Shopify WebMCP Checkout: The Intent/Authorization/Settlement Split, Live in Production Shopify extended its WebMCP protocol to checkout on September 28, 2026, letting browser-based AI agents read, update, and submit orders on eligible merchant storefronts with no merchant configuration, provided the buyer explicitly authorizes the purchase and no payment credentials pass through the agent. The rollout builds on native WebMCP tools activated August 5 across Liquid storefronts and includes Shop Pay, positioning Shopify against Amazon and Adidas, which are blocking agent-initiated purchases. A developer testing a per-payment confidence gate on the new tools reported that the conservative heuristic escalated even a read-only get_checkout pattern (score 0.16), since it scores instruction text rather than the buyer's confirmation state. The short answer: on September 28, 2026, Shopify extended WebMCP to checkout. Browser-based AI agents can now read a checkout, update it, and submit the order — after the buyer authorizes it. Shop Pay is included. Zero merchant configuration. Every outlet covered the announcement. None covered the authorization architecture — which is the real story. Three new checkout tools per Shopify's Sept 28 developer changelog, via Unite.AI https://www.unite.ai : get checkout — reads checkout state, messages, post-completion order details update checkout — updates supported checkout fields address, delivery option, discounts complete checkout — submits the checkout, navigate to storefront — returns the tab to the storefront They run inside checkout-web, share the checkout UI's state, expose no new API, and require no merchant configuration. This builds on native WebMCP activated August 5 across all Liquid storefronts catalog + cart tools: search catalog , update cart , proceed to checkout . The agent can READ, EDIT, and SUBMIT . The agent CANNOT input payment credentials — control hands back to the buyer whenever input is required 3D Secure, blocking UI extensions . The buyer explicitly authorizes the purchase. That's the intent / authorization / settlement split the six-bank "Building Trust in Agentic Commerce" report Sept 22 and the GFF regulators Sept 25 demanded — now shipping as product on a major commerce platform. The context: Amazon and Adidas are blocking agents from purchasing TechCrunch https://techcrunch.com , Sept 28 — "and Adidas, apparently " . Shopify bet the opposite way. Muse and Instinct already have direct Shopify partnerships. The platform war for agentic checkout is on. Shopify's "buyer confirms" is the human-confirm band made standard. But buyer confirmation proves WHO agreed — not whether the agreement was wise . That's the $78k Codex lesson, and exactly the gap the per-payment confidence gate fills: the machine-native layer that scores the instruction before it reaches human confirmation. Live receipts, tested ~20:18 EDT Sept 28 on our gate decider local-heuristic-v1, calibrated=false : | Instruction pattern | Score | Band | |---|---|---| | AI agent calls WebMCP complete checkout for a $249 digital trading bundle; buyer confirmed the purchase in the checkout session; no payment credentials pass through the agent | 0.18 | ESCALATE — block + log | | AI agent calls WebMCP get checkout to READ checkout state and display the order summary. No money moves, no order is placed. | 0.16 | ESCALATE — block + log | The honest finding: the heuristic is conservative by design — it escalates even the read-only pattern, because it keys on agent+checkout+payment instruction language. It scores the instruction text, not the buyer's actual confirmation state — which it cannot see. Shop Pay's buyer confirmation and the confidence gate are complements, not competitors. It's on by default. Merchants don't install an app, flip a setting, or write code — WebMCP tools were pre-registered on storefronts Aug 5 and checkout arrives the same way. Any eligible merchant store on the platform is now agent-purchasable out of the box — including ours ScriptMasterLabs sells 9 high-ticket products on Shopify . Rollout is to "all eligible Shopify merchants" — eligibility terms weren't detailed in the Sept 28 coverage; that's the piece to watch. Full dated receipts, claim receipts, and a 5-minute merchant checklist: Canonical version with live receipts: https://scriptmasterlabs.com/shopify-webmcp-checkout https://scriptmasterlabs.com/shopify-webmcp-checkout