Install
npm install -g @shopify/ucp-cliProducts
Shopify, product by product →Shopify ships more than one product — each judged line competes in its own arena on the same stories as everyone else.
| Line | Arena | Rank | PA Score | Agent-ready |
|---|---|---|---|---|
| Shopify Platform | E-commerce Platforms | #2/5 | 32/100 | 56/100 |
| Shopify Agentic Commercethis page | Agentic Commerce | #2/7 | 33/100 | 68/100 |
Not yet judged (3 — no arena where they compete): Shopify POS · Shopify Payments · Shop
Try itExperimental
See what an agent can do with Shopify Agentic Commerce before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si -X POST https://catalog.shopify.com/api/ucp/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # full keyless handshakerecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agent checkout — stories about agent checkout in this arenaAgent checkoutevidence →
Stories about agent checkout in this arena
Agent discovery — stories about agent discovery in this arenaAgent discoveryevidence →
Stories about agent discovery in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Fees economics — stories about fees economics in this arenaFees economicsevidence →
Stories about fees economics in this arena
Merchant enablement — stories about merchant enablement in this arenaMerchant enablementevidence →
Stories about merchant enablement in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Order lifecycle — stories about order lifecycle in this arenaOrder lifecycleevidence →
Stories about order lifecycle in this arena
Payment credentials — stories about payment credentials in this arenaPayment credentialsevidence →
Stories about payment credentials in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Protocol openness — stories about protocol openness in this arenaProtocol opennessevidence →
Stories about protocol openness in this arena
Refunds disputes — stories about refunds disputes in this arenaRefunds disputesevidence →
Stories about refunds disputes in this arena
Trust safety — stories about trust safety in this arenaTrust safetyevidence →
Stories about trust safety in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Shopify Agentic Commerce stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent checkout — stories about agent checkout in this arenaAgent checkout
Stories about agent checkout in this arena
My agent can create and update a cart or order draft through a documented protocol call
✓9/10
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
~7/10
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
~6/10
Build against a versioned commerce protocol with a published schema and conformance or validation tooling
✓7/10
Agent discovery — stories about agent discovery in this arenaAgent discovery
Stories about agent discovery in this arena
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
✓8/10
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
✓9/10
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell
✓9/10
My agent can discover payable services and APIs through a published directory or discovery index
✓8/10
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓9/10
unlocks → API sandbox · Full data export
Subscribe to events via webhooks
~5/10
Build against official SDKs
~6/10
Issue scoped/least-privilege API credentials for an agent
✓7/10
Connect an agent via an official MCP server
✓9/10
Download a machine-readable API spec (OpenAPI or equivalent)
~4/10
Rely on versioned APIs with a documented deprecation policy
~4/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
~4/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
~7/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
✓7/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
~4/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Fees economics — stories about fees economics in this arenaFees economics
Stories about fees economics in this arena
Merchant enablement — stories about merchant enablement in this arenaMerchant enablement
Stories about merchant enablement in this arena
Orders are attributed to the originating agent and I can report on or filter transactions by agent
~5/10
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
~5/10
Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout
~3/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle
Stories about order lifecycle in this arena
Payment credentials — stories about payment credentials in this arenaPayment credentials
Stories about payment credentials in this arena
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
~4/10
Monetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI
n/an/a
Settle agent-initiated payments in stablecoins over documented rails
—0/10
Provision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility
—0/10
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Protocol openness — stories about protocol openness in this arenaProtocol openness
Stories about protocol openness in this arena
Refunds disputes — stories about refunds disputes in this arenaRefunds disputes
Stories about refunds disputes in this arena
Trust safety — stories about trust safety in this arenaTrust safety
Stories about trust safety in this arena
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots
✓9/10
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
~6/10
The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk
—0/10
Set per-agent spend caps and usage limits and revoke an agent's payment authority instantly
—–
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 7/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Cclaimed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots C Agent identity | merchant | Trust safety — stories about trust safety in this arenaTrust safety | 3 | full | 9/10 | Tprobed | |
My agent can create and update a cart or order draft through a documented protocol call C Cart | ai-native user | Agent checkout — stories about agent checkout in this arenaAgent checkout | 3 | full | 9/10 | Tprobed | |
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell C Merchant feeds | merchant | Agent discovery — stories about agent discovery in this arenaAgent discovery | 3 | full | 9/10 | Tprobed | |
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required C Agent search | ai-native user | Agent discovery — stories about agent discovery in this arenaAgent discovery | 3 | full | 8/10 | Tprobed | |
The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything C Spec publication | developer | Protocol openness — stories about protocol openness in this arenaProtocol openness | 3 | full | 8/10 | Tprobed | |
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order C Checkout | ai-native user | Agent checkout — stories about agent checkout in this arenaAgent checkout | 3 | partial | 7/10 | Tprobed | |
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves C Human oversight | ai-native user | Trust safety — stories about trust safety in this arenaTrust safety | 3 | partial | 6/10 | Cclaimed | |
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint C Onboarding to agents | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 3 | partial | 5/10 | Tprobed | |
My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmatically C Order events | developer | Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle | 3 | partial | 5/10 | Cclaimed | |
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number C Delegated credentials | ai-native user | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | partial | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 3/10 | Cclaimed | |
Provision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility C Wallets | ai-native user | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Monetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI C Machine payments | developer | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service C Machine readable offers | developer | Agent discovery — stories about agent discovery in this arenaAgent discovery | 2 | full | 9/10 | Tprobed | |
My agent can discover payable services and APIs through a published directory or discovery index C Service discovery | ai-native user | Agent discovery — stories about agent discovery in this arenaAgent discovery | 2 | full | 8/10 | Tprobed | |
My agent can query the status and tracking of an order it placed, after the purchase C Post purchase status | ai-native user | Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle | 2 | full | 8/10 | Cclaimed | |
At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration C Ecosystem adoption | developer | Protocol openness — stories about protocol openness in this arenaProtocol openness | 2 | full | 7/10 | Tprobed | |
Build against a versioned commerce protocol with a published schema and conformance or validation tooling C Protocol conformance | developer | Agent checkout — stories about agent checkout in this arenaAgent checkout | 2 | full | 7/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 7/10 | Tprobed | |
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers) C Embedded surfaces | merchant | Agent checkout — stories about agent checkout in this arenaAgent checkout | 2 | partial | 6/10 | Tprobed | |
Orders are attributed to the originating agent and I can report on or filter transactions by agent C Attribution analytics | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 2 | partial | 5/10 | Cclaimed | |
Refunds on agent-placed orders can be initiated and tracked programmatically C Refunds | developer | Refunds disputes — stories about refunds disputes in this arenaRefunds disputes | 2 | partial | 4/10 | Cclaimed | |
Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout C Traffic controls | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 2 | partial | 3/10 | Cclaimed | |
Settle agent-initiated payments in stablecoins over documented rails C Settlement rails | developer | Payment credentials — stories about payment credentials in this arenaPayment credentials | 2 | none | 0/10 | ||
The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk C Liability | merchant | Trust safety — stories about trust safety in this arenaTrust safety | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes C Disputes | developer | Refunds disputes — stories about refunds disputes in this arenaRefunds disputes | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Set per-agent spend caps and usage limits and revoke an agent's payment authority instantly G Spend controls | ai-native user | Trust safety — stories about trust safety in this arenaTrust safety | 2 | none | untested | none yet | |
The fees for agent-originated transactions are published — I can price agentic channels without asking sales C Fees transparency | merchant | Fees economics — stories about fees economics in this arenaFees economics | 2 | none | untested | none yet | |
Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel C Payouts | merchant | Fees economics — stories about fees economics in this arenaFees economics | 1 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 32 stories with headroom
What would move Shopify Agentic Commerce’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Missing: any first-party built-in assistant UI/feature, evidence of a user directly delegating a task to an in-product assistant, and independent confirmation of such an assistant's existence.
Payment credentials — stories about payment credentials in this arenaProvision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility
nonemoves PA Scoreimpact 30
Shopify's UCP evidence covers checkout, payment-handler negotiation (e.g., com.google.pay), and AP2 payment mandates/verifiable credentials tied to cart state, but there is no documentation of a user-funded, agent-held wallet construct with balance visibility — payment credentials are collected per-checkout, not provisioned as a standing wallet.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
None of the evidence addresses data export, portability, or the ability for a user/agent to extract their commerce data in an open format and leave the platform — the pack only covers catalog search, cart/checkout MCP tools, order webhooks, and profile negotiation.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
partialq3/10moves PA Scoreimpact 21
Missing: a rule-definition interface or automation engine, support for triggers beyond order state changes, and any evidence of user-authored conditional actions rather than raw webhook delivery.
Trust safety — stories about trust safety in this arenaThe fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk
nonemoves PA Scoreimpact 20
The evidence pack documents UCP's protocol mechanics (catalog, cart, checkout, order webhooks, trust tiers, profile negotiation) but nowhere specifies fraud liability, chargeback responsibility, or dispute-resolution rules for agent-initiated purchases.
Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once
nonemoves PA Scoreimpact 20
The evidence describes single-item/cart-at-a-time flows (search, build a cart, checkout, track one order) and catalog pagination for browsing, but nothing documents a bulk operation primitive — e.g., adding many items to a cart in one call, batch checkout, or bulk order management — for an AI agent to act on many items at once.
Refunds disputes — stories about refunds disputes in this arenaDisputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes
nonemoves PA Scoreimpact 20
The evidence pack covers catalog, cart, checkout, order state, and order webhooks (which surface refunds/returns/cancellations), but nowhere mentions a dispute or chargeback API, evidence submission, dispute status tracking, or dispute outcome handling for agent transactions.
Fees economics — stories about fees economics in this arenaThe fees for agent-originated transactions are published — I can price agentic channels without asking sales
nonemoves PA Scoreimpact 20
The evidence pack thoroughly documents UCP's technical architecture (catalog, cart, checkout, orders, trust tiers) but contains no mention of transaction fees, take rates, commission percentages, or pricing terms for agent-originated sales — nothing addresses what a merchant would pay for agentic-channel transactions.
Showing the top 8 of 32 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 34 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs34 stories
- My agent can create and update a cart or order draft through a documented protocol call
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- Build against a versioned commerce protocol with a published schema and conformance or validation tooling
- My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
- Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
- Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell
- My agent can discover payable services and APIs through a published directory or discovery index
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Explore an interactive API reference with runnable examples
- Download a machine-readable API spec (OpenAPI or equivalent)
- Rely on versioned APIs with a documented deprecation policy
- Define rules that trigger actions automatically on events
- Orders are attributed to the originating agent and I can report on or filter transactions by agent
- I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
- Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout
- Do everything through the API that I can do in the UI
- My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmatically
- My agent can query the status and tracking of an order it placed, after the purchase
- Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
- At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration
- The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything
- Refunds on agent-placed orders can be initiated and tracked programmatically
- Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
Index docs8 stories
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- Build against a versioned commerce protocol with a published schema and conformance or validation tooling
- My agent can discover payable services and APIs through a published directory or discovery index
- Download a machine-readable API spec (OpenAPI or equivalent)
- Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
- At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration
- The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
ucp.dev7 stories
- Build against a versioned commerce protocol with a published schema and conformance or validation tooling
- My agent can discover payable services and APIs through a published directory or discovery index
- Point an agent at llms.txt or agent-oriented docs
- Download a machine-readable API spec (OpenAPI or equivalent)
- Rely on versioned APIs with a documented deprecation policy
- At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration
- The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything
Documentation docs3 stories
- Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
- The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
llms.txt2 stories
OpenAPI spec2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si -X POST https://catalog.shopify.com/api/ucp/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # full keyless handshakereproduced$ curl -si -X POST https://catalog.shopify.com/api/ucp/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # full [redacted]less handshake
HTTP/2 200
x-shopify-ucp-mcp-api-version: 2026-08-25
{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-06-18","capabilities":{"tools":{"listChanged":true},"prompts":{"listChanged":true},"resources":{"listChanged":true},"logging":{}},"serverInfo":{"name":"universal-ucp-mcp","version":"0.1.0"}}}
$curl -s -X POST https://hardware.shopify.com/api/ucp/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # merchant-storefront UCP endpointreproduced$ curl -s -X POST https://hardware.shopify.com/api/ucp/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # merchant-storefront UCP endpoint
{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-06-18","capabilities":{"tools":{"listChanged":true},"prompts":{"listChanged":true},"resources":{"listChanged":true},"logging":{}},"serverInfo":{"name":"universal-commerce","version":"0.1.0"}}}
$ucp catalog search --business https://hardware.shopify.com --set /query='card reader' && ucp cart create --business https://hardware.shopify.com --set "/line_items/0/item/id=<variant>" # real keyless cart via UCP on Shopify's own storereproduced$ ucp catalog search --business https://hardware.shopify.com --set /query='card reader' && ucp cart create --business https://hardware.shopify.com --set "/line_items/0/item/id=<variant>" # real [redacted]less cart via UCP on Shopify's own store
variant: gid://shopify/ProductVariant/47695038775318
## result.id
gid://shopify/Cart/hWNGq5dzsdbPBsyc61ZAKkYq?[redacted]=7e08cff65ba43ad1c8996ae4655ae03f
--
| ucp checkout create --business <business> --input '{"cart_id":"<cart_id>","line_items":[]}' | create checkout from this cart — substitute <cart_id> with result.id and <business> with the same business used for this cart; line_items is required and can be empty for cart conversion |
| ucp cart update --input-schema --business <business> | inspect the cart update schema before requesting shipping estimates — only send fulfillment fields the merchant advertises |
| ucp cart update <cart_id> --business <business> --input '{"line_items":[{"id":"<line_item_id>","item":{"id":"<item_id>"},"quantity":<quantity>}],"fulfillment":{"methods":[{"type":"shipping","line_item_ids":["<line_item_id>"],"destinations":[{"address_country":"<country>","address_region":"<region>","postal_code":"<postal_code>"}]}]}}' | request cart-stage shipping estimates with request-shaped line_items; returned cart fulfillment/totals are estimates |
$curl -s -X POST https://catalog.shopify.com/api/ucp/mcp -d '<tools/call search_catalog without agent profile>' # the documented agent-identity gate answers with a structured errorreproduced$ curl -s -X POST https://catalog.shopify.com/api/ucp/mcp -d '<tools/call search_catalog without agent profile>' # the documented agent-identity gate answers with a structured error
{"jsonrpc":"2.0","id":3,"error":{"code":-32001,"message":"UCP discovery failed","data":{"code":"invalid_profile_url","content":"Unable to fetch agent profile: Missing profile uri"}}}
$curl -s https://ucp.dev/llms.txt | head -3 # the open UCP spec indexreproduced$ curl -s https://ucp.dev/llms.txt | head -3 # the open UCP spec index # Universal Commerce Protocol (UCP) > The Universal Commerce Protocol (UCP) is a solution for enabling gen AI agents to make payments on behalf of users, safely, securely, and in a decentralized and privacy protecting manner. This protocol is a part of the broader ecosystem, which includes agentic protocols like A2A and MCP, and encompasses the global nature of payments.
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
15 of 24 testable claims verified · 2 contradicted → integrity 46/100
31 distinct capability claims found in Shopify Agentic Commerce’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
15
Verified
7
Unverified
2
Contradicted
12
Undersold
Verified (19)
“Official CLI offers commands to search the catalog, build carts, create checkouts, hand off buyers, and track orders”
“Global Catalog MCP lets agents search and discover products across the whole Shopify ecosystem, spanning multiple merchants”
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership requiredfullproof ↗
“Storefront Catalog MCP lets agents search a single merchant's own catalog to find and buy from that store”
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sellfullproof ↗
“Cart MCP lets agents build and iterate on a cart before the buyer commits to purchase”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Checkout MCP lets agents create/manage checkout sessions, convert carts to checkouts, and refer buyers to the merchant storefront”
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed orderpartialproof ↗
“Agent and shop capability profiles are intersected and negotiated down to a single active capability set per session”
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous botsfullproof ↗
“Tooling validates GraphQL queries, Liquid templates, and Extensions against Shopify schemas to catch errors early”
Build against a versioned commerce protocol with a published schema and conformance or validation toolingfullproof ↗
“MCP servers connect any AI assistant to real-time Shopify commerce data”
“Universal Cart API lets agents collect items from any merchant, Shopify or not, into one unified cart”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Assistant can translate a natural-language product request into the right UCP CLI command”
Operate the product with natural-language commandsfullproof ↗
“Products can be discovered across AI chat channels with checkout completed directly inside the chat”
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)partialproof ↗
“Catalog search returns machine-readable offer data (price, availability, variants) clustered by product ID across merchants”
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or servicefullproof ↗
“Every catalog MCP request must include a URL pointing to the agent's UCP identity profile”
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous botsfullproof ↗
“Agents can fetch a merchant's live input schema at runtime before composing a request payload”
Download a machine-readable API spec (OpenAPI or equivalent)partialproof ↗
“Checkout actions require authentication via short-lived JWT tokens minted from Dev Dashboard client credentials”
Issue scoped/least-privilege API credentials for an agentfullproof ↗
“Agents are classified into Token, Signed, or Anonymous identification tiers that gate access to sensitive tools”
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous botsfullproof ↗
“Order status lookups require a Token-tier agent with a specific read-orders JWT scope”
Issue scoped/least-privilege API credentials for an agentfullproof ↗
“The commerce protocol is co-developed by major industry players including Google, Amazon, Walmart, Target, and Microsoft”
At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integrationfullproof ↗
“Complete protocol spec, docs, and reference implementations are published in a public GitHub repository”
The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anythingfullproof ↗
Unverified (8)
“Order MCP lets agents fetch current order state including line items, fulfillment events, and post-purchase adjustments”
My agent can query the status and tracking of an order it placed, after the purchasefullproof ↗
“Shopify pushes UCP-shaped order webhooks to a registered endpoint whenever an agent-placed order has a committed change”
My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmaticallypartialproof ↗
“Carts carry agent attribution metadata such as referring domain, click IDs, and UTM parameters”
Orders are attributed to the originating agent and I can report on or filter transactions by agentpartialproof ↗
“Purchase completion is gated until checkout is ready, the buyer has reviewed the order, and payment credentials are collected”
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money movespartialproof ↗
“Checkouts needing buyer input or review escalate and hand off to the buyer via a continue_url, which the CLI can auto-open”
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money movespartialproof ↗
“Rate limits scale by identification tier, with checkout endpoints throttled more strictly than cart endpoints”
Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkoutpartialproof ↗
“Order webhook deliveries are HMAC-SHA256 signed and retried up to 8 times over 4 hours for reliability”
“Payments can flow through AP2 payment mandates and verifiable credentials rather than raw card data”
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card numberpartialproof ↗
Contradicted (2)
“Autonomous AI agents can transact on a user's behalf within pre-defined, verifiable boundaries”
Set per-agent spend caps and usage limits and revoke an agent's payment authority instantlynone
“Merchants remain Merchant of Record with full ownership of the customer relationship in agent-driven transactions”
The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risknoneproof ↗
Undersold (12)
My agent can discover payable services and APIs through a published directory or discovery indexfullproof ↗
Point an agent at llms.txt or agent-oriented docspartialproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Drive the product through a documented public APIfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Explore an interactive API reference with runnable examplespartialproof ↗
Rely on versioned APIs with a documented deprecation policypartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpointpartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Refunds on agent-placed orders can be initiated and tracked programmaticallypartialproof ↗
Claims outside our story set (2)
Real capability claims found in Shopify Agentic Commerce’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“CLI can initialize a local UCP profile for an agent”
source ↗“A store can be spun up from a simple prompt or pre-built template”
source ↗
Business model
Agent surfaces come with a Shopify store subscription (Basic $29 to Plus from $2,300/month) plus standard processing from 2.9% + 30¢; UCP catalog, cart, checkout, and order MCP endpoints carry no separate fee.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
