How AI Agents Like OpenClaw, Hermes, Grok and Meta's Muse Are Changing Online Shopping

Picture a Tuesday night at 11:40. (It's a made-up example, but every step is something these tools can do today.) A shopper in Denver texts her AI assistant on WhatsApp: "Find me a soy candle under $45 that arrives by Friday, and buy it." The assistant is OpenClaw, running on her own laptop. It opens a browser, signs in to your store with her saved login, reads the stock count on your product page and checks out in about 40 seconds. Your team never sees a person. They see an order.
Orders like that are about to get common. Salesforce's 2026 holiday retail predictions say 20% of holiday ecommerce traffic will come from AI chat agents, and 50% of shoppers say they've used an AI assistant somewhere in their buying journey.
Some agents drive a browser like that one. Others, such as ChatGPT, Google's Gemini, Amazon's Alexa and Meta's Muse, read your product feed (the file of product data you send to shopping channels) or buy through a checkout standard. All of them depend on three things you control: a stock count that's right, a price that still matches at checkout, and a complete feed. This guide explains how each agent buys, what the acronyms behind them mean, and what to fix first if you sell on more than one channel.
What's in this guide
- What "AI shopping agent" means in 2026
- The agents, one by one
- The protocols: ACP, UCP, MCP, WebMCP, AP2 and agent identity
- Side-by-side comparison tables
- What breaks for multichannel sellers (with a worked example)
- Readiness checklist by platform
- What to do this week
What "AI shopping agent" means in 2026
In 2025, "AI shopping agent" mostly meant a chatbot that suggested products. By late 2026 it means software that searches, compares and buys for a person, sometimes with a one-tap approval and sometimes with none. It now covers three quite different things.
- Open-source personal agents. OpenClaw and Hermes Agent run on the user's own machine or server. They shop the way a person does. They open a browser, sign in as the user and click through your checkout. You have no partnership with them and no way to see them coming.
- Platform assistants. ChatGPT, Gemini and Google's AI Mode, Alexa for Shopping, Meta's Muse and Microsoft Copilot read product data from feeds and protocols, then either send the shopper to your checkout or complete the order through a payment partner.
- Retailer-owned agents. A store builds its own agent on someone else's model. Gopuff's Go, running on xAI's Grok, is the clearest example.
The numbers explain why this matters before the holidays. Salesforce's forecast (published July 20, 2026) expects one in three ecommerce sites to have a site-specific shopper agent live by Cyber Week. It also found that 74% of shoppers trust product recommendations from AI chat.
Adobe's data points the same way. According to Digital Commerce 360's report on Adobe's May 2026 AI traffic data, AI-referred traffic to U.S. retail sites grew 138% year over year and 1,324% since October 2024. Those visitors converted 54% better than non-AI traffic. The same analysis found that 30–40% of content on high-value retail pages is still missed by AI.
One caution: a visit is not a sale. Most AI-referred shoppers still click through and buy on your site, which is why the rest of this guide spends as much time on your data as on the agents.
The agents, one by one
OpenClaw (formerly Clawdbot and Moltbot)
OpenClaw is an open-source personal assistant that runs on the user's own hardware and takes instructions through WhatsApp, Telegram, Slack, Discord, iMessage and other chat apps. The OpenClaw GitHub repository lists it under an MIT license held by the OpenClaw Foundation, an independent nonprofit. It had roughly 390,000 stars at the time of writing.
The project started as Clawdbot. TechCrunch's report on creator Peter Steinberger joining OpenAI says it was renamed Moltbot after Anthropic threatened legal action over the similarity to Claude, and later renamed OpenClaw. It went viral in late January 2026. On February 15, 2026, Steinberger joined OpenAI, and the project moved to a foundation that OpenAI said it would continue to support.
OpenClaw has no checkout protocol of its own, meaning no agreed technical route into a store's checkout. It shops by controlling a browser and through community add-ons called "skills", installed from a library called ClawHub. To your store, an OpenClaw purchase looks like a logged-in customer who clicks very fast.
The weak spot is ClawHub itself, which is open by default: anyone can publish a skill. Palo Alto Networks Unit 42's analysis of the OpenClaw skill marketplace (June 2026) documents the 341 malicious skills from the "ClawHavoc" disclosure and estimates about 17% of early skills carried malicious payloads. One skill it found, "money-radar", routed every recommendation through affiliate links that its operator could change remotely. That let the operator decide which products the agent "recommended".
What sellers should do. You can't integrate with OpenClaw, but you can make your store work for it. Keep product pages readable, keep stock status correct on the page, and don't depend on pop-ups or interstitials to show the price. When an agent's recommendation can be bought, being the brand a shopper asks for by name protects you more than any ranking trick. For the operations side, our guide to using OpenClaw for ecommerce operations covers safe setups.
Hermes Agent (Nous Research)
Hermes Agent is Nous Research's open-source, MIT-licensed agent, billed as "the agent that grows with you". The Hermes Agent GitHub repository describes agent-curated memory, skills it creates itself after complex tasks, connections to Telegram, Discord, Slack, WhatsApp, Signal and email, and support for MCP (a standard way for AI tools to connect to other software, explained below). It had about 249,000 stars in late September 2026.
TechCrunch's July 2026 report on Nous Research's funding talks says Hermes launched weeks after OpenClaw went viral. It also reports a cloud-hosted version priced at $20–$200 a month, and Nous in talks to raise at least $75 million at a $1.5 billion valuation.
Hermes shops two ways. It can call any MCP server you connect, so it can query a store or inventory system directly. It can also drive a browser. The Hermes browser automation docs list cloud browsers with stealth mode, residential proxies (home internet addresses that make traffic look like an ordinary household) and CAPTCHA solving (getting past the "prove you're human" puzzles), plus a mode that lets the agent "browse as you, with your existing logins and cookies." Nous hasn't announced a checkout integration with any retailer.
What sellers should do. With those features, your bot protection can't reliably tell a customer's Hermes agent from a scraper (a bot copying your prices and pages), and it may not flag either one. Treat anonymous automation as normal traffic that needs rate limits (a cap on how many requests one visitor can make per minute). You won't be able to spot every one. Give legitimate agents a signed identity route, covered in the protocols section below.
If you want to run Hermes on your own store's back office, start with our plain-English Hermes Agent guide. If you are choosing between the two open-source agents, our Hermes Agent vs OpenClaw comparison puts them side by side.
ChatGPT: from Instant Checkout to discovery and ads
ChatGPT's approach changed twice in twelve months, and the history explains where it is now.
- September 29, 2025: OpenAI's Instant Checkout and Agentic Commerce Protocol announcement let shoppers buy inside the chat. It came with ACP (Agentic Commerce Protocol), a set of rules co-developed with Stripe for how an AI assistant places an order with a store, released as open source. Merchants paid "a small fee on completed purchases" and kept fulfillment, returns and customer contact.
- March 24, 2026: In OpenAI's product discovery update, the company said it was "allowing merchants to use their own checkout experiences while we focus our efforts on product discovery." ACP became the way merchants send product feeds and promotions. Target, Sephora, Nordstrom, Lowe's, Best Buy, The Home Depot and Wayfair integrated for discovery, Shopify merchants joined through Shopify Catalog, and Walmart started building its own ChatGPT app.
- September 16, 2026: OpenAI's advertising update launched a ChatGPT Ads app in the Shopify App Store for U.S. merchants, available internationally from September 23 where ChatGPT Ads run. It also started testing "Sponsored Agents", clearly labeled conversations with an advertiser's own agent.
What sellers should do. In ChatGPT, your feed determines whether you're seen, and your checkout determines whether you convert. See how to get products into ChatGPT shopping for the feed side.
Google Gemini, AI Mode and Universal Cart
On May 19, 2026, Google's Universal Cart announcement introduced one cart that works across Search, Gemini, YouTube and Gmail. The cart monitors prices and stock levels on its own and checks out through Google Pay with brands including Nike, Sephora, Target, Ulta Beauty, Walmart, Wayfair, Fenty and Steve Madden.
The same post said checkout through UCP (Universal Commerce Protocol, Google and Shopify's shared rulebook for agent shopping) would expand to Canada and Australia, then the U.K. It also described AP2 (Agent Payments Protocol) as the way agents buy within user-set spending limits and merchant restrictions, leaving "a permanent digital paper trail." Google said U.S. rollout across Search and the Gemini app would start in summer 2026. We couldn't confirm how far that rollout had reached by late September.
What sellers should do. A cart that watches stock and price for the shopper will notice your restock or price drop before your email list does. Your Google Merchant Center feed (the product list Google Shopping reads) and your live stock need to agree. See what Google and Shopify's UCP checkout expects from your store.
Amazon: Alexa for Shopping (Rufus merged) and Buy for Me
In May 2026 Amazon replaced Rufus with Alexa for Shopping. Amazon's Alexa for Shopping announcement says it's free to every signed-in U.S. customer, with no Prime membership or Echo required, and that Rufus "helped over 300 million customers in 2025 research, compare, and buy products."
Two features matter most for sellers:
- Scheduled Actions: conditional buying, such as "Add this sunscreen to my cart if the price drops to $10 and I haven't purchased it in the last 2 months."
- Buy for Me: for eligible products, the agent "handles the entire purchase on your behalf using your primary address and credit card," including on other retailers' sites.
What sellers should do. On Amazon, your listing content is what the agent reads. Off Amazon, a brand's own site can receive orders that Amazon's agent placed. Our breakdown of why most listings aren't ready for Amazon's auto-buy covers the listing fixes.
Meta AI, Muse Spark and the Muse agent
Meta's Muse Spark announcement (April 8, 2026) introduced the first model from Meta Superintelligence Labs, built to power Meta AI. It added a shopping mode that searches Facebook Marketplace listings alongside options from across the web, draws on "styling inspiration and brand storytelling" across Meta's apps, and lets users tag a brand or creator to browse their products.
At Meta Connect on September 23, 2026, the company went further. TechCrunch's roundup of Meta's Muse agent announcements reports partnerships with Stripe and Shopify. According to chief AI officer Alexandr Wang, Muse can access the entire Shopify product catalog and use Shop Pay, with PayPal also supported. Retail connectors include Best Buy, Gap, Sephora, Walmart and Wayfair. Mark Zuckerberg said Meta expects to "profit by taking a small fee from transactions."
What sellers should do. On Meta, your Instagram and Facebook content now feeds product discovery, and your Shopify catalog may be what Muse buys from. Our guide to the product data Meta AI shopping reads covers both. For the Muse agent itself, including why Amazon blocked it, read our seller's guide to Meta's Muse agent.
xAI Grok
We found no general-purpose Grok checkout that we could verify. Grok's confirmed shopping role is inside another retailer's app. xAI's post on powering Gopuff's Go agent (June 2026) says Grok's text, voice and image models power Go, which builds "personalized carts before you even open the app, using past preferences and external signals like the weather." Go is live in the Gopuff iOS and Android apps.
What sellers should do. This is the retailer-owned model: your own agent, running on a rented model. With Salesforce expecting one in three ecommerce sites to run one by Cyber Week, it's worth deciding whether you need one. Whatever you decide, an agent that builds carts ahead of time needs stock data it can trust. Our Grok Bot guide for online stores covers xAI's always-on AI teammates and where they fit in store work.
Perplexity Comet and the Ninth Circuit ruling
Amazon sued Perplexity over the AI assistant in its Comet browser, which shops Amazon.com for a signed-in user. On August 4, 2026, the Ninth Circuit appeals court threw out the temporary order (a preliminary injunction) that had blocked Perplexity's agent from Amazon. Cooley's analysis of the Amazon v. Perplexity decision says the court held that the user, not Perplexity, "accessed" Amazon's computers under the CFAA (the Computer Fraud and Abuse Act, the main U.S. anti-hacking law).
The ruling has limits. It came at an early stage of the case, before a full trial, and covers only the federal and California anti-hacking statutes. It leaves contract, tort and terms-of-service claims open, and the court called the question fact-specific.
What sellers should do. Don't assume anti-hacking law will stop agents that a shopper directs. If you want to limit agents, you'll have to do it through your terms and technical controls.
Microsoft Copilot Checkout
Microsoft's Copilot Checkout announcement (January 8, 2026) put in-chat purchasing live in the U.S. on Copilot.com, built with PayPal, Shopify and Stripe. Merchants stay the merchant of record, which means the sale, the refund and any dispute are legally theirs. Shopify merchants were enrolled automatically after an opt-out window.
The protocols: ACP, UCP, MCP, WebMCP, AP2 and agent identity
A protocol here is a published set of rules that lets an agent and a store talk without a custom deal between them. They get confusing because they sit in different layers and several cover more than one. In plain English, an agent asks four questions in order, and each layer answers one:
LAYER WHAT THE AGENT ASKS STANDARDS
-------------------------------------------------------------------------------
1. Discovery "What do you sell? Is it in stock? Product feeds (ACP feed, Merchant
What does it cost?" Center, Shopify Catalog),
UCP catalog + /.well-known/ucp
|
v
2. Tools "Let me search, build a cart, MCP (server-side),
read your return policy." WebMCP (in the shopper's browser)
|
v
3. Checkout "Create this order, at this price, ACP checkout, UCP cart /
shipped here." checkout / order
|
v
4. Payment and "Prove a human approved this, and AP2 mandates, Stripe Shared
identity prove I'm a real agent." Payment Token, Visa TAP,
Mastercard Agent Pay, Web Bot Auth
-------------------------------------------------------------------------------
UNDER ALL FOUR: one live count of stock and price across every channel
Every layer reads from that last row. If your stock and prices differ by channel, every protocol above passes the error along faster.
MCP (Model Context Protocol)
MCP is the general standard agents use to call tools, such as "look up stock" or "create an order", in other software. Anthropic created it, and on December 9, 2025 it moved to neutral governance. The Linux Foundation's announcement of the Agentic AI Foundation lists MCP as a founding project alongside Block's goose and OpenAI's AGENTS.md. It counted more than 10,000 published MCP servers, and its platinum members include AWS, Anthropic, Google, Microsoft and OpenAI.
For sellers, MCP matters in two ways. Hermes and similar agents use it to reach your systems, and both UCP and ACP now accept it as a way to carry their messages. If you're new to it, start with what MCP is and how it works. If you want agents to ask for your live stock count instead of copying it off your pages, an inventory MCP server is the direct route.
WebMCP (tools in the browser tab)
WebMCP brings MCP-style tools into the web page itself, so an agent in the shopper's browser can call "search products" or "add to cart" instead of guessing from screenshots. The WebMCP specification was published as a Draft Community Group Report on September 26, 2026 by the W3C Web Machine Learning Community Group, with editors from Microsoft and Google. The W3C, the body that sets web standards, hasn't made it an official standard yet.
In plain English: your page announces a named tool, what it needs and what it returns, and the agent calls it like a button. For developers, the API centers on document.modelContext.registerTool(). A simplified sketch of a stock-check tool:
// Illustrative sketch — the WebMCP API is a draft and may change
document.modelContext.registerTool({
name: "check_stock",
description: "Return live stock and price for a SKU",
inputSchema: {
type: "object",
properties: { sku: { type: "string" } },
required: ["sku"]
},
execute: async ({ sku }) =>
fetch("/api/stock/" + encodeURIComponent(sku)).then(r => r.json())
});
Shopify has already shipped it. Shopify's WebMCP changelog entry (announced August 5, effective August 21, 2026) says every Liquid storefront (the standard Shopify theme system) and the Hydrogen developer preview (Shopify's framework for custom-built stores) now expose search_catalog, get_product, show_variant, get_cart, update_cart, proceed_to_checkout, manage_orders and search_shop_policies_and_faqs, among others. There's "nothing to install or configure". For now, only Chromium-based browsers such as Chrome and Edge support it, and only as a time-limited trial.
ACP (Agentic Commerce Protocol)
ACP launched with ChatGPT Instant Checkout in September 2025. OpenAI and Stripe maintain it, and the ACP specification repository lists it as beta under the Apache 2.0 open-source license. The latest stable version, 2026-04-17, adds cart, feed, orders, sign-in and MCP. At launch, OpenAI said Stripe's Shared Payment Token, a stand-in for the shopper's card that only works for one merchant and amount, lets stores on other payment processors take part without switching.
Since OpenAI's March change, ACP's main job in ChatGPT is discovery: feeds and promotions. It still defines checkout, and ACP support is worth having for any agent that implements it.
UCP (Universal Commerce Protocol)
UCP launched on January 11, 2026. The UCP announcements log shows how quickly its governance grew:
- April 24: Amazon, Meta, Microsoft, Stripe and Salesforce joined the technical committee.
- April 28: Stripe joined Google and Shopify on the governing council.
- July to September: food, lodging and payments technical councils formed. The payments council includes Adyen, PayPal, Stripe and Coinbase.
- August 25: version v2026-08-25 added 3DS2 (the card check where a bank asks the buyer to confirm a payment), stricter request rules, separate version numbers for each feature and support for grocery orders.
The UCP specification overview defines catalog, cart, checkout, order and identity-linking capabilities over REST (the ordinary way web services talk), MCP and A2A (Google's agent-to-agent protocol). Agents find a business through a small profile file at /.well-known/ucp. For the ACP-versus-UCP decision, see our ACP and UCP protocols guide and how UCP support works.
AP2 and A2A
AP2 (Agent Payments Protocol) is Google's layer for proving that a human authorized a purchase. In the Universal Cart announcement, Google describes it as letting agents buy within user-defined spending limits and merchant restrictions, with a verifiable record between the parties. A2A handles messages between agents, and UCP accepts it as a way to carry its messages. You'll rarely implement either yourself. Your payment provider and platform do that. What you control is keeping the cart price stable so the approved amount matches the charged amount.
Agent identity: Visa TAP, Mastercard Agent Pay and Web Bot Auth
This layer answers the question every fraud team is asking: is this a real agent, and is it browsing or buying? Cloudflare's post on securing agentic commerce with Visa and Mastercard explains that Web Bot Auth attaches a cryptographic signature to each agent request, a bit like a tamper-proof ID badge. Visa's Trusted Agent Protocol (TAP) and Mastercard Agent Pay both use it to prove an agent is who it says it is. They add a tag saying whether the agent is browsing or paying, plus a one-time code so nobody can copy and replay the request. Merchants can then "set the rules for agent interactions on their site."
One last, optional item is llms.txt, a proposed plain-text summary file at your site root. It's harmless to publish, but none of the checkout protocols above requires it. Put that effort into your feed first.
Side-by-side comparison tables
The agents
| Agent | Maker | Open or closed | How it buys | Protocols / rails | Status, Sept 2026 |
|---|---|---|---|---|---|
| OpenClaw | OpenClaw Foundation (created by Peter Steinberger) | Open source (MIT) | Browser control and ClawHub skills, using the user's own accounts | No commerce protocol required | ~390K GitHub stars; skill-supply-chain risk documented |
| Hermes Agent | Nous Research | Open source (MIT) | Browser (stealth, logged-in profiles) or any connected MCP server | MCP | ~249K stars; hosted tiers $20–$200/mo |
| ChatGPT | OpenAI | Closed | Discovery in chat, checkout on the merchant's site or app | ACP feeds, Shopify Catalog | Instant Checkout scaled back (Mar); Ads app for Shopify (Sep) |
| Gemini / AI Mode | Closed | Universal Cart, Google Pay checkout | UCP, AP2 | Announced May 19; U.S. rollout from summer | |
| Alexa for Shopping | Amazon | Closed | Amazon catalog, Scheduled Actions, Buy for Me on other sites | Amazon's own stack | Live for U.S. customers since May |
| Muse / Meta AI | Meta Superintelligence Labs | Closed | Shopping mode, Shopify catalog, Shop Pay, retailer connectors | Shopify, Stripe, PayPal | Muse Spark since Apr 8; agent shopping expanded Sep 23 |
| Grok (via Gopuff Go) | xAI / Gopuff | Closed model in a retailer's app | Pre-built carts inside Gopuff | Retailer-owned | Live in the Gopuff app since June |
| Perplexity Comet | Perplexity | Closed | Browser assistant acting in the user's session | None required | Amazon injunction vacated Aug 4 |
| Copilot Checkout | Microsoft | Closed | In-chat checkout | PayPal, Stripe, Shopify | Live in the U.S. since Jan 8 |
The protocols
| Protocol | Backers | Layer | Status, Sept 2026 | What the merchant must do |
|---|---|---|---|---|
| ACP | OpenAI, Stripe | Feed + checkout | Beta; stable 2026-04-17 | Send a complete, current product feed; support ACP checkout if an agent you sell through uses it |
| UCP | Google, Shopify, Stripe (council); Amazon, Meta, Microsoft, Salesforce (tech committee) | Discovery → cart → checkout → orders | v2026-08-25 | Publish a /.well-known/ucp profile (or let your platform do it); keep the Merchant Center feed accurate |
| MCP | Agentic AI Foundation (Linux Foundation) | Tools | 10,000+ servers (Dec 2025) | Expose stock, price and order status through a scoped MCP server if you want agents to query rather than scrape |
| WebMCP | W3C Web ML Community Group; Google and Microsoft editors | Tools in the browser | Draft report (Sep 26); Chromium origin trial | Shopify Liquid: nothing. Others: optional tools for search, cart and checkout |
| AP2 / A2A | Google and partners | Payment authorization / agent messaging | Used by Universal Cart | Handled by your payment provider; keep the cart price stable through checkout |
| Visa TAP, Mastercard Agent Pay, Web Bot Auth | Visa, Mastercard, Cloudflare | Agent identity + payment | Live programs | Configure bot management to recognize signed agents rather than blocking all automation |
What breaks for multichannel sellers when agents buy
None of these agents cares about your theme. They care about whether the data they read matches what happens at checkout. For a seller on three or more channels, five things break first.
1. Stale stock becomes agent-cancelled orders
A human who finds an item out of stock at checkout shrugs and moves on. An agent that bought through Buy for Me or a scheduled price trigger reports to its user that the order failed, and you don't get to explain. If Amazon, Shopify and TikTok Shop each show stock that was correct 15 minutes ago, agents buy the same last units on all three.
2. Price mismatches between feed, page and checkout
OpenAI's feed rules are blunt: OpenAI's product feed specification tells merchants to "keep current price and availability up to date." AP2-style approvals make this stricter, because they record the exact items and price the human approved. If a sale ends between cart and checkout, expect the agent to stop and ask again or drop the order.
3. Missing feed attributes
That same spec requires an item ID per variant, title, description, URL, brand, seller name, image, availability and price. It also expects a GTIN (the barcode number, such as a UPC) or MPN (the manufacturer's part number) for Google-compatible feeds and availability dates for preorders and backorders. Return fields (accepts_returns, return_deadline_in_days, return_policy) are optional, but agents answer "can I return this?" from them. Running your export through a product feed validator catches most of these gaps in minutes. Keeping one feed source for every channel is what the product feed export in an order management system (OMS) is for.
4. Bot traffic you can't classify
Stealth browsers, residential proxies and CAPTCHA solving are listed features of open-source agents, so plan for them as normal traffic. Expect more sessions with no analytics history, faster add-to-cart, and checkout attempts from ordinary residential IPs. Separate signed agents from unsigned ones. Rate-limit per customer account as well as per IP address. Label agent orders in reporting so you can measure them.
5. Returns, disputes and manipulated recommendations
Under ChatGPT's original checkout, Copilot Checkout and UCP, the merchant stays merchant of record. Returns and chargebacks come to you. Plan for the dispute where a shopper says "my agent bought the wrong thing," and keep order-source data that shows what was requested. The Unit 42 affiliate-injection finding is a reminder that some "recommendations" were bought. If your margins depend on being recommended, they depend on the agent playing fair.
Worked example: a price drop on the last 40 units
Example (hypothetical): Say you sell a candle at $48 on Shopify, Amazon and TikTok Shop from one warehouse holding 40 units. Each channel's stock updates every 15 minutes. At 9:00 a.m. you drop the price to $38.
Price-watching agents react within minutes: Alexa Scheduled Actions, carts tracking price and stock, and human shoppers using assistants. In the first 15-minute window before the next sync, you get:
| Channel | Orders placed | Stock the channel showed |
|---|---|---|
| Amazon | 22 | 40 |
| Shopify (incl. agent checkouts) | 19 | 40 |
| TikTok Shop | 7 | 40 |
| Total | 48 | 40 on the shelf |
That's 48 − 40 = 8 oversold orders. At $38 each, that's 8 × $38 = $304 in revenue you have to refund, plus eight cancellations against your seller metrics. It also means eight agents telling eight shoppers your store failed them.
Now run the same morning with one shared stock pool that syncs in under 5 seconds. In plain English: the shorter the gap between updates, the fewer orders can sneak in on stale numbers. Demand was 48 orders in 15 minutes, or 3.2 orders per minute. The most that can arrive inside a 5-second sync window is 3.2 × (5 ÷ 60) ≈ 0.27 orders. That's less than one unit of exposure, so you can cover it with a 1–2 unit buffer per marketplace. You still sell all 40 units. The other 8 shoppers see "out of stock" and nobody gets a cancellation. A safety stock calculator helps size that buffer from your real sales velocity.
Nventory runs one shared pool like that behind Shopify, Amazon, TikTok Shop and your other channels. Price-watching agents make the gap between syncs matter more than it did a year ago.
Readiness checklist by platform
Shopify
- WebMCP tools are already live on Liquid themes. Because
search_shop_policies_and_faqsexposes your policies, rewrite your return, shipping and warranty pages so an agent can quote them accurately. - Decide deliberately about Copilot Checkout. Shopify merchants were auto-enrolled after an opt-out window.
- Shopify Catalog feeds ChatGPT discovery, so fill in product fields, variants, GTINs and images in Shopify itself.
- If you also sell on Amazon, Walmart or TikTok Shop, make sure Shopify's available quantity is the shared pool, not a separate count. Otherwise every agent reading Shopify sees stock that has already sold elsewhere. Our Shopify integration works this way.
- Consider the ChatGPT Ads app only after the feed is clean. Paid placement on a bad feed sends buyers to cancellations.
WooCommerce
- According to WooCommerce's agentic commerce page, MCP shipped in WordPress 6.9 and WooCommerce 10.3 with nine built-in abilities. ACP (through Stripe's Agentic Commerce Suite) and UCP are listed as "coming soon".
- For UCP readiness, WooCommerce's own advice is to sync your catalog to Google Merchant Center with the Google for WooCommerce extension and keep your structured data correct.
- If you use Stripe, install the official Stripe extension so you can upload your catalog to Stripe's suite when it goes live.
- WebMCP is optional on WooCommerce today. If you add it, start with read-only tools (search, stock check) before cart actions.
- Stock drift between WooCommerce and marketplaces is the most common failure. Check your WooCommerce inventory sync interval before Black Friday.
Marketplace sellers (Amazon, Walmart, TikTok Shop, eBay)
- Alexa for Shopping answers from your listing. Fill in attributes, bullets and images as if the reader were a parser, because it is.
- Scheduled Actions mean a price drop can release a burst of pre-set purchases. Stage promotions with stock buffers, not all at once.
- Marketplace listings and your own site share one warehouse, so they need one stock pool. Send each order to the location that has the item and can ship it, which is the job of order routing.
- Watch cancellation and late-shipment metrics weekly through Q4. Agent-driven demand spikes show up there first.
If you want a quick read on where you stand across channels, the multichannel readiness assessment takes about ten minutes.
What to do this week
- Pick your best-selling SKU (one product variant you track, such as a 12 oz vanilla candle) and write down its stock on every channel at the same minute. If the numbers differ, fix that first.
- Run your product feed through a validator and fill in any missing GTIN, MPN and return-policy fields.
- Change one price and time how long it takes to show on each channel and in each feed. Anything over a few minutes needs fixing before Black Friday.
- Rewrite your return, shipping and delivery pages in plain sentences an agent can quote: the return window, who pays return postage and delivery times by region.
- Ask whoever runs your bot protection to allow signed agents (Web Bot Auth, Visa TAP, Mastercard Agent Pay) and to rate-limit per account, not only per IP address.
- Add "AI agent" as its own order source in your reports so you can see conversion, cancellations and returns for those orders.
- Read why some CFOs forecast zero agentic revenue before you spend money on AI channels.
If your stock count lives in three spreadsheets and two apps, an agent will find the gap before you do. Nventory's Free plan connects one channel with unlimited orders and no card, so you can start one shared stock pool and compare plans when you add channels.
Frequently Asked Questions
Both. The big-retailer deals get the headlines, but open-source agents like OpenClaw and Hermes shop any site a browser can open, using the shopper's own logins and card. On Shopify, every Liquid storefront already exposes WebMCP tools, and Shopify merchants were auto-enrolled in Copilot Checkout after an opt-out window. A small store doesn't need a partnership to get agent orders. It needs stock and prices that are right when the agent checks.
ACP (Agentic Commerce Protocol) is maintained by OpenAI and Stripe and grew out of ChatGPT's checkout. Since March 2026 ChatGPT mainly uses it for product feeds and discovery. UCP (Universal Commerce Protocol) is governed by Google, Shopify and Stripe and covers catalog, cart, checkout, orders and identity linking, discovered through a /.well-known/ucp profile. They overlap in scope. Which one you need depends on which AI surfaces you sell through.
If you're on a Shopify Liquid theme, no. Shopify turned on search, cart, checkout and policy tools for every Liquid storefront in August 2026. On WooCommerce or a custom site, WebMCP is optional for now. The spec is a draft community report and browser support is limited to a Chromium origin trial. Get your feed, stock and checkout right first. They matter to every agent, including ones that never use WebMCP.
Blocking all of them also blocks real customers who send an agent to buy for them. The Ninth Circuit's August 2026 Perplexity ruling suggests anti-hacking law may not stop agents a user directs, so any blocking comes down to your own terms and bot controls. A better default is to separate signed agents (Web Bot Auth, Visa TAP, Mastercard Agent Pay) from anonymous scrapers and rate-limit the rest.
Only with care. ClawHub is open by default, and researchers found hundreds of malicious skills in early 2026, including one that quietly rewrote recommendations into affiliate links. If you use OpenClaw or Hermes for operations, give it a scoped, read-mostly API key, install only skills you've reviewed, keep payment credentials out of reach, and send it through an MCP server that limits which tools it can call.
Start with the fields that decide whether an agent can buy at all: a stable item ID per variant, title, price, availability, image, URL, brand and seller name. OpenAI's feed spec requires all of these. Then add GTIN or MPN, return-window and return-policy fields, and availability dates for preorders and backorders. Availability and price do the most damage when they're wrong, because they're the fields that change hourly.
In most cases, you do. ChatGPT's original checkout, Copilot Checkout and UCP all keep the merchant as merchant of record, so fulfillment, returns and disputes run through your normal systems. Record where each order came from, keep the agent's order confirmation data, and write a return policy an agent can read and quote accurately. Treat agent orders like any other channel's orders, with their own label in reports.
