Agentic Checkout: How AI Agents Complete Ecommerce Purchases
How agentic checkout works step by step, from cart and checkout session to payment, order and webhooks, with idempotency, signatures and error handling.
Quick answer
Agentic checkout is a purchase an AI agent completes for a shopper through the merchant's own checkout system. The agent creates a checkout session with the selected items, the merchant returns authoritative prices, tax and fulfillment options, the agent adds buyer and delivery details, the shopper confirms, the agent completes the session with a payment credential, and the merchant charges, creates the order and sends updates by webhook.
The merchant is in charge throughout: it calculates totals, decides whether to accept the order, processes payment and remains merchant of record. The engineering challenges are the classic ones made sharper by automation: idempotency, authentication, signatures, retries, clear errors and order consistency.
The complete flow
The sequence below follows the two main open specifications, the Agentic Commerce Protocol (ACP, checkout API in the 2026-04-17 release) and the Universal Commerce Protocol (UCP, checkout capability in the 2026-08-25 release). Names differ slightly; the shape is the same.
Agent Merchant (authoritative)
│ 1 Product: agent picks variant ID from feed/catalog
│ 2 Cart: items + quantities
│ 3 POST create checkout session ─────▶ validate items, stock
│ ◀──────────── session: line items, prices, status=incomplete
│ 4 Buyer info (email, phone) ────────▶
│ 5 Fulfillment address ──────────────▶ shipping options
│ ◀──────────── fulfillment options + costs
│ choose option ────────────────────▶
│ 6 Pricing ◀──── totals: items, discounts, shipping
│ 7 Tax ◀──── tax calculated by merchant
│ ◀──────────── status=ready_for_payment / ready_for_complete
│ ✓ shopper reviews totals and confirms (in the agent UI)
│ 8 Payment: complete session + delegated / tokenized
│ credential, Idempotency-Key ─────▶ risk checks, charge via PSP
│ 9 Order ◀──── status=completed + order id + link
│ 10 Webhook ◀── order.created / shipped / delivered (signed)
│ 11 Confirmation shown to shopper; receipt by email from merchantStep by step
| Step | What happens | Authority |
|---|---|---|
| Product | Agent selects a specific variant ID from feed or catalog data | Merchant catalog |
| Cart | Items and quantities assembled; some protocols have a separate cart object | Agent proposes; merchant validates |
| Checkout session | Created on the merchant; returns line items, availability and status | Merchant |
| Buyer information | Contact details added; identity linking may connect an existing account | Shopper consents via agent |
| Fulfillment | Address supplied; merchant returns shipping or pickup options and costs | Merchant |
| Pricing | Discounts and totals calculated | Merchant |
| Tax | Calculated for the destination | Merchant |
| Payment | Agent completes the session with a scoped credential | Shopper authorizes; PSP and merchant process |
| Order | Merchant accepts or declines; returns order ID | Merchant |
| Webhook | Order and fulfillment updates sent to the agent platform | Merchant (signed) |
| Confirmation | Agent shows confirmation; merchant sends its usual receipt | Both |
Authoritative merchant state
The single most important rule: the merchant's checkout session is the source of truth. The agent may have seen a price in a feed an hour ago; the session's totals are what the shopper pays. UCP states that the checkout state reported by the business is authoritative, and ACP describes the merchant validating orders, calculating tax and fulfillment, assessing risk, charging payment and accepting or declining orders. Agents must display the merchant's totals for confirmation and never compute their own.
Session statuses
Both specifications use explicit statuses so the agent knows what to do next. ACP's checkout session statuses include incomplete, not_ready_for_payment, requires_escalation, authentication_required, ready_for_payment, pending_approval, complete_in_progress, completed, canceled, in_progress and expired (ACP specification). UCP uses incomplete, requires_escalation, ready_for_complete, complete_in_progress, completed and canceled (UCP checkout). Map your internal checkout states to these precisely; ambiguous states are where duplicate charges and stuck orders come from.
Idempotency and retries
Agents, networks and platforms retry. ACP requires an Idempotency-Key header on every POST. UCP is precise about the complete operation: the platform must not start a new complete while the status is complete_in_progress; if a response is lost, it should poll the session with bounded backoff; only if the outcome is still unknown may it resend the identical request with the same key; and reusing a key with a different payload returns a 409 conflict. Implement idempotency at the payment and order-creation layers too, not only at the HTTP edge.
Key takeaway
A lost response to 'complete' is the most dangerous moment in agentic checkout. Poll for state before retrying, and retry only with the same idempotency key.
Authentication and signatures
The merchant must know which agent platform is calling and that requests were not altered. ACP requests carry authorization and an API version, with optional request signature and timestamp headers. UCP uses HTTP Message Signatures (RFC 9421) with published keys, and requires webhooks from business to platform to be signed. Verify signatures and timestamps, reject replays, rotate keys, and scope each platform's credentials to the capabilities it needs. Agent identity is separate from shopper authorization and from payment authorization; see AI commerce payments and verifying AI agent traffic.
Error handling
Return errors an agent can act on: a type, a machine-readable code, a human-readable message and the field concerned. Distinguish recoverable problems the agent can fix (invalid address, variant out of stock, price changed: show new totals) from those that need the buyer (authentication required, policy acceptance, age verification), which should escalate with a continue URL rather than fail silently. Never let an agent complete a session whose totals changed since the shopper confirmed; return to confirmation.
Order consistency
After completion, the agent platform, the shopper and your systems must agree on the order. Create the order atomically with the payment outcome, return the order ID in the completion response, send signed webhooks for every state change, make webhook handling idempotent on the receiving side, and provide an order lookup so either side can reconcile. Mark agent orders with their channel for operations and analytics; see orders placed by AI agents.
Implementation checklist
- Checkout session endpoints backed by your real pricing, tax, inventory and fulfillment logic
- Feed and checkout share product and variant IDs
- Explicit status mapping, documented and tested
- Idempotency keys enforced on all writes, including payment and order creation
- Request authentication, signature verification and replay protection
- Typed errors; escalation with a continue URL for buyer-only steps
- Re-confirmation when totals change
- Atomic order creation with payment; signed, idempotent webhooks
- Channel tagging and reconciliation reports
- Sandbox tests for retries, timeouts, price changes and stock-outs
Implementing checkout for AI agents?
ZSpace Labs builds checkout APIs, payment integrations and order webhooks for Shopify and custom commerce platforms. See Shopify development and full-stack development.
Conclusion
Agentic checkout moves the checkout form from your website into an agent's conversation, but not the responsibility. Keep the merchant's session authoritative, map statuses precisely, enforce idempotency and signatures, return actionable errors, escalate to the shopper when needed and keep orders consistent with signed webhooks. For the API around it, see agent-ready ecommerce API, and for protocol differences, ACP vs UCP vs MCP.
Common questions.
Agentic checkout is a purchase completed by an AI agent on a shopper's behalf through the merchant's checkout system: the agent creates a checkout session, supplies buyer and fulfillment details, receives authoritative totals from the merchant, passes a payment credential and receives the order.