3 minTime to key
YesNo-human path
0Gates to a test key
9/10Onboarding score
Live keys only:Email verificationManual reviewWaitlist
Fastest path to a key
- Agentic-commerce path (fastest): `npm install -g @shopify/ucp-cli` + `claude plugin install shopify-ai-toolkit@claude-plugins-official`; `ucp profile init --name agent`; `ucp catalog search ...` works with NO credenti…
- For Token tier: sign up / log in at dev.shopify.com (Dev Dashboard) -> Catalogs -> 'Get an API key' -> name -> Create -> copy client_id/client_secret -> exchange for a JWT bearer token at runtime.
- Admin approvalAdmin API path: Dev Dashboard account -> create free dev store -> `shopify app init` (Shopify CLI opens browser login) -> app installed on dev store -> Admin API access token.
- Merchant path with no developer work: add Claude connector https://setup.shopify.com/mcp (OAuth, CIMD) -> sign in to Shopify -> manage store / even create a business before a store exists.
- Working API key
Biggest gap
Completing checkout in-agent requires trusted-tier approval (most agents hand off to continue_url); Universal Cart behind a Google-Form waitlist; shopify.dev lacks a real llms.txt.
Worth copying
Tiered trust (anonymous -> signed profile -> token) lets agents start with no credential and upgrade; every doc page has a .md twin.
Sources (12) · checked 2026-10-11
- https://shopify.dev/docs/apps/build/ai-toolkit.md
- https://shopify.dev/docs/agents.md
- https://shopify.dev/docs/agents/get-started/quickstart.md
- https://shopify.dev/docs/agents/get-started/authentication.md
- https://shopify.dev/docs/agents/profiles/auth-and-rate-limiting.md
- https://shopify.dev/docs/agents/catalog/global-catalog.md
- https://shopify.dev/docs/agents/catalog/storefront-catalog.md
- https://catalog.shopify.com/api/ucp/mcp (probed: tools/list 200 unauthenticated)
- https://setup.shopify.com/.well-known/oauth-protected-resource
- https://setup.shopify.com/auth/.well-known/oauth-authorization-server
- https://claude.com/marketplace/connectors/shopify
- https://www.shopify.com/llms.txt
53Readiness score / 100
L2 Agent-documentedBeats 71% of 1,846 companies
Access20/20
Context20/20
Interfaces8/32
Onboarding3/19
Trust2/9
llms.txt · root
Biggest gains
- +12 Remote MCP server for the product. Host a remote MCP server (e.g. mcp.<domain>/mcp, Streamable HTTP) for your core actions.
- +8 Machine-readable API spec. Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
- +6 Agents can self-register OAuth clients. Support dynamic client registration (RFC 7591) or client ID metadata documents so MCP clients connect in one click.
All 20 checks
- PASSAgents get the real page, not a bot wall10
- PASSrobots.txt lets user-triggered agents in6
- PASSContent is server-rendered4
- PASSllms.txt exists8
- PASSllms-full.txt exists3
- PASSDocs available as markdown6
- PASSSitemap2
- PASSStructured metadata1
- PASSPublic developer docs4
- FAILMachine-readable API spec8
- FAILRemote MCP server for the product12
- FAILDocs MCP or searchable docs4
- PASSSDKs and a CLI4
- FAILOAuth discovery metadata5
- FAILAgents can self-register OAuth clients6
- FAILSelf-serve API keys5
- PASSFree tier or test mode3
- FAILAgent manifests4
- PASSsecurity.txt2
- FAILPublic status page3
Your fix pack: 9 changes, up to +47 points
Each change is ready to paste, filled in for shopify.com, with a command to check it worked. Or hand the whole list to your coding agent.
Add the badge to your README
[](https://agentsready.dev/c/shopify.com)