# Agentic checkout, explained for Shopify merchants

What happens when an AI assistant buys for a shopper, what ACP, UCP and payment tokens cover, and what you still control. Updated 2026-10-08.

## The short version

In agentic checkout, a shopper asks an AI assistant to find and buy something, and the assistant talks to your store on their behalf. Two open protocols describe that conversation. The Agentic Commerce Protocol (ACP) was developed by Stripe and OpenAI and is published under the Apache 2.0 license [1]. Shopify builds on the Universal Commerce Protocol (UCP) and its own MCP servers [2]. Stripe supports both for sellers [3].

The protocols move the cart, the checkout and the payment credential. They do not move responsibility. Under ACP, the business stays the merchant of record and keeps control of what it sells, how products are shown and how orders are fulfilled [1]. OpenAI states that it "is not the merchant of record" [4]. Your prices, stock, shipping zones, discount rules and return policy still decide what the shopper gets.

## What can go wrong

**The assistant buys something you cannot ship.** If your shipping zones, stock or variant data are wrong, an assistant can build a cart that fails at the last step. Out-of-stock variants (X-05) and countries you do not serve (X-06) are the common cases.

**The assistant tries a discount it found elsewhere.** A code from an old forum post or a planted page is just text to an assistant. Your discount rules are the only thing that decides whether it applies (X-03, X-04).

**The total goes over what the shopper allowed.** In OpenAI's delegated payment spec, each payment credential carries an allowance. `max_amount` is the most the method can be charged, `expires_at` sets an expiry, and the reason `one_time` means the credential "should not be used again for other flows" [5]. Stripe's shared payment tokens work the same way. Each token has usage limits for currency, maximum amount and expiry, and the agent sets the maximum to match the transaction total [6]. If your shipping or tax changes the total after the token is issued, the charge can fail (X-01, X-02).

**Questions after the order.** The shopper may come back through the assistant to ask about delivery, returns or cancelling (X-07, X-09, X-10). OpenAI's key concepts page lists the merchant's checkout duties. It does not mention returns or customer support [4]. Plan for those questions to reach your normal support channels.

## What to set up

**1. Know which channels are on.** Shopify's agentic storefronts let shoppers find and buy your products in ChatGPT, Google AI Mode and Gemini, Microsoft Copilot and Meta surfaces. Shopify says the feature "is active by default for eligible stores." You choose channels under **Sales channels > Agentic** in the admin, and you must accept Shopify's supplemental terms [7]. Open that page and decide channel by channel.

**2. Know where checkout happens.** On Shopify, it depends on the channel. In ChatGPT, shoppers buy on your online store checkout, opened in ChatGPT's in-app browser or a new tab. In Google, Microsoft and Meta channels, shoppers can buy inside the channel through Shopify-powered checkout if direct checkout is turned on [7]. Shopify's developer docs say agents usually hand the buyer to the merchant storefront to pay, and agents in higher trust tiers can complete checkout directly [2]. Your checkout settings, payment methods and fraud tools apply in both cases.

**3. Clean the data the assistant reads.** Products reach these channels through Shopify Catalog, the Google & YouTube channel or Google Merchant Center [7]. Fix variant names, stock, weights and prices before you worry about anything else. An assistant cannot choose the right size if your options say "Option 1."

**4. Write discount rules that stand on their own.** Set minimums, end dates, usage limits and product eligibility on every code. Assume any code you have ever shared will be tried by an assistant.

**5. Set quantity limits where you need them.** If a product is limited to two per customer, enforce it in your store, not in your product description (X-08).

**6. Decide your accept or decline rules.** ACP lets a business accept or decline transactions by agent, by transaction or with its own logic [1]. Under OpenAI's flow, the merchant validates the order, sets fulfillment options and tax, checks risk signals, and accepts or declines [4]. If you run a custom integration, write down which orders you will refuse.

**7. Tag and watch agent orders.** On Shopify, these orders appear in your admin with channel or referrer attribution, and you keep the customer relationship [7]. Build a saved view for them. Shopify's order tools let agents fetch order state, and order webhooks report fulfillment, returns, refunds and edits [2]. Your order status pages need to be accurate, because the assistant may read them back to the shopper.

## How to check it

Use a test product and a small budget. Ask an assistant on each channel you have turned on to do the following, and write down what happens:

- Buy one item under a set budget, then one that goes over it (X-01, X-02).
- Apply a valid code, then a code you never issued (X-03, X-04).
- Buy a variant you have marked out of stock (X-05).
- Ship to a country you do not serve (X-06).
- Buy more than your quantity limit (X-08).
- Ask about your return window before buying (X-07).
- After buying, ask for order status, then ask to cancel (X-09, X-10).

For each one, check the order in your admin. Look at the channel attribution, the total charged, the discount applied and the customer details. Then cancel and refund the test orders.

If you use Stripe for an ACP integration, read the token on each test order. Stripe returns the token's `usage_limits` and a limited view of the card, such as brand and last four digits. A `shared_payment.granted_token.deactivated` event tells you when a token was used, expired or revoked [6].

## Further reading

- The ACP site links to the spec and its GitHub repository [1].
- OpenAI's key concepts page shows the order flow from the assistant's side [4].
- Shopify's agentic storefronts page lists eligibility and channel settings [7].

## Sources

1. [Agentic Commerce Protocol](https://www.agenticcommerce.dev/), Agentic Commerce Protocol (agenticcommerce.dev), accessed 2026-10-08
2. [Agentic commerce (agents)](https://shopify.dev/docs/agents), Shopify (shopify.dev), accessed 2026-10-08
3. [Agentic commerce](https://docs.stripe.com/agentic-commerce), Stripe, accessed 2026-10-08
4. [Key concepts (Agentic Commerce)](https://developers.openai.com/commerce/guides/key-concepts.md), OpenAI, accessed 2026-10-08
5. [Delegated Payment Spec](https://developers.openai.com/commerce/specs/payment.md), OpenAI, accessed 2026-10-08
6. [Shared payment tokens (sellers)](https://docs.stripe.com/agentic-commerce/concepts/shared-payment-tokens.md?agent-seller=seller), Stripe, accessed 2026-10-08
7. [Agentic storefronts](https://help.shopify.com/en/manual/online-sales-channels/agentic-storefronts), Shopify Help Center, accessed 2026-10-08

Source page: https://commerceaiagents.com/guides/agentic-checkout-explained
