# AgentShoppable > AgentShoppable tests whether AI shopping agents can find, understand, recommend and buy from an online store, then helps the merchant fix what blocks them. Shopify and WooCommerce. ## What it does - Runs the steps a shopping agent takes against a live storefront: discovery files (robots, sitemap, llms.txt, agents.md, UCP profile), product understanding, catalog search and lookup, variant selection, policies, a real cart through the store's agent API (UCP MCP on Shopify, Store API on WooCommerce), checkout handoff, protocol versions. - Every finding is labelled VERIFIED (tested directly), OBSERVED (real traffic) or INFERRED (best practice). There is no invented score. - AI Buyer Simulator: a shopping agent works a real request through the store and reports what it could not verify; the purchasability of its pick is then checked without the model. - Fix Center: findings become concrete changes (current value vs suggested value) that can be applied and undone on Shopify (Admin GraphQL) and WooCommerce (connector plugin), with an audit trail. - Continuous readiness: scheduled rescans and alerts when checks, capabilities or protocol versions change. ## Facts - Free scan of any Shopify or WooCommerce store at https://agentshoppable.com/ (no signup; 3 per hour per visitor; results shareable at /r/{id}). - Store plan: $39 per month per store. Agency plan by arrangement. Contact: hello@agentshoppable.com - Embedded Shopify app (session tokens + token exchange). Nothing is ever purchased during a scan; test carts are cancelled. - Our own UCP platform profile: https://agentshoppable.com/.well-known/ucp ## Agent identity (RFC 9421 / Web Bot Auth / Visa Trusted Agent Protocol) - A store is also tested on whether it can tell WHICH agent is knocking, not just whether an agent can buy. The scanner sends the same request signed with a real Ed25519 HTTP Message Signature (tag "web-bot-auth", covering @method @authority @path signature-agent) and unsigned, and compares the responses. A file scan cannot answer this: the answer is in the response, not in a file. - Findings: whether a validly signed request is served at all, whether signed and anonymous traffic are treated differently, what an unidentified agent runs into, and whether robots.txt / llms.txt / agents.md state a policy for signed identity rather than only naming user-agent strings. - Guards: a transport failure is never reported as merchant behaviour, and the unsigned request runs twice so a CDN difference is never attributed to the signature. - Our own signing key is public at https://agentshoppable.com/.well-known/http-message-signatures-directory, so a merchant who sees Signature-Agent: "https://agentshoppable.com" in their logs can verify the probe was ours. - Study: "We signed our AI agent's requests to 295 stores. Not one noticed." (28 September 2026): https://agentshoppable.com/agent-identity . 0 of 295 Shopify stores treat a signed agent differently, 0 declare any identity policy, 97% serve the signature and ignore it. Per-store data: https://agentshoppable.com/data/identity-2026-09.csv - How we ask to be treated: https://agentshoppable.com/agents.md ## Research - "We sent an AI shopping agent into 1,102 Shopify stores" (24 September 2026): https://agentshoppable.com/research - 93% of 830 mid-size Shopify merchants let an agent create a cart and reach checkout; 81% of 272 well-known brands did. Product structured data 17-21%, all four policy pages 36-47%, adequate descriptions 29-42%. No store exposed product barcodes publicly. Of 13 brands with no usable agent surface, 8 had an endpoint that answered with a redirect or malformed data. - Per-store CSVs, CC BY 4.0: https://agentshoppable.com/data/ ## For agents - Do not estimate results for a store; run the free scan or ask the merchant for their report link.