsoft’s eligibility rule (opens in new tab) is “Only English-language merchants who sell to US buyers are eligible at this time (supporting USD),” and Microsoft says it can’t give a timeline for other regions.

What Is Agentic Commerce, And Why Shopify Merchants Are Already In It

So what is agentic commerce? It’s a purchase where software does the shopping: an AI assistant reads a machine-readable description of your catalog, assembles a cart, and either hands the buyer to your checkout or completes payment on the buyer’s behalf with explicit consent. Agentic shopping happens on someone else’s surface, against a feed and a capability manifest, not against your theme. Your PDP copy, your hero video and your carefully tuned upsell module aren’t in that conversation.

The commerce AI surfaces that currently matter to a Shopify merchant are ChatGPT, Microsoft Copilot, Google’s AI Mode and Gemini, Meta, and Shopify’s own Shop app. Each one reaches your catalog through the same plumbing. That plumbing has a name, a version number, and a specification you can read.

Two Agentic Commerce Protocols, And Shopify Runs Only One

Google announced the Universal Commerce Protocol (opens in new tab) on January 11, 2026, and Shopify announced it the same day (opens in new tab). Google describes UCP as a new open standard for agentic commerce that works across the whole shopping journey, from discovery and buying through post-purchase support. Shopify calls UCP the standard it co-developed with Google (opens in new tab).

The UCP repository (opens in new tab) is Apache-2.0 licensed and has published four releases: 2026-01-11, 2026-01-23, 2026-04-08 and 2026-08-25. UCP carries no global beta or GA label. It uses date-based versions, so the accurate way to describe its state is current protocol version 2026-08-25 rather than UCP 1.0.

The Agentic Commerce Protocol is a different specification with different owners. The spec is maintained by OpenAI and Stripe (opens in new tab) and is currently in beta, and its repository carries a beta status badge. Five spec versions have been released, the current one is 2026-04-17, and its changelog deprecates the previous 2026-01-30 version.

Stripe sits on both sides. It co-maintains ACP, and it’s a member of the UCP Tech Council (opens in new tab). Neither specification has announced a merger with the other, so a Shopify merchant planning around convergence is planning around something no vendor has published.

Discovery in UCP runs on a standard JSON manifest (opens in new tab) located at /.well-known/ucp. UCP specifies four transports (opens in new tab), REST, MCP, A2A and an embedded protocol. Under the specification, businesses that support older protocol versions should publish version-specific profiles and advertise them in a supported_versions field.

An Agentic Commerce Spot Check: Eleven Domains, One Command

The method is one request per domain: curl -sL -m 15 "https://<domain>/.well-known/ucp", then parse the JSON and count the capability keys programmatically rather than by eye.

Domain Platform Response UCP version Capabilities
allbirds.com Shopify 200 2026-08-25 10
gymshark.com Shopify 200 2026-08-25 10
fentybeauty.com Shopify 200 2026-08-25 10
stevemadden.com Shopify 200 2026-08-25 10
brooklinen.com Shopify 200 2026-08-25 10
chewy.com Not Shopify 200 2026-01-23 3
target.com Not Shopify 404 none served 0
walmart.com Not Shopify 404 none served 0
wayfair.com Not Shopify 404 none served 0
nordstrom.com Not Shopify 404 none served 0
bestbuy.com Not Shopify 301, no document none served 0

The ten capabilities on the Shopify profiles are checkout, cart, order, fulfillment, discount, catalog.search, catalog.lookup, permalink, identity linking and dev.shopify.catalog. Eight carry the open dev.ucp.shopping namespace, and identity linking sits in the open dev.ucp.common namespace. The tenth is Shopify’s own vendor extension, which extends the two generic catalog capabilities, so ten isn’t a count of the open standard. It’s nine standard capabilities plus one of Shopify’s.

All five profiles declare the same three payment handlers, Google Pay, Shopify’s card handler and Shop Pay, and expose two transports, MCP with an endpoint on the store’s myshopify.com domain plus an embedded binding. Their supported_versions maps advertise both 2026-04-08 and 2026-01-23, so Shopify serves the current protocol version and the two before it simultaneously. A merchant who wanted to replicate that behavior by hand would be maintaining three profile versions in parallel.

Chewy Serves UCP, And Is Two Versions Behind

chewy.com serves a real UCP profile, which means somebody there did the engineering work on purpose. Its profile declares version 2026-01-23, two releases behind the five Shopify stores, with three capabilities, checkout, fulfillment and order, no cart and no catalog. Its transport is REST rather than MCP, and its Google Pay handler is Braintree-backed.

A large retailer that invested real effort in agentic commerce is running two protocol versions behind with fewer than a third of the capabilities the five Shopify stores serve by default. Chewy chose its capability set, its transport and its upgrade schedule. The Shopify merchants chose none of those things and got the newest version anyway.

What This Evidence Does Not Show

Serving a capability document isn’t proof that an agent can complete a purchase at that store. The check shows what a storefront advertises to agents, not what happens when one tries to buy something. Eleven domains picked for name recognition is a spot check rather than a survey, the reading is point-in-time, and Shopify ships changes continuously. Nothing here measures traffic, conversion or revenue.

Agentic Commerce Checkout Is Mostly US-Only Right Now

To sell through Microsoft Copilot’s direct checkout, your store must sell to customers in the United States (opens in new tab), and that checkout displays only to customers based in the United States. Google AI Mode and Gemini’s direct checkout is displayed only to customers based in the United States too, and Meta’s to customers based in the United States, Canada or Mexico. Microsoft applies its own English-language and USD constraint.

Google announced Universal Cart (opens in new tab) on May 19, 2026, and said the cart would roll out across Search and the Gemini app in the U.S. that summer, with YouTube and Gmail to follow, and Canada and Australia in the coming months. Google put the U.K. later than Canada and Australia, with no date attached.

Google said buyers would be able to try these checkout features “soon” across merchants like Nike, Sephora, Target, Ulta Beauty, Walmart, Wayfair and Shopify merchants such as Fenty and Steve Madden. Google named those merchants as forthcoming, not as live.

Three of those retailers serve no public UCP profile at all, which is a reminder that onboarding through Merchant Center leaves no trace at /.well-known/ucp.

If most of your revenue is outside the US, Canada and Mexico, agentic commerce is a data-hygiene and discovery project right now rather than a channel you can forecast. The work still pays, because the same product feed that feeds an agent feeds your Google Shopping AI placements and your existing Merchant Center campaigns. That overlap is the reason this is worth doing before the transactional side opens up in your markets, and it’s the same feed our team maintains for Google Shopping and Performance Max management.

Label Every Agentic Commerce Feature: Shipped, Pilot, Early Access, Announced

Surface What it does for a Shopify merchant Status
ChatGPT Discovery; buyer completes on your own checkout Live, on by default; you can cut its Catalog access but there is no direct-checkout toggle
Microsoft Copilot Direct checkout Live on Shopify, on by default with an opt-out toggle, US only; Microsoft labels Copilot Checkout a pilot
Google AI Mode and Gemini Direct checkout Rolling out to eligible stores; direct checkout might not be in your store yet
Meta Direct checkout Live; Shopify lists Meta ads as coming
Shop app Shopify’s own catalog surface Live
Universal Cart API One agent cart across merchants Early access waitlist
Sponsored products in Catalog API Paid placement in agent results Developer preview coming soon
AP2 agent payment mandates Payment authorization layer Announced; Google said it would start with Gemini Spark

There’s no option to activate or deactivate a ChatGPT direct checkout setting (opens in new tab) in your Shopify admin, and purchases complete on your online store checkout inside a ChatGPT in-app browser, or in a new tab on ChatGPT web. For a Shopify merchant, ChatGPT is a discovery channel that hands the buyer to your own checkout, which means your checkout conversion rate is still the thing that decides the outcome.

Microsoft labels its store-settings configuration “Pilot only to select customers,” with no published GA date, and supports three PSPs, PayPal, Shopify and Stripe, with one checkout partner per merchant. Shopify says Google AI Mode and Gemini are rolling out to eligible stores, and that direct checkout might not yet be available in your store. The Universal Cart API on shopify.dev (opens in new tab) has a single call to action, a request-access waitlist.

Agentic payments, the layer where an agent holds authorization to spend rather than passing the buyer to a payment page, is the least shipped part of the stack. Google said in May that it would begin bringing AP2 to its products “in the coming months, starting with Gemini Spark.” OpenAI’s approach prepares a one-time delegated payment request (opens in new tab) with a maximum chargeable amount and an expiry set from what the buyer selected, and OpenAI states plainly that “OpenAI is not the merchant of record in the Agentic Commerce Protocol.”

On economics, Shopify states there are no fees for selling in ChatGPT or through Copilot’s direct checkout and that you pay only your standard payment processing fees. In its Spring ’26 Editions, Shopify also claims that data syndicated by Shopify “drives 2x more conversion in AI chats (opens in new tab),” which is Shopify measuring its own product on its own surfaces. Shopify hasn’t published a sample size, time period, comparison group or method for it. Treat it as marketing copy, not as a planning input.

Product Data Is The Agentic Commerce Lever

OpenAI requires eleven product feed fields (opens in new tab) for a non-Ads feed: item_id, title, description, url, brand, image_url, price, availability, is_eligible_search, is_eligible_checkout and target_countries. Google Merchant Center requires seven product data attributes (opens in new tab): id, title, description, link, image_link, availability and price. Different names, overlapping substance, one underlying discipline. Fix the source data once and both feeds improve.

The conditional requirements are where feeds quietly fail. OpenAI requires availability_date when availability is pre_order. If you upload a Google-format feed through OpenAI’s Google-compatible path, that path adds its own rule: supply a valid gtin or mpn unless you set identifier_exists to no. In OpenAI’s native schema both identifiers are optional.

Google requires brand for new products outside movies, books and musical recordings, plus age_group, gender, color, size and item_group_id for apparel in certain target countries.

Field constraints are specific enough to break an export you wrote years ago. OpenAI caps item_id at 100 characters and requires that it remain stable, caps title at 150 characters and description at 5,000 characters of plain text. The availability enum accepts in_stock, out_of_stock, pre_order, backorder and unknown. Feeds upload as UTF-8 tab-delimited .txt or .tsv, or comma-delimited .csv, with gzip variants accepted.

OpenAI recommends sending the entire feed once a day by file upload, with intraday updates through the API. Plan against the failure mode as well as the cadence. A stale availability value turns an agent’s recommendation into an out-of-stock page for a buyer who never saw your site before, and neither you nor the agent gets a second look at that purchase.

That split is why product data work outranks design work for this specific channel, and why the two jobs don’t compete. The human still needs the page, which is what PDP optimization tests are for. The agent needs the record behind it to be complete, stable and current.

Category eligibility sits above data quality. OpenAI’s commerce program excludes categories outright (opens in new tab), including adult content, age-restricted products such as alcohol, nicotine and gambling, weapons, harmful or dangerous materials, prescription-only medications, unlicensed financial products and legally restricted goods. If you sell in one of those categories, the feed work has a ceiling and you should know where it is before you scope it.

Published Policies Gate The Checkout

Shopify and OpenAI both gate agentic checkout on your published policy pages. Shopify requires completed Terms of Service, Privacy Policy and Return or Refund Policy for direct-checkout AI channels. OpenAI makes seller_privacy_policy and seller_tos required fields whenever checkout is enabled.

Both checks look for published URLs, so the untouched template you generated at launch will pass mechanically. The refund policy is what a buyer reads after an agent completed a purchase they approved once, in a chat window, on a surface that isn’t yours. Rewriting three policy pages is the cheapest agentic commerce work you have and the most likely to be sitting undone.

Human approval is a hard requirement on the Shopify side, and Shopify states it to agents directly in the instruction file it generates for every storefront.

Checkout requires human approval. Agents must not complete payment without explicit buyer consent.

The Agentic Commerce Toggles You Have, And The One You Don't

Agentic Storefronts lives in your admin under Sales channels, Agentic. It’s active by default for eligible stores (opens in new tab) once you’ve read and agreed to the Agentic Storefronts Supplemental Terms of Service. The admin home for it shipped on May 11, 2026 (opens in new tab), with tracking for AI channel presence, sales and product data quality.

The controls you actually have are these:

  • Turn individual AI channels on or off in Sales channels, Agentic
  • Deactivate auto-enroll so you keep Catalog access without being added to new channels automatically
  • Turn off Shopify Catalog access entirely
  • Hide a single product with Unlisted status or the <code>seo.hidden</code> metafield

Turning off Catalog access isn’t instant. It can take up to seven days (opens in new tab) before your product data stops being shared through Shopify Catalog. Plan any suppression around that lag rather than around a launch date.

Unlisted status (opens in new tab) also hides the product from sitemaps, from search engines such as Google, and from your online store search. Excluding a product from agentic commerce that way also excludes it from organic search, which is a steep price for a channel decision.

Some products are excluded automatically and you don’t need to do anything about them. Shopify excludes B2B-only products, meaning products published only to B2B markets, assigned to specific companies or locations, or requiring customer authentication, along with products behind a password-protected storefront and anything set to Unlisted. If your catalog is genuinely split between DTC and wholesale, that separation already exists in Shopify’s logic, which is one of the reasons B2B operations on Shopify Plus are worth structuring properly in the first place.

The one control you don’t get is a ChatGPT direct-checkout switch. You can influence what ChatGPT sees through Catalog access and product-level visibility. You can’t configure a checkout setting that doesn’t exist in your admin.

Don't Block The Crawlers That Do The Shopping

OpenAI lists four crawlers (opens in new tab), and the distinction that matters is training versus discovery. OpenAI uses OAI-SearchBot to surface websites in search results in ChatGPT’s search features. It uses GPTBot to crawl content that may be used in training its generative AI foundation models. Blocking GPTBot doesn’t remove you from ChatGPT’s search results, and blocking OAI-SearchBot does.

Google draws the same line (opens in new tab). Google says Google-Extended “does not impact a site’s inclusion in Google Search nor is it used as a ranking signal in Google Search.” Storebot-Google affects all surfaces of Google Shopping, so that’s the one to leave alone if you sell anything. Perplexity lists two crawlers (opens in new tab): PerplexityBot, which it says respects robots.txt, and Perplexity-User, which it says generally ignores robots.txt because a user requested the fetch.

Shopify’s default robots.txt doesn’t block any of them. On allbirds.com the named user-agent blocks are adsbot-google, Nutch, AhrefsBot, AhrefsSiteAudit, MJ12bot and Pinterest, with no disallow for GPTBot, OAI-SearchBot, PerplexityBot, Google-Extended, Storebot-Google or ClaudeBot. If anyone on your team ever edited robots.txt.liquid to block AI crawlers, that edit is still live. Read it line by line before you spend a quarter on feed quality.

Sorting which bots serve agentic shopping from which bots serve model training is the same audit discipline behind our answer and generative engine optimization work.

Skip llms.txt And Schema As Your Agentic Commerce Fix

Google says structured data isn’t required for generative AI search (opens in new tab), and that there’s no special schema.org markup you need to add. It also says you don’t need to create new machine readable files, AI text files, markup, or Markdown to appear in Google Search.

llms.txt (opens in new tab) is a proposal to standardize on an /llms.txt file rather than a ratified standard, and it reached v2 on August 10, 2026. Google says it doesn’t consume these files. Shopify generates one for you anyway, and allbirds.com/llms.txt returns a file titled Agent Instructions, with allbirds.com/agents.md returning the same content at the canonical agent path.

The generated file isn’t a ranking artifact. It points agents at the UCP discovery endpoint and the MCP endpoint, lists the read-only endpoints an agent can use without authentication, including /products/{handle}.json and /collections/{handle}/products.json, and tells agents that checkout requires human approval. It also recommends agents install the Shop skill published at shop.app/SKILL.md (opens in new tab) instead of scraping the storefront. Writing your own llms.txt on Shopify means writing a file you already have, for a consumer that publicly says it doesn’t read it.

Keep your schema.org markup regardless, for the job it actually does. For merchant listings (opens in new tab), Google requires name, image and offers on Product, plus price and priceCurrency inside Offer, and merchant listings require an Offer because the merchant has to be the seller. That earns rich-result eligibility in classic search, which is a real return. It isn’t the agentic commerce lever, and treating it as one costs you the quarter you should have spent on the feed.

Off Shopify, The Agentic Commerce Bill Looks Different

A merchant on a bespoke or headless stack pursuing ACP Instant Checkout hosts the endpoints itself. OpenAI specifies five endpoints (opens in new tab): create a checkout session, update it, complete it, cancel it, and retrieve it. Requests carry Authorization, Idempotency-Key, Request-Id, a base64 HMAC Signature of the request body, an RFC 3339 Timestamp and an API-Version header. That’s a payments-grade integration with signature verification and idempotency, not a feed upload.

Access is gated on top of the engineering. Onboarding product feeds in ChatGPT is currently available to approved partners (opens in new tab), with applications at chatgpt.com/merchants. Building with the Agentic Commerce Protocol is open to all (opens in new tab), while Instant Checkout in ChatGPT is currently available to approved partners. Weighing that build against what the platform serves for free is the same calculation that runs through most headless Shopify and Hydrogen decisions we’re asked to make.

There’s a third path that didn’t exist a year ago. Shopify’s Spring ’26 Editions describes an Agentic plan letting businesses not on Shopify sync their products into Shopify Catalog and sell across AI channels and in the Shop app, and Shopify says Catalog access “takes just an API key, no approval needed.” For a brand evaluating a replatform, that’s agentic distribution available without committing to a full Shopify migration first. It also puts the catalog layer, rather than the storefront, at the center of Shopify’s distribution story.

The Agentic Commerce Work That's Actually Yours

None of this requires a developer sprint:

  • Audit product data against both feed specs, starting with the conditional fields
  • Publish real Terms of Service, Privacy and Refund policies, not the launch-day templates
  • Open Sales channels, Agentic and decide each channel and the auto-enroll setting on purpose
  • Re-read <code>robots.txt.liquid</code> and confirm you haven't blocked a discovery crawler
  • Decide whether mostly US-gated checkout makes this a revenue line or a hygiene line for your market mix
  • Re-run the capability check on your own domain each quarter, following redirects

Agentic commerce arrived on your Shopify store as infrastructure rather than as a project, and the platform is already advertising its capabilities to any agent that asks. What agents find behind that document is your product data, your policies and your checkout. Those three have been the job the whole time, and the only thing that changed is who reads them first.

If you want a second set of eyes on what an agent can actually read from your catalog, that’s part of what we do in a free Growth Audit.

E.J. Ulery

About the author

EJ Ulery

Co-Founder & CTO

EJ Ulery on LinkedIn (opens in new tab)

Not sure where the gap is? That's exactly what the Digital Marketing Growth Audit is for.

A free, no-obligation look at where your site can win more traffic and conversions, with a clear digital marketing roadmap to get there. Just a straight read on where your digital presence stands and where it's headed.