Let Agents In

Agent readiness · Commerce platforms

shopify.com

7 of 13 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with. 3 of them could not be measured from where we ask, and those are left out of the denominator rather than counted as failures.

A · Discovery

  • PASS
    Answers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
  • PASS
    llms.txt publishedllms.txt and llms-full.txt present at https://www.shopify.com/llms.txt and https://www.shopify.com/llms-full.txt and https://docs.shopify.com/llms.txt, and the 12 links we sampled across both files all answer
  • UNMEASURED
    Docs readable without JavaScriptUnmeasurable: no documentation page could be found to readLink your documentation from your home page or list it in llms.txt.
  • PASS
    On-demand agents not blockedNo on-demand agent is blocked
  • N/A
    Paths robots.txt points at answerrobots.txt names no concrete path, only patterns or nothing, so there is no claim to check
  • PASS
    No punishing crawl delayNo Crawl-delay applies to the agents we check

B · Agent entry

  • PART
    Agent entry pointFound https://www.shopify.com/skill.md, but it states a policy rather than a procedure: nothing in it names a credential, an endpoint or a way to get an account.
  • FAIL
    OAuth dynamic client registrationOAuth metadata published, but no registration_endpoint in it
  • FAIL
    MCP surfaceNo MCP surface: nothing answered at mcp.shopify.com, mcp.shopify.com/mcp, mcp.shopify.com/v1/mcp, api.shopify.com/mcp, /mcp or /api/mcp, and no file mentions MCP

C · Registration

  • UNMEASURED
    No CAPTCHA in the signup HTMLUnmeasurable: the signup form at https://admin.shopify.com/signup?locale=en&language=en&signup_page=https%3A%2F%2Fwww.shopify.com%2F&signup_types%5B%5D=paid_trial_experience is not in the server HTML, so its gates are not eitherServer-render the form, or tell us the endpoint it posts to, and the gates become visible to us and to an agent.
  • UNMEASURED
    Signup reachable without a browserUnmeasurable: https://admin.shopify.com/signup?locale=en&language=en&signup_page=https%3A%2F%2Fwww.shopify.com%2F&signup_types%5B%5D=paid_trial_experience answers 403 to an agent and 403 to a Chrome user-agent, so nothing gets in from here and the difference we test for cannot be seenNothing for you to do here. It becomes measurable from a network your edge admits.

D · Provisioning

  • FAIL
    Programmatic key provisioningNone of the 7 provisioning phrases appears in the 3 documents we read
  • PASS
    Free tier or no-card trial stated in textFree tier or no-card signals at https://www.shopify.com/pricing: "no credit card", "Basic Start for free"

E · Integration

  • PASS
    Typed SDK on the registry@shopify/shopify-api@14.0.0 ships types, matched from the registry by who publishes it rather than by a link on your site
  • FAIL
    Machine-readable API descriptionNo OpenAPI spec at the 5 usual paths, none declared by https://www.shopify.com, and no markdown negotiationPoint at your spec from your docs page with rel="service-desc" and an agent finds it without guessing.

Tell me when this changes

The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.

This page is the newest scan we hold for shopify.com and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.

Scan a domain yourself

Is shopify.com ready for AI agents? 7/13 · Let Agents In