Merchant and global catalogs, products, variants, store policies, carts, checkout sessions, buyer context, agent-originated orders, fulfillment events, post-purchase adjustments, customer accounts, and preferences.
Shopify
Included as a hosted agentic-commerce surface spanning merchant and global catalog discovery, carts, checkout, agent-originated orders, and authenticated customer accounts with explicit transaction handoff.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
Search merchant catalogs and policies; inspect carts and checkouts; fetch eligible agent-originated orders; and retrieve authenticated customer account, order, and preference information.
Create, replace, or cancel carts; create and update checkout sessions; complete eligible checkouts or hand buyers to the merchant; and manage supported customer-account preferences.
Catalog and cart access can be anonymous, signed, or token-authenticated. Checkout requires a signed request or token; order reads require a scoped Global API JWT; customer accounts use OAuth PKCE.
Shopify remains merchant of record, escalates unsupported purchases to storefront checkout, requires agent-profile capability negotiation, and limits customer/order data through scopes, origin rules, and protected-data approval.
Storefront cart tools are maintained only through August 31, 2026. UCP cart updates replace full contents; checkout is more tightly rate-limited, and order reads exclude cross-channel history.
First-party access
Documented surfaces
Agent access
MCP support
Support: Official MCP server
Read scope: Expose catalog, policy, cart, checkout, eligible order, and customer-account reads as separate contexts; preserve merchant, buyer identity, agent origin, authorization tier, and freshness.
Write scope: Limit actions to cart and checkout lifecycle operations plus documented account preferences. These servers do not establish general Admin API authority over products, inventory, discounts, refunds, or fulfillment.
Authentication: Use no credential, a signed request, or a Shopify-issued bearer token according to the UCP tier. Customer Accounts separately uses authorization-code OAuth 2.0 with PKCE.
Approval boundary: Confirm full cart replacement, cart cancellation, checkout creation or update, buyer and fulfillment details, totals, merchant handoff, and any direct completion before advancing purchase state.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Shopify ships them.
Single-platform patterns
- Shoppable campaign and assisted-commerce interface
- Revenue reconciliation console
- Commerce operations cockpit
- Customer-resolution workbench
Multi-platform compositions
- Shopify + CRM or support system: revenue reconciliation console
- Shopify + lifecycle platform + analytics or finance system: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
6 recorded sources
Shopify exposes multiple purpose-specific MCP surfaces. The storefront endpoint is store-specific and often unauthenticated, while customer-specific actions require the Customer Accounts server. Distinguish all…
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 12, 2026
Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.
First-party developer documentation or platform overview.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Reverified the named access facet exactly as bounded by the reviewed first-party record.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 12, 2026
Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party webhook, event, SDK, embedded-app, or extension documentation.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.