Agentic Commerce Journey Discovery to Transaction, Mapped
No7 Engineering Team
Growth Architecture Unit

Agentic commerce is shopping in which an AI agent finds, buys and follows up on a product for a shopper. Its journey runs from discovery to transaction: the agent finds a product, builds a cart, pays, then needs to know what happened to the order. At each step it asks your store for something specific. This guide maps that journey across the Agentic Commerce Protocol (ACP) documented by OpenAI, the Universal Commerce Protocol (UCP), Shopify’s agent tools and PayPal’s agentic services.
The agentic commerce journey, from discovery to transaction
Take a store selling running shoes when a shopper asks an assistant for a waterproof trail pair in size nine. The agent first needs to know the store stocks that pair (discovery). It then opens a session holding that item and a delivery method (checkout), and hands over a scoped payment credential (payment). Finally it needs to tell the shopper when the pair ships (order updates). Each of those four moments is a request your systems must answer, and each fails in its own way.
Step 1: discovery, where the agent learns what you sell
Discovery starts before any conversation. Under ACP the merchant publishes a product feed. The feed specification makes availability (in_stock, out_of_stock or preorder) and inventory_quantity required fields. OpenAI's reason is plain: accurate inventory data means shoppers only see items they can actually buy. A feed that lags behind your stock loses the sale before it starts, because the agent offers an item you cannot ship.
UCP takes a different route. A business publishes a profile at /.well-known/ucp. It holds three registries: services, capabilities and payment_handlers. Per the UCP overview, each capability declares what functionality is supported and where to find its documentation and schemas. Businesses also advertise whether they offer an MCP transport through that same profile.
On Shopify, the Storefront Catalog MCP server lets an agent search a single merchant’s catalogue. It follows the UCP Catalog capability’s tool names and request and response shapes. Shopify points cross-merchant discovery, such as comparison shopping, to the Global Catalog MCP instead. PayPal’s Store Sync connects your catalogue and commerce API to PayPal’s agentic services, though PayPal lists it as in limited availability.
Step 2: cart and checkout, where the agent builds an order
Once the shopper picks something, the agent opens a checkout session. In ACP that is POST /checkout_sessions. According to the checkout specification, it takes the item details and returns a unique session ID with line items, messages and the available fulfilment options. The create call should respond with a 201 status. Every later change, whether to items, shipping or discounts, goes to POST /checkout_sessions/{checkout_session_id}. Fetching a session that does not exist with GET /checkout_sessions/{checkout_session_id} returns a 404. A session’s status is one of four values: not_ready_for_payment, ready_for_payment, completed and canceled.
UCP's REST checkout updates a session with PUT /checkout-sessions/{id}, sending the buyer’s email, the line items and a shipping fulfilment method with a destination address. On Shopify, the Checkout MCP tools (create_checkout, get_checkout, update_checkout, complete_checkout and cancel_checkout) manage the active purchase session from the store’s own MCP endpoint, so the session logic is Shopify’s rather than yours.
Step 3: payment, where the agent hands over a credential
Unless you run your own PCI DSS level 1 vault, your systems should never handle raw card details. In ACP, OpenAI sends the payment details to your payment service provider (PSP), or to your own PCI DSS level 1 vault, through POST /agentic_commerce/delegate_payment, which creates a delegated payment token. The payment specification requires a payment_method, an allowance, risk_signals and metadata in the request body, with an optional billing_address. The token is scoped to the allowance and is then passed in the complete_checkout call, which completes the session (status completed) and creates the order. Confirm your PSP enforces the allowance when the token is used, rather than treating it as a field you pass through. Our agentic payments checkout architecture guide goes deeper on this step.
UCP handles the same step through the payment_handlers registry in the business profile. On Shopify, the complete_checkout tool finalises a checkout through the MCP endpoint. It needs a valid token, the checkout ID and the payment details, and Shopify’s example calls it only once the checkout status is ready_for_complete. For Braintree merchants, PayPal's Agent Ready lets them accept payments from AI shopping assistants such as ChatGPT, Google AI Mode and Gemini without a separate integration for each platform.
Step 4: order updates, where the agent learns what happened
The journey does not end at payment. ACP's checkout specification requires the merchant to publish order lifecycle events to the webhook URL OpenAI provides, so ChatGPT can tell the shopper what is happening with fulfilment. The events cover an order being created and an order being updated, and an order's status can be created, manual_review, confirmed, canceled, shipped or fulfilled. Under UCP, the agent platform’s profile declares the order capability (dev.ucp.shopping.order) with a webhook_url, which is where your order events go. If your order system only emails the customer, the agent is left guessing, and so is the shopper who asked it. Our guide to agentic commerce risks covers what goes wrong when these signals are missing.
What does the agent ask for at each step?
The journey at a glance
| Step | Agent asks | Merchant returns | Failure mode |
|---|---|---|---|
| Discovery | What do you sell, and is it in stock? | An ACP product feed or a UCP profile and catalogue | Stale inventory shows items the shopper cannot buy |
| Checkout | Create and update a session | Session ID, line items, fulfilment options, status | Retrieving a missing session returns 404 |
| Payment | Pay without exposing card data | A completion call that accepts the PSP’s delegated token, or a declared UCP payment handler | Raw card data in the merchant’s systems, or no limit on the token |
| Order updates | What happened after payment? | Order lifecycle events to the agent platform | The shopper gets no status from the agent |
The minimum viable set for your store
Do this first: fix discovery data, the step that fails silently. A feed or catalogue with accurate stock matters more than early checkout work. An agent that offers an item you cannot ship damages the sale before payment is even attempted. Then decide which protocol you are implementing, rather than trying to cover all of them at once.
If you run on Shopify, the catalogue and checkout MCP servers are Shopify's own, so most of your work is data quality and order status. If you run on another platform and want ChatGPT checkout, the ACP checkout endpoints and the order webhooks are yours to build. The delegated payment endpoint comes from your PSP unless you run your own PCI DSS level 1 vault. If you also want UCP-based agents to find you, publish a UCP profile at /.well-known/ucp declaring your capabilities and payment handlers. For the protocol background, see our guides to Shopify's UCP and agent defaults and to GPT-5.5 and agentic commerce on Shopify.
Where to start this week
- Pull your current product data and check two fields for every live item: whether it is in stock and how many units you hold.
- Compare them with your warehouse figures before you touch any endpoint, because that gap is what an agent will expose first.
- List the order statuses your system already tracks and map each one to the six ACP order statuses, to see which events you could publish today and which need new plumbing.
- Only then scope the checkout work, starting with the session create, update and retrieve calls and the 404 on retrieve, and ask your PSP whether it supports delegated payment.
If you would rather have a team build and test that integration with you, see our Shopify development services.
Frequently Asked Questions
The questions buyers and engineers ask us most about this topic.
What does an AI agent need from a store during discovery?
Accurate product data. Under ACP that is a product feed in which availability and inventory_quantity are required fields; under UCP it is a business profile at /.well-known/ucp whose capabilities declare what is supported and where their documentation and schemas live.
How is an agent purchase paid without card details reaching the merchant?
Under ACP, OpenAI sends the payment details to the merchant's payment service provider, or to the merchant's own PCI DSS level 1 vault, through POST /agentic_commerce/delegate_payment. That creates a token scoped to the allowance, which is then passed in the complete_checkout call.
Does a Shopify store have to build the checkout endpoints itself?
No. Shopify's Checkout MCP tools, such as create_checkout, update_checkout and complete_checkout, manage the purchase session from the store's own MCP endpoint, so the session logic is Shopify's. The merchant's work is mainly product data quality and order status.