Shopify agent storefront check
For D2C Shopify stores that want evidence of what an AI shopper actually receives. €1,900 plus VAT, fixed scope, delivered in 48 hours from a written kickoff.
Shopify stores now meet shopping agents through three separate interfaces. They are related, and an agent does not always get the same answer from each. This check tests one live store across all of them and reports what an agent receives on each, with the evidence attached.
A general agent-readiness audit is not a prerequisite. This check stands on its own, and it is not a step inside the audit.
Price and timing
€1,900 plus VAT. Fixed scope. 48 hours.
The 48-hour clock starts at the agreed written kickoff, once the preflight, payment and merchant evidence are complete. No response is required from you during the delivery window.
If the public preflight cannot establish an observable agent-commerce surface suitable for controlled testing, the engagement is not sold and nothing is invoiced.
If the 48-hour package of four deliverables is not sent within 48 elapsed hours, the fee is refunded. The retest is the fifth deliverable. It runs on its own 14-day window.
All work is asynchronous and delivered in writing.
The three surfaces
Every one of these is tested in the same session, against the same products, so a difference between them is visible rather than inferred.
- Browser WebMCP tools inside the shopper's live storefront tab.
- Shopify-hosted Storefront and UCP MCP endpoints.
- Shopify Catalog and Agentic storefront channels.
What the check answers
Within 48 hours you receive an evidence-backed status for each of the following, including anything restricted, unavailable or not testable.
- Which agent tools were observed and functional in the tested session.
- Whether product, variant, price, currency and availability data agree across the tested surfaces.
- Whether an agent can build the intended anonymous cart.
- Where the buyer is handed off to checkout.
- Whether your Shopify Agentic channel settings match what your team intended.
- Which product-data, theme, app or configuration changes should be made first.
Fixed scope
The scope is fixed before the clock starts, and it does not move during delivery.
The check covers: - One Shopify store. - One market, language and currency. - Up to three named product and variant pairs. - Up to five real buyer searches. - One clean, supported Chromium browser session. - Browser WebMCP. - Storefront and UCP MCP. - Shopify Agentic settings and a Catalog search preview. - One anonymous browser cart with one permitted checkout navigation, plus one separate remote UCP Cart lifecycle that stops before Checkout MCP. - One retest of up to two corrected items within 14 days.
No Shopify Admin password is requested. The check uses public storefront surfaces, an isolated shopper session, and settings evidence you provide as redacted screenshots or a short screen recording.
No customer details are entered. No payment is submitted and no order is placed.
What you receive
Five written deliverables. The first four are sent as one package within 48 hours. The fifth is the retest, and it follows within 14 days.
- Three-surface map. What is present, restricted, unavailable or not tested on browser WebMCP, remote MCP and Agentic channels.
- Product truth matrix. The tested title, variant, price, currency, availability and policy facts across surfaces.
- Buyer-journey evidence. The tool, the input, the observed result, the cart state and the exact stop before payment or order creation.
- Prioritised correction plan. Up to five specific changes, their owner and a ready acceptance check.
- Retest. One verification of up to two corrected items within 14 days.
Implementation of the corrections is not included. Your team can act on the plan directly, or the corrections can be bought separately as implementation days.
What this is not
This is an operational storefront check. It is not a penetration test. It is not a Shopify, MCP, WebMCP or UCP certification either.
A documented Shopify tool or public endpoint is not treated as a vulnerability. Browser WebMCP does not establish remote access. Checkout navigation is not reported as payment completion. Ranking or product placement in an external AI channel is not promised.
This is an independent service, not affiliated with or endorsed by Shopify.
What the public preflight measured
Before this check was offered, 26 Shopify storefronts were read with a public read-only preflight on 2026-08-09. All 26 advertised the same ten-tool WebMCP inventory that Shopify documents as its platform-supplied surface.
What that measurement does not establish, and the reason the paid check exists: - No tool was called on any of the 26 stores. - Cart, checkout, payment and order creation were not tested. - Remote MCP behaviour and Agentic Admin settings were not read. - The identical inventory is Shopify's platform surface rather than 26 separate merchant implementations, so it says nothing about any one store's product data. - Five of the 26 needed a repeat run before the scanner finished, so the reading is the latest available observation rather than one clean pass. - The 26 of 26 figure describes those stores at that hour under that scanner version, and it is not generalised to Shopify stores.
Sample report
A synthetic sample report is available on request. It uses invented store data. It shows the format of the three-surface map, the product truth matrix and the correction plan, and it is not a report on a real merchant.
Frequently asked
Do I need an agent-readiness audit first?
No. The Shopify agent storefront check is a separate fixed-scope diagnosis with its own price and its own deliverables. The general audit measures a whole site or API against agent-readiness norms, this check measures what an AI shopper receives from one Shopify store.
What does it cost, and what is the delivery time?
€1,900 plus VAT, fixed scope. Four written deliverables arrive as one package within 48 elapsed hours of the agreed written kickoff. The fifth is a retest of up to two corrected items, within 14 days.
Do you need access to my Shopify Admin?
No. No Shopify Admin password is requested and no credentials are handled. Settings evidence comes from you as redacted screenshots or a short screen recording, and everything else is read from public storefront surfaces.
Will you place a test order?
No. The cart lifecycle stops before payment, one checkout navigation is permitted if you authorise it, and no customer details, payment or order are ever submitted.
What happens if the check finds nothing wrong?
You receive the same deliverables, with the surfaces recorded as matching. A documented match is the result you are paying to be able to show, and the correction plan then names what to keep stable instead.
How to start
Email info@turva.dev with your storefront URL, your .myshopify.com domain, your primary market and up to three priority products. A preflight and a fixed quote follow within one business day.
No calls, no calendar links, and no discovery sessions.
All prices exclude VAT. 25,5% for Finnish customers, reverse charge for EU B2B, 0% for non-EU.