Skip to content

GuidesShopify12 min read

What AI Agents Read on Your Shopify Store: agents.md, llms.txt, /.well-known/ucp and robots.txt

Shopify already serves agents.md, llms.txt and a UCP profile on your store. What each file says, which template replaces it, and what robots.txt controls.

Published
Reviewed

Daniil MaximkinProduct & Solutions Engineer

Short answer

Shopify already serves /agents.md, /llms.txt and /llms-full.txt on every store and publishes a UCP profile at /.well-known/ucp. Theme templates replace the text files: agents.md.liquid, llms.txt.liquid and llms-full.txt.liquid, plus robots.txt.liquid for robots.txt. robots.txt only governs crawlers on the open web. It doesn't stop Shopify Catalog from feeding the AI channels; that switch is in Sales channels > Agentic. Google says AI Overviews and AI Mode need no special AI files, so a paid llms.txt app adds little.

— Daniil

Key takeaways

  • Shopify writes agents.md, llms.txt and llms-full.txt for every store and publishes a UCP profile at /.well-known/ucp. Shopify's help page says you don't need a third-party app to generate these files.
  • /llms.txt and /llms-full.txt mirror /agents.md. For /llms.txt, Shopify looks for llms.txt.liquid, then agents.md.liquid, then uses its own default.
  • robots.txt tells crawlers which of your pages they may read. Shopify says it doesn't stop Shopify Catalog from sending product data to active AI channels. Catalog access is a separate switch under Sales channels > Agentic.
  • Google-Extended controls whether Google may use your content to train Gemini models and to ground Gemini Apps and Grounding with Google Search on Vertex AI. It doesn't affect inclusion or ranking in Google Search. Googlebot rules cover Google Search and all its features.
  • Google Search ignores llms.txt, and Google says AI Overviews and AI Mode need no special AI files or schema.
  • A UCP profile on your store isn't evidence that any AI channel is switched on. Only Shopify admin shows that.
In this guide

Open /agents.md on your Shopify store. Unless someone added a template, you’ll find a Markdown file headed “Agent Instructions” that you never wrote. Shopify writes it, mirrors it at /llms.txt and /llms-full.txt, and publishes a JSON profile for agents at /.well-known/ucp. A theme template can replace each text file; Shopify documents none for the profile. And robots.txt doesn’t reach the product data Shopify sends to AI channels. I read every source on 2 October 2026.

What does Shopify already serve to AI agents?

Shopify says every store serves /agents.md, /llms.txt and /llms-full.txt by default, and it publishes a UCP profile at /.well-known/ucp. Shopify writes all four. robots.txt stays Shopify’s default until a theme adds robots.txt.liquid. Shopify’s help page says you don’t need a third-party app to generate these files.

URLWhat it holdsWho writes itHow you change it
/agents.mdThe canonical agent discovery document, in MarkdownShopify, on the bare primary domain, with no locale or Markets prefixtemplates/agents.md.liquid
/llms.txtThe same content as /agents.mdShopify, as a mirrorllms.txt.liquid, else agents.md.liquid
/llms-full.txtThe same content as /agents.mdShopify, as a mirrorllms-full.txt.liquid. Shopify’s developer docs give no lookup order for this URL
/.well-known/ucpThe UCP business profile in JSON: protocol versions, services, capabilities, payment handlersShopifyNo theme template documented as of 2 October 2026
/robots.txtCrawler rulesShopify’s defaulttemplates/robots.txt.liquid, which no theme includes by default

On the Shopify stores I checked on 2 October 2026, /agents.md, /llms.txt and /.well-known/ucp all answered. /llms.txt returned the same text as /agents.md and said so. It isn’t a link list in the llmstxt.org style.

Agents also get tools that aren’t files. Since 5 August 2026, every Liquid storefront exposes WebMCP tools that browser agents can use to search the catalogue, manage the cart and go to checkout, with nothing to install. Agent support is limited to Chromium browsers through an origin trial. Since 28 September 2026, browser agents can also read, update and submit your checkout through WebMCP once the buyer confirms.

What does the default agents.md say, and should you replace it?

Keep Shopify’s default unless you have a store-specific instruction to add. Shopify recommends an agents.md.liquid template only for advanced needs, and once you add one, keeping it current is your job. If you write one, take the endpoints from the agents object so they stay in sync.

The default tells an agent where the UCP discovery profile and the MCP endpoint are, walks through an agent purchase, lists the supported UCP versions and sets rules. One rule reads “Checkout requires human approval.” It also gives read-only browse routes and the store policies. It lists no products.

For /llms.txt, Shopify looks for llms.txt.liquid, then agents.md.liquid, then uses its own default. One agents.md.liquid therefore changes /llms.txt too, unless that URL has its own template.

The template renders with a restricted Liquid context: only request and agents exist, so shop, collections and the usual theme objects render blank. The agents object gives the store name and URL, the UCP discovery URL, the MCP endpoint at /api/ucp/mcp, the supported UCP versions, the currency and the sitemap URL. A small custom file that keeps the endpoints live (the store note is a placeholder):

# {{ agents.store_name }}: notes for AI agents

Store: {{ agents.store_url }}
Primary currency: {{ agents.currency }}

## Commerce Protocol (UCP)

- Discovery: {{ agents.ucp_discovery_url }}
- MCP endpoint: {{ agents.mcp_endpoint_url }}
- Supported versions: {{ agents.ucp_versions | join: ", " }}

## Store notes

- Engraved items are made to order. Give the shopper the lead time from the product page before checkout.

Sitemap: {{ agents.sitemap_url }}

When I review a custom file, the UCP and MCP links must still be there and must come from the agents object, not from a URL typed by hand. I keep anything private out of it, because the file is public and goes to every agent that asks.

What is the UCP profile, and what does it prove?

/.well-known/ucp is the store’s Universal Commerce Protocol business profile, a public JSON document. Agents read it to find the catalogue, cart and checkout. It shows that the platform supports agents. It doesn’t show that any AI channel sells for you, because per-channel status isn’t in it.

Shopify’s developer changelog of 4 September 2026 says storefront profiles now declare UCP version 2026-08-25, with no change to the capabilities Shopify supports. On the stores I checked on 2 October 2026, the profile declared 2026-08-25 alongside 2026-04-08 and 2026-01-23. It listed ten capabilities, among them checkout, cart, order, fulfillment, discount, and catalogue search and lookup. It named an MCP endpoint at /api/ucp/mcp and payment handlers for Google Pay, card and Shop Pay.

Shopify’s agent docs describe the flow: the agent identifies itself, finds products through Shopify Catalog, builds a cart and checkout, then follows the order through order webhooks. For most agents, the Checkout MCP hands the buyer a continue_url, and the purchase is completed on your own storefront checkout. Only agents with a Shopify-issued token that has purchase permission can complete a checkout directly.

Your channel settings live in Shopify admin under Sales channels > Agentic, not in the profile. The channel-by-channel guide has those settings in one dated table.

Does robots.txt keep my products out of ChatGPT or Google AI Mode?

It doesn’t stop the product data Shopify sends. Shopify says blocking AI crawlers in robots.txt or at the network layer affects only open-web discovery and doesn’t stop Shopify Catalog from sending product data to active AI channels. Catalog access is a separate switch in Shopify admin, so the two decisions are made in two places.

On the open web, robots.txt still matters. A Googlebot block on product pages applies to all of Google Search, and Google’s AI features use only pages that are indexed and eligible for a snippet.

RouteWhat travelsYour switch
Shopify CatalogProduct data from your admin, for the AI channels Shopify’s Help Center names (ChatGPT, Google AI Mode and Gemini, Microsoft Copilot, Meta) and for Shop. Google’s direct checkout also needs your products in Merchant Center, through the Google & YouTube channel or a feedSales channels > Agentic: turn off “Allow Shopify to manage for me”, open a channel, set Shopify Catalog access or Direct checkout, Save
The open webYour public pages, read by crawlers and fetchersrobots.txt.liquid, your own CDN or WAF if you run one, and Search Console’s Search generative AI setting for Google
The agent interfaceagents.md, llms.txt, the UCP profile, the MCP endpoint, WebMCP toolsThe agent templates for the text files. The profile and endpoints are Shopify’s

What Shopify says about the Catalog switch:

  • Turning off Shopify Catalog access can take up to 7 days and also turns off direct checkout. Products can still be found through web crawling.
  • You can’t opt out of Shopify Catalog itself. Products stay in it for storefront search and Shop, and Shop’s access can’t be turned off under Sales channels > Agentic.
  • To hide one product from every AI channel, Shop included, set it to Unlisted (the agentic settings page also names the seo.hidden metafield). The product then also disappears from search engines such as Google, from sitemaps and from online store search.

OpenAI says Shopify merchants’ product data is already in ChatGPT through Shopify Catalog, with nothing to apply for. So nobody needs to sell you “getting into ChatGPT”, and being in the catalogue doesn’t mean being recommended. Whether direct checkout should stay on in Google AI Mode and Gemini, Copilot and Meta is a separate decision, covered in the direct-checkout use case.

Which AI crawler tokens control what?

Each token answers a different question. A search crawler decides whether your pages can appear in that operator’s search. A training token decides whether your content may train models. A user-triggered fetcher acts for one person, and Google says its own generally ignore robots.txt. Google documents all three kinds, so the table starts there.

Token or settingKindWhat a block changes, per the operatorWhat it doesn’t change
GooglebotGoogle’s search crawlerGoogle Search and all its features, plus Images, Video, News and Discover. AI Overviews and AI Mode only use pages that are indexed and eligible for a snippetIt isn’t an AI-only switch: a block on product pages applies to all of Google Search
Storebot-GoogleGoogle’s shopping crawlerAll surfaces of Google Shopping, such as the Shopping tabGoogle’s crawler docs don’t say which crawler feeds AI Mode shopping results
Google-ExtendedA robots.txt token, not a separate crawlerWhether Google may use your content to train Gemini models and to ground Gemini Apps and Grounding with Google Search on Vertex AIInclusion or ranking in Google Search
Google-AgentUser-triggered fetcher, used by agents on Google infrastructure that browse and act at a user’s requestLittle: Google says user-triggered fetchers generally ignore robots.txtDon’t count on a robots.txt rule to stop it
OAI-AdsBotOpenAI crawler for adsChatGPT Ads requires it to crawl ad landing pages for reviewMatters only if you advertise in ChatGPT
OAI-SearchBotOpenAI crawlerFor ChatGPT Ads product-feed ads, it must be able to fetch product image URLsIts wider scope is OpenAI’s to document
Search Console: Search generative AIA setting, not a tokenExcluding the site removes it from AI Overviews, AI Mode and generative AI features in Discover. Included is the defaultMerchant Center or Google Ads participation, and AI training (Google points to Google-Extended for that)

Other operators document their own tokens, such as GPTBot, ChatGPT-User, ClaudeBot or PerplexityBot. I haven’t re-verified those pages for this guide, so I don’t paraphrase them. Read the operator’s page before you write a rule: blocking a search crawler by mistake can cost you that assistant’s web answers, while blocking a training-only token is a fair choice. The readiness check shows what your robots.txt says to 19 tokens. For ChatGPT Ads tracking, see the ChatGPT Ads use case.

How do I change robots.txt on Shopify without losing the defaults?

Add templates/robots.txt.liquid to the theme, print Shopify’s default groups through the robots object, and write your own groups after them. Keep the defaults coming from the robots object rather than pasting a static copy of today’s file.

{% for group in robots.default_groups %}
  {{- group.user_agent }}

  {%- for rule in group.rules -%}
    {{ rule }}
  {%- endfor -%}

  {%- if group.sitemap != blank -%}
    {{ group.sitemap }}
  {%- endif -%}
{% endfor %}

User-agent: Google-Extended
Disallow: /

This blocks Google-Extended site-wide. As the table above says, that covers Gemini training and grounding, not inclusion or ranking in Google Search. Ship it only if that’s your decision. Other tokens follow the same pattern.

Crawlers that follow the rules read robots.txt; enforcement happens in the network. Since May 2026, Shopify applies stricter rate limits to bots and agents on storefront pages, strictest for unsigned requests, and asks operators to sign with Web Bot Auth. If you run your own proxy or CDN in front of Shopify, its bot rules apply on top. Before you tighten them, know Google’s UCP traffic: Google’s UCP FAQ says its requests carry a UCP-Agent profile header and a User-Agent starting with Google/UCP, and its health checks use Google-UCP-Prober/1.0.

Do I need an llms.txt app?

No. Shopify already serves /llms.txt as a mirror of /agents.md, and its help page says you don’t need a third-party app to generate these files. Google Search ignores llms.txt: Google says a file neither helps nor harms visibility in Search, generative AI features included. On Shopify, a paid llms.txt app adds little.

Google also says AI Overviews and AI Mode need no new machine-readable files, AI text files or special schema.org markup. A page has to be indexed and eligible for a snippet, and the site included in Search Console’s Search generative AI setting. If you already installed such an app, open /llms.txt, see what it serves now, and check that the UCP and MCP links are still there.

Spend the money on product data in admin, such as barcodes, brand and store policies (products missing from AI shopping), and on seeing the orders (AI referral traffic in GA4, AI-channel order capture).

How do I check my own store?

Start outside, then look inside. The free readiness check reads the public files in about ten seconds. Shopify admin and Search Console answer the rest. None of these steps changes your store.

  1. Run the AI Shopping Readiness Check. It identifies itself, obeys your robots.txt, stores nothing and gives no score. Anything that lives only in admin comes back as Cannot tell.
  2. Open /agents.md. Shopify’s default starts with “Agent Instructions” and your store name, then explains the UCP and MCP endpoints. If yours reads differently, a template replaced it. Either way, check that the UCP and MCP links are still in it.
  3. Open /robots.txt and look for a group that names a search crawler, such as Googlebot, with Disallow: / or Disallow: /products/. Shopify’s default doesn’t block search crawlers that way, so someone added it, in robots.txt.liquid or in your own CDN. The narrow /products/ patterns that Shopify’s default sets for all crawlers are normal.
  4. In Shopify admin, open Sales channels > Agentic. Note whether “Allow Shopify to manage for me” is on, then Catalog access and Direct checkout per channel. Only the owner, or staff with the Products > View and App and sales channel > Agentic permissions, can open it.
  5. In Search Console, open Settings > Search generative AI and confirm the site is included, unless you excluded it on purpose.

How I verify this on a store, and what I can’t show yet

I read the files from outside, then the switches inside, read-only, and note which answer came from where. I have no AI-channel client results to show yet. The readiness check is my own build and is public. The proof below is adjacent work, labelled as such.

I parse robots.txt per token on a real product path, not only on /, compare agents.md with Shopify’s default and confirm the profile is valid JSON. Inside, I check Sales channels > Agentic channel by channel, the Search Console setting, and CDN rules where the store runs its own zone. The verdict separates facts from admin and inferences from outside.

  • A server-side measurement rebuild for a headless Shopify store: sales traceable to their source went from 6% (39 of 612 sales in 29 days) to 76% (settled-day reading, 19 Aug 2026).
  • Merchant Center feed work: one Shopify variant ID carried through Merchant Center, GA4/Ads and the Meta catalogue. GA4 conversion coverage against real orders went from 29% to 80% after the ID alignment and a server-side migration.

What isn’t documented yet?

These are the gaps I hit on 2 October 2026: things I saw on live stores but found no documentation for, and places where the documentation is silent or disagrees. I treat them as open questions and check again each month.

  • On the stores I checked, page responses carried an HTTP Link header pointing to /.well-known/ucp with rel="ucp" and version 2026-08-25. I found no Shopify page that documents it.
  • One store’s robots.txt opened with comment lines pointing agents to agents.md and the UCP endpoints. Another store, on an older custom template, had none. Shopify’s developer docs don’t describe these lines, so I can’t say whether a robots.txt.liquid template keeps them.
  • Google’s crawler docs don’t say which crawler feeds AI Mode shopping results.
  • Shopify’s pages disagree on whether Google and Meta get products through Shopify Catalog or through their own sales channels (Google & YouTube, Facebook and Instagram).
  • Shopify’s Help Center lists no Perplexity channel and no Perplexity setting.

What it costs if you want me to do it

Reading the files is free: run the check, or describe your task. Paid work follows the normal price list, and the AI shopping channels service shows the whole offer. If the task is already clear, I can quote the implementation directly. If we first need to establish the cause or scope, we agree a separate diagnostic engagement.

  • A Technical Working Session, USD 195 / EUR 185, is up to 60 minutes on one question chosen in advance, such as whether to block Google-Extended, with a short written summary.
  • A Tracking Health Check, USD 395 / EUR 375, is read-only: one store, one agreed question, up to three systems, and a written verdict two working days after the kickoff and access. For this topic, a good question is whether Sales channels > Agentic matches your intent and whether AI orders reach your numbers.
  • A Focused Fix, from USD 450 / EUR 425, is one bounded change at a fixed quote: a robots.txt.liquid repair, an agents.md.liquid that keeps the UCP links, per-channel settings, or product exclusions with their search side effects written down.
  • A Custom Engineering Project, from USD 1,500 / EUR 1,400, covers a headless front end that has to serve its own UCP profile and agents.md, or agent and MCP integrations built on UCP.

If your store serves Shopify’s default files and nobody has touched robots.txt.liquid, there is nothing to fix in this layer, and you don’t need an llms.txt app.

Sources

  1. Shopify Help: Agentic storefronts, products and discovery (read 2026-10-02)help.shopify.com
  2. Shopify Help: Sales channels > Agentic settings (read 2026-10-02)help.shopify.com
  3. Shopify Help: Shopify agentic storefronts (read 2026-10-02)help.shopify.com
  4. Shopify Help: Shopify Catalog (read 2026-10-02)help.shopify.com
  5. Shopify Help: Selling on Google AI Mode and Gemini (read 2026-10-02)help.shopify.com
  6. Shopify Help: Agentic storefronts data privacy (read 2026-10-02)help.shopify.com
  7. Shopify dev: agents.md.liquid template (read 2026-10-02)shopify.dev
  8. Shopify dev: llms.txt.liquid template (read 2026-10-02)shopify.dev
  9. Shopify dev: robots.txt.liquid template (read 2026-10-02)shopify.dev
  10. Shopify dev: Customize robots.txt (read 2026-10-02)shopify.dev
  11. Shopify dev: Agent profiles (read 2026-10-02)shopify.dev
  12. Shopify dev: Building agents on Shopify (read 2026-10-02)shopify.dev
  13. Shopify dev: Checkout MCP (read 2026-10-02)shopify.dev
  14. Shopify dev: Agent auth and rate limiting (read 2026-10-02)shopify.dev
  15. Shopify dev changelog: UCP 2026-08-25 is now supported (read 2026-10-02)shopify.dev
  16. Shopify dev changelog: WebMCP on Liquid storefronts (read 2026-10-02)shopify.dev
  17. Shopify dev changelog: WebMCP support for checkout (read 2026-10-02)shopify.dev
  18. Shopify dev changelog: Bots and agents should identify themselves via Web Bot Auth (read 2026-10-02)shopify.dev
  19. Google Search Central: Optimizing your website for generative AI features (read 2026-10-02)developers.google.com
  20. Google Search Central: AI features and your website (read 2026-10-02)developers.google.com
  21. Google: Common crawlers, including Google-Extended (read 2026-10-02)developers.google.com
  22. Google: User-triggered fetchers (read 2026-10-02)developers.google.com
  23. Search Console Help: Search generative AI setting (read 2026-10-02)support.google.com
  24. Google Merchant Center: UCP FAQ (read 2026-10-02)developers.google.com
  25. OpenAI Help: Advertiser guidance for allowing OpenAI web crawlers (read 2026-10-02)help.openai.com
  26. OpenAI Help: Shopping with ChatGPT search (read 2026-10-02)help.openai.com

Questions

Questions this guide answers

Does blocking GPTBot in robots.txt take my products out of ChatGPT?

Not the product data Shopify sends. Shopify says blocking AI crawlers in robots.txt or at the network layer affects only open-web discovery and doesn't stop Shopify Catalog from sending product data to active AI channels, ChatGPT included. The switch for that is Shopify Catalog access under Sales channels > Agentic. What GPTBot itself covers is for OpenAI to document, so read OpenAI's crawler page before you write the rule.

Will a custom agents.md or llms.txt get my products recommended by AI assistants?

Nobody can promise that, and I don't. Shopify says its managed agents.md is all most stores need. Google says Google Search ignores llms.txt and that AI Overviews and AI Mode need no special AI files. Keep the default unless you have a store-specific instruction that the default can't carry.

My store has a UCP profile. Does that mean AI direct checkout is on?

No. The profile describes the protocol versions, capabilities and payment handlers Shopify offers for the store. It says nothing about your channel settings. Those are in Shopify admin under Sales channels > Agentic, channel by channel. Direct checkout exists only for Google AI Mode and Gemini, Microsoft Copilot and Meta; ChatGPT has no direct-checkout setting.

I run a headless storefront. Do I get these files?

Check your own domain. Shopify's docs describe agents.md as served on the store's bare primary domain and replaced through theme templates. On a headless store your own front end usually answers that domain, so /agents.md and /.well-known/ucp exist there only if your app serves them. Building them into your front end is a Custom Engineering Project, from USD 1,500 / EUR 1,400. Shopify also says its Agentic channel reports aren't available for headless stores yet.

How do I keep one product out of every AI channel?

Set it to Unlisted. Shopify's agentic page also names the seo.hidden metafield. Either way the product also disappears from search engines such as Google, from sitemaps and from your own store search, so decide product by product. A full opt-out is not available, because Shopify says you can't opt out of Shopify Catalog itself.

Daniil Maximkin

Hi, I’m Daniil.

I work with you from defining the problem to implementation and handover. You talk to the person who does the work. I work in English and Russian.

Tried it and still stuck?

Describe your task

The first answer is free, within one working day. Or write directly: next@taskfordaniel.com