Open /agents.md on your Shopify store. Unless someone added a template, you’ll find a Markdown file headed “Agent Instructions” that you never wrote. Shopify writes it, mirrors it at /llms.txt and /llms-full.txt, and publishes a JSON profile for agents at /.well-known/ucp. A theme template can replace each text file; Shopify documents none for the profile. And robots.txt doesn’t reach the product data Shopify sends to AI channels. I read every source on 2 October 2026.
What does Shopify already serve to AI agents?
Shopify says every store serves /agents.md, /llms.txt and /llms-full.txt by default, and it publishes a UCP profile at /.well-known/ucp. Shopify writes all four. robots.txt stays Shopify’s default until a theme adds robots.txt.liquid. Shopify’s help page says you don’t need a third-party app to generate these files.
Comparison table — scroll horizontally to see all columns
| URL | What it holds | Who writes it | How you change it |
|---|---|---|---|
/agents.md | The canonical agent discovery document, in Markdown | Shopify, on the bare primary domain, with no locale or Markets prefix | templates/agents.md.liquid |
/llms.txt | The same content as /agents.md | Shopify, as a mirror | llms.txt.liquid, else agents.md.liquid |
/llms-full.txt | The same content as /agents.md | Shopify, as a mirror | llms-full.txt.liquid. Shopify’s developer docs give no lookup order for this URL |
/.well-known/ucp | The UCP business profile in JSON: protocol versions, services, capabilities, payment handlers | Shopify | No theme template documented as of 2 October 2026 |
/robots.txt | Crawler rules | Shopify’s default | templates/robots.txt.liquid, which no theme includes by default |
On the Shopify stores I checked on 2 October 2026, /agents.md, /llms.txt and /.well-known/ucp all answered. /llms.txt returned the same text as /agents.md and said so. It isn’t a link list in the llmstxt.org style.
Agents also get tools that aren’t files. Since 5 August 2026, every Liquid storefront exposes WebMCP tools that browser agents can use to search the catalogue, manage the cart and go to checkout, with nothing to install. Agent support is limited to Chromium browsers through an origin trial. Since 28 September 2026, browser agents can also read, update and submit your checkout through WebMCP once the buyer confirms.
What does the default agents.md say, and should you replace it?
Keep Shopify’s default unless you have a store-specific instruction to add. Shopify recommends an agents.md.liquid template only for advanced needs, and once you add one, keeping it current is your job. If you write one, take the endpoints from the agents object so they stay in sync.
The default tells an agent where the UCP discovery profile and the MCP endpoint are, walks through an agent purchase, lists the supported UCP versions and sets rules. One rule reads “Checkout requires human approval.” It also gives read-only browse routes and the store policies. It lists no products.
For /llms.txt, Shopify looks for llms.txt.liquid, then agents.md.liquid, then uses its own default. One agents.md.liquid therefore changes /llms.txt too, unless that URL has its own template.
The template renders with a restricted Liquid context: only request and agents exist, so shop, collections and the usual theme objects render blank. The agents object gives the store name and URL, the UCP discovery URL, the MCP endpoint at /api/ucp/mcp, the supported UCP versions, the currency and the sitemap URL. A small custom file that keeps the endpoints live (the store note is a placeholder):
# {{ agents.store_name }}: notes for AI agents
Store: {{ agents.store_url }}
Primary currency: {{ agents.currency }}
## Commerce Protocol (UCP)
- Discovery: {{ agents.ucp_discovery_url }}
- MCP endpoint: {{ agents.mcp_endpoint_url }}
- Supported versions: {{ agents.ucp_versions | join: ", " }}
## Store notes
- Engraved items are made to order. Give the shopper the lead time from the product page before checkout.
Sitemap: {{ agents.sitemap_url }}
When I review a custom file, the UCP and MCP links must still be there and must come from the agents object, not from a URL typed by hand. I keep anything private out of it, because the file is public and goes to every agent that asks.
What is the UCP profile, and what does it prove?
/.well-known/ucp is the store’s Universal Commerce Protocol business profile, a public JSON document. Agents read it to find the catalogue, cart and checkout. It shows that the platform supports agents. It doesn’t show that any AI channel sells for you, because per-channel status isn’t in it.
Shopify’s developer changelog of 4 September 2026 says storefront profiles now declare UCP version 2026-08-25, with no change to the capabilities Shopify supports. On the stores I checked on 2 October 2026, the profile declared 2026-08-25 alongside 2026-04-08 and 2026-01-23. It listed ten capabilities, among them checkout, cart, order, fulfillment, discount, and catalogue search and lookup. It named an MCP endpoint at /api/ucp/mcp and payment handlers for Google Pay, card and Shop Pay.
Shopify’s agent docs describe the flow: the agent identifies itself, finds products through Shopify Catalog, builds a cart and checkout, then follows the order through order webhooks. For most agents, the Checkout MCP hands the buyer a continue_url, and the purchase is completed on your own storefront checkout. Only agents with a Shopify-issued token that has purchase permission can complete a checkout directly.
Your channel settings live in Shopify admin under Sales channels > Agentic, not in the profile. The channel-by-channel guide has those settings in one dated table.
Does robots.txt keep my products out of ChatGPT or Google AI Mode?
It doesn’t stop the product data Shopify sends. Shopify says blocking AI crawlers in robots.txt or at the network layer affects only open-web discovery and doesn’t stop Shopify Catalog from sending product data to active AI channels. Catalog access is a separate switch in Shopify admin, so the two decisions are made in two places.
On the open web, robots.txt still matters. A Googlebot block on product pages applies to all of Google Search, and Google’s AI features use only pages that are indexed and eligible for a snippet.
Comparison table — scroll horizontally to see all columns
| Route | What travels | Your switch |
|---|---|---|
| Shopify Catalog | Product data from your admin, for the AI channels Shopify’s Help Center names (ChatGPT, Google AI Mode and Gemini, Microsoft Copilot, Meta) and for Shop. Google’s direct checkout also needs your products in Merchant Center, through the Google & YouTube channel or a feed | Sales channels > Agentic: turn off “Allow Shopify to manage for me”, open a channel, set Shopify Catalog access or Direct checkout, Save |
| The open web | Your public pages, read by crawlers and fetchers | robots.txt.liquid, your own CDN or WAF if you run one, and Search Console’s Search generative AI setting for Google |
| The agent interface | agents.md, llms.txt, the UCP profile, the MCP endpoint, WebMCP tools | The agent templates for the text files. The profile and endpoints are Shopify’s |
What Shopify says about the Catalog switch:
- Turning off Shopify Catalog access can take up to 7 days and also turns off direct checkout. Products can still be found through web crawling.
- You can’t opt out of Shopify Catalog itself. Products stay in it for storefront search and Shop, and Shop’s access can’t be turned off under Sales channels > Agentic.
- To hide one product from every AI channel, Shop included, set it to Unlisted (the agentic settings page also names the
seo.hiddenmetafield). The product then also disappears from search engines such as Google, from sitemaps and from online store search.
OpenAI says Shopify merchants’ product data is already in ChatGPT through Shopify Catalog, with nothing to apply for. So nobody needs to sell you “getting into ChatGPT”, and being in the catalogue doesn’t mean being recommended. Whether direct checkout should stay on in Google AI Mode and Gemini, Copilot and Meta is a separate decision, covered in the direct-checkout use case.
Which AI crawler tokens control what?
Each token answers a different question. A search crawler decides whether your pages can appear in that operator’s search. A training token decides whether your content may train models. A user-triggered fetcher acts for one person, and Google says its own generally ignore robots.txt. Google documents all three kinds, so the table starts there.
Comparison table — scroll horizontally to see all columns
| Token or setting | Kind | What a block changes, per the operator | What it doesn’t change |
|---|---|---|---|
Googlebot | Google’s search crawler | Google Search and all its features, plus Images, Video, News and Discover. AI Overviews and AI Mode only use pages that are indexed and eligible for a snippet | It isn’t an AI-only switch: a block on product pages applies to all of Google Search |
Storebot-Google | Google’s shopping crawler | All surfaces of Google Shopping, such as the Shopping tab | Google’s crawler docs don’t say which crawler feeds AI Mode shopping results |
Google-Extended | A robots.txt token, not a separate crawler | Whether Google may use your content to train Gemini models and to ground Gemini Apps and Grounding with Google Search on Vertex AI | Inclusion or ranking in Google Search |
Google-Agent | User-triggered fetcher, used by agents on Google infrastructure that browse and act at a user’s request | Little: Google says user-triggered fetchers generally ignore robots.txt | Don’t count on a robots.txt rule to stop it |
OAI-AdsBot | OpenAI crawler for ads | ChatGPT Ads requires it to crawl ad landing pages for review | Matters only if you advertise in ChatGPT |
OAI-SearchBot | OpenAI crawler | For ChatGPT Ads product-feed ads, it must be able to fetch product image URLs | Its wider scope is OpenAI’s to document |
| Search Console: Search generative AI | A setting, not a token | Excluding the site removes it from AI Overviews, AI Mode and generative AI features in Discover. Included is the default | Merchant Center or Google Ads participation, and AI training (Google points to Google-Extended for that) |
Other operators document their own tokens, such as GPTBot, ChatGPT-User, ClaudeBot or PerplexityBot. I haven’t re-verified those pages for this guide, so I don’t paraphrase them. Read the operator’s page before you write a rule: blocking a search crawler by mistake can cost you that assistant’s web answers, while blocking a training-only token is a fair choice. The readiness check shows what your robots.txt says to 19 tokens. For ChatGPT Ads tracking, see the ChatGPT Ads use case.
How do I change robots.txt on Shopify without losing the defaults?
Add templates/robots.txt.liquid to the theme, print Shopify’s default groups through the robots object, and write your own groups after them. Keep the defaults coming from the robots object rather than pasting a static copy of today’s file.
{% for group in robots.default_groups %}
{{- group.user_agent }}
{%- for rule in group.rules -%}
{{ rule }}
{%- endfor -%}
{%- if group.sitemap != blank -%}
{{ group.sitemap }}
{%- endif -%}
{% endfor %}
User-agent: Google-Extended
Disallow: /
This blocks Google-Extended site-wide. As the table above says, that covers Gemini training and grounding, not inclusion or ranking in Google Search. Ship it only if that’s your decision. Other tokens follow the same pattern.
Crawlers that follow the rules read robots.txt; enforcement happens in the network. Since May 2026, Shopify applies stricter rate limits to bots and agents on storefront pages, strictest for unsigned requests, and asks operators to sign with Web Bot Auth. If you run your own proxy or CDN in front of Shopify, its bot rules apply on top. Before you tighten them, know Google’s UCP traffic: Google’s UCP FAQ says its requests carry a UCP-Agent profile header and a User-Agent starting with Google/UCP, and its health checks use Google-UCP-Prober/1.0.
Do I need an llms.txt app?
No. Shopify already serves /llms.txt as a mirror of /agents.md, and its help page says you don’t need a third-party app to generate these files. Google Search ignores llms.txt: Google says a file neither helps nor harms visibility in Search, generative AI features included. On Shopify, a paid llms.txt app adds little.
Google also says AI Overviews and AI Mode need no new machine-readable files, AI text files or special schema.org markup. A page has to be indexed and eligible for a snippet, and the site included in Search Console’s Search generative AI setting. If you already installed such an app, open /llms.txt, see what it serves now, and check that the UCP and MCP links are still there.
Spend the money on product data in admin, such as barcodes, brand and store policies (products missing from AI shopping), and on seeing the orders (AI referral traffic in GA4, AI-channel order capture).
How do I check my own store?
Start outside, then look inside. The free readiness check reads the public files in about ten seconds. Shopify admin and Search Console answer the rest. None of these steps changes your store.
- Run the AI Shopping Readiness Check. It identifies itself, obeys your
robots.txt, stores nothing and gives no score. Anything that lives only in admin comes back as Cannot tell. - Open
/agents.md. Shopify’s default starts with “Agent Instructions” and your store name, then explains the UCP and MCP endpoints. If yours reads differently, a template replaced it. Either way, check that the UCP and MCP links are still in it. - Open
/robots.txtand look for a group that names a search crawler, such asGooglebot, withDisallow: /orDisallow: /products/. Shopify’s default doesn’t block search crawlers that way, so someone added it, inrobots.txt.liquidor in your own CDN. The narrow/products/patterns that Shopify’s default sets for all crawlers are normal. - In Shopify admin, open Sales channels > Agentic. Note whether “Allow Shopify to manage for me” is on, then Catalog access and Direct checkout per channel. Only the owner, or staff with the Products > View and App and sales channel > Agentic permissions, can open it.
- In Search Console, open Settings > Search generative AI and confirm the site is included, unless you excluded it on purpose.
How I verify this on a store, and what I can’t show yet
I read the files from outside, then the switches inside, read-only, and note which answer came from where. I have no AI-channel client results to show yet. The readiness check is my own build and is public. The proof below is adjacent work, labelled as such.
I parse robots.txt per token on a real product path, not only on /, compare agents.md with Shopify’s default and confirm the profile is valid JSON. Inside, I check Sales channels > Agentic channel by channel, the Search Console setting, and CDN rules where the store runs its own zone. The verdict separates facts from admin and inferences from outside.
- A server-side measurement rebuild for a headless Shopify store: sales traceable to their source went from 6% (39 of 612 sales in 29 days) to 76% (settled-day reading, 19 Aug 2026).
- Merchant Center feed work: one Shopify variant ID carried through Merchant Center, GA4/Ads and the Meta catalogue. GA4 conversion coverage against real orders went from 29% to 80% after the ID alignment and a server-side migration.
What isn’t documented yet?
These are the gaps I hit on 2 October 2026: things I saw on live stores but found no documentation for, and places where the documentation is silent or disagrees. I treat them as open questions and check again each month.
- On the stores I checked, page responses carried an HTTP
Linkheader pointing to/.well-known/ucpwithrel="ucp"and version 2026-08-25. I found no Shopify page that documents it. - One store’s
robots.txtopened with comment lines pointing agents toagents.mdand the UCP endpoints. Another store, on an older custom template, had none. Shopify’s developer docs don’t describe these lines, so I can’t say whether arobots.txt.liquidtemplate keeps them. - Google’s crawler docs don’t say which crawler feeds AI Mode shopping results.
- Shopify’s pages disagree on whether Google and Meta get products through Shopify Catalog or through their own sales channels (Google & YouTube, Facebook and Instagram).
- Shopify’s Help Center lists no Perplexity channel and no Perplexity setting.
What it costs if you want me to do it
Reading the files is free: run the check, or describe your task. Paid work follows the normal price list, and the AI shopping channels service shows the whole offer. If the task is already clear, I can quote the implementation directly. If we first need to establish the cause or scope, we agree a separate diagnostic engagement.
- A Technical Working Session, USD 195 / EUR 185, is up to 60 minutes on one question chosen in advance, such as whether to block Google-Extended, with a short written summary.
- A Tracking Health Check, USD 395 / EUR 375, is read-only: one store, one agreed question, up to three systems, and a written verdict two working days after the kickoff and access. For this topic, a good question is whether Sales channels > Agentic matches your intent and whether AI orders reach your numbers.
- A Focused Fix, from USD 450 / EUR 425, is one bounded change at a fixed quote: a
robots.txt.liquidrepair, anagents.md.liquidthat keeps the UCP links, per-channel settings, or product exclusions with their search side effects written down. - A Custom Engineering Project, from USD 1,500 / EUR 1,400, covers a headless front end that has to serve its own UCP profile and
agents.md, or agent and MCP integrations built on UCP.
If your store serves Shopify’s default files and nobody has touched robots.txt.liquid, there is nothing to fix in this layer, and you don’t need an llms.txt app.