The State of Agentic Commerce — September 2026
Last month we closed with a single line: the event to watch is the first platform template declaring 2026-08-25 — everything else follows it. It took three days. On August 28 and 29, Shopify's template moved to the August release, and about 10,600 storefronts moved with it. A month ago two stores in the census declared 2026-08-25. Today 10,704 do.
It was not the only template that moved. Between September 17 and 19 Shopify turned on identity linking, and declarations went from 27 to 7,355. The week before, its catalogue search changed how it answers a generic query. And this morning, while we were writing this report, Wix began switching on cart across its fleet. By mid-afternoon it was halfway through. Meanwhile the question we have asked in every issue since May — who, other than Shopify, ships next? — finally has a long answer: fourteen commerce platforms we can identify now have at least one verified UCP store, from Riyadh to Santiago to Hong Kong.
This is the eighth monthly state-of-the-ecosystem report from UCP Checker. Here is what the data says as of September 22, 2026.
The numbers
What the score board says about the 17,767 verified stores in the census:
- Modal score 97. Six integer values hold 89% of all verified stores
- 16,544 A · 1,221 B · 2 C: 93% of the fleet in one grade band
- 60.2% on v2026-08-25, four weeks after release; the rest on 2026-04-08
- 0.14% declared-versus-actual gap on catalog (17,693 declared, 17,668 resolving)
- 14 named commerce platforms with a verified store
- 7,355 stores declaring identity linking, 7,332 of them naming an external identity provider
- 1 production merchant declaring a payment token
Figures are a point-in-time census as of September 22, 2026.
Two platforms still make up 98% of the verified fleet: Shopify with 10,632 stores and Wix with 6,929. That concentration is why everything below reads as a story about templates. It is also why the platform map, further down, is the part of this report most likely to change the picture.
August's watch list, answered
We end every report with what to watch. Here is how each item from August resolved.
| What we said to watch | September's answer |
|---|---|
| Whether any platform template declares 2026-08-25 | Shopify, August 28–29. 10,627 of 10,632 Shopify stores. Wix is still on 2026-04-08. |
| Where the score towers move | The top tower moved from 96 to 97. The cause is one capability, not a rescore (below). |
| The AP2 rename biting | 3 stores declare the new dev.ucp.common.payment.ap2_mandate. 6 still declare the old dev.ucp.shopping.ap2_mandate, two of them while declaring the version that retired it. |
signing_keys[] stragglers |
4 stores declare 2026-08-25 and still publish the removed signing_keys. 45 publish keys. |
| Identity linking's configured share | 27 declared became 7,355, nearly all naming one external provider. The August release also changed what "configured" means (below). |
| The first non-shopping vertical profile in the wild | A services profile on a live small business, plus food, travel and booking profiles on demo deployments. No live lodging profile yet, but lodging booking is now a complete draft in review. |
| Whether payment stays a lab phenomenon | One production merchant now declares a payment token. The other seven are development, demo or agency deployments. |
Three days: how the template moved
Sep 22: 10,704
The August report said a platform-led fleet migrates "in cohorts rather than a trickle," and that the version a store declares is the version its platform declares. Both held more cleanly than we expected. Five Shopify stores out of 10,632 are still on April's version. No Wix store is on August's. There is no middle.
The timing is the finding: August 28 and 29, three to four days after the release was tagged. That is not the release train we said to expect — QA, staged rollout, merchant comms over weeks. It is a platform that was ready on release day and shipped in a single wave.
The August release made this safe by design. A profile that declares a version must declare that same version on every dev.ucp.* entry, so each store sits wholly on one version or the other. There is no half-migrated store in the census. What an agent now meets instead is a fleet split cleanly by platform: August's schemas on Shopify, April's on Wix. The spec lets each business list the versions it supports and leaves the platform to pick one both sides speak, which is what keeps a split like this from breaking anything.
What the score says
Mode 97
The distribution is still a set of towers, not a curve, and the towers are still templates. Six integer values hold 89% of all verified stores, up from 84% in August. The tallest tower moved from 96 to 97, and the reason is visible in the score's own components. Shopify stores at 97 score 100 on Capability; Shopify stores at 96 score 97. The three points are identity linking. About 7,300 Shopify merchants now declare it, and each gains one point overall.
The scoring model did not change. It is still v1.0.0, fixed on August 25. The tower moved because stores declared something new, which is exactly what a versioned score is meant to show. Wix's towers sit lower, at 84–86, because its template declares fewer capabilities. That gap should narrow as Wix's cart rollout lands.
A month of platform events
2026-08-25. About 10,600 stores, in two days.In one month, the platforms changed thousands of storefronts at once four times, and only one of those changes followed a protocol release. Two added capability. One changed a version. One changed behaviour without changing a single declared field: Shopify's catalogue search stopped returning a default listing for a generic query and began matching it literally. Between September 10 and 14, roughly three in ten of the generic catalogue searches we ran came back empty. Agents searching for real products with real words were unaffected. A generic query like "popular products" now returns nothing on many stores that used to answer it.
This is the practical meaning of "the template is the unit of adoption." A merchant's agent readiness can change overnight without the merchant doing anything, in either direction. The only way to know is to look again tomorrow.
Wix turns on cart — today
August's platform split was total: Shopify stores declared cart and order at exactly 100%, Wix stores at exactly 0%. That changed this morning. On September 22, Wix storefronts began declaring dev.ucp.shopping.cart. By mid-afternoon UTC, 3,549 of 6,929 did. It is a staged rollout still in progress, not a switch flipped once.
The rollout is on the April version, and it adds cart only. Order is still at zero across the Wix fleet, and no Wix store has moved to 2026-08-25. The fleet-wide cart figure in this report (80%) is a photograph of a number in motion. By the time you read this it will be closer to 100% of Wix and about 99% of the whole fleet.
Who shipped next: the platform map
verified store: 6 → 14
Since May, every one of these reports has asked the same question: when does a second platform ship? August gave the first big answer (Wix). September gives a long list. Fourteen named commerce platforms now have at least one verified UCP store, up from six a month ago.
One caveat before anything else: some of this is us getting better at seeing. We added platform fingerprints for Salesforce Commerce Cloud, Boutir, Tiendanube and Cafe24 on September 16, and for Zid, Salla, Shoptet, Tray and Jumpseller on September 22. Some of those stores were already in the census as "custom". What is new is that we can now say whose template they run.
What the list shows is where UCP's second wave is being built. It is not mostly in the US:
| Platform | Home market | Verified | What the template declares |
|---|---|---|---|
| Salla | Saudi Arabia | 7 | Catalog, checkout, cart, order, identity linking — the full shopping surface |
| Zid | Saudi Arabia | 5 | Catalog only |
| Boutir | Hong Kong · Taiwan | 19 | Catalog, cart, checkout; no order |
| Cafe24 | South Korea | 3 | Full surface, on the platform's own test stores |
| Tiendanube | Latin America | 1 | Catalog, checkout, cart, order |
| Tray | Brazil | 5 | Catalog only |
| Jumpseller | Chile | 5 | Catalog and cart |
| Shoptet | Czech Republic | 0 of 5 | Publishing, not yet valid: the profiles omit the required payment_handlers |
| BigCommerce | US | 27 | Checkout, cart, order; no catalog |
The template rule holds on every platform here, including the small ones: within each platform, the stores declare the same thing. Zid and Tray publish catalog-only profiles, which make a store discoverable by an agent but not purchasable through the protocol. That is a legitimate first step, and it is the same order Wix took. Salla ships the full surface, identity linking included, on all seven stores we see.
Salesforce Commerce Cloud is the absence worth watching, and it has a date. At Dreamforce, Salesforce put UCP integration at general availability in October 2026. None of the 64 Commerce Cloud storefronts we track declare UCP today, which is what "GA in October" should look like in September. We wrote up what those storefronts publish before launch.
One more reading note. Several of the largest retailers named as UCP supporters publish no profile at /.well-known/ucp. That tells you about the public endpoint, not about whether a retailer is connected to an AI shopping surface through a direct integration. "No public profile" is the accurate description; "not using UCP" may not be.
Capability coverage
identity 27 → 7,355
The fleet-wide shape is now three steps rather than a cliff. The shopping core sits at about 99%, because every template declares it. Cart and order sit lower because Wix hasn't finished (cart) or hasn't started (order). Identity linking at 41% is new this month and belongs to one platform. Below that is the deep end, where the numbers are still counted in single digits: location (3 stores), payment token (8), AP2 on the new namespace (3).
Identity: from 27 to 7,355
Sep 22: 7,355
Last month we reported 27 stores declaring identity linking, 18 of them without configuring it, and said: if the declared number grows while the configured number doesn't, it is becoming decoration. The declared number grew 270-fold. The configured question needs restating, because the August release changed what "configured" means.
Under 2026-08-25, identity linking works in one of two ways. A store can name trusted external identity providers in config.providers, and accept a buyer's identity from them through the spec's accelerated IdP flow. Or it can name none, and the platform runs OAuth discovery directly against the store's own domain. That is what 7,332 Shopify stores do with the first path: every one of them names the same provider, app.shop.accounts, which is Shop's account service. They began declaring it between September 17 and 19, three weeks after the version move, which makes it a separate rollout. It is a real, resolvable configuration. It is also a single point: nearly all identity linking in the fleet now runs through one provider. It is the same sign-in Shopify uses in its reference storefront agent for Anthropic's Claude for Commerce blueprints: "a storefront shopping agent over UCP and Sign in with Shop."
That also retires August's "unconfigured" line. Under the current spec, a declaration without providers is not a gap: it tells the agent to discover the store's own OAuth server. Whether that server exists is a question for the agent's first request, not for the manifest, which is why we check it separately. About 30% of Shopify stores don't declare identity linking at all, which suggests it follows a store-level setting inside an otherwise identical template.
Payment: one merchant
August's honest test was a payment token on a production storefront belonging to a real merchant on a real platform. Eight verified stores now declare one. Seven are what we found in August: development deployments, a platform's demo storefront, an agency site, and one profile that declares payment under a namespace the protocol doesn't define.
The eighth passes the test. houseofparfum.nl, a Dutch perfume retailer on WooCommerce, publishes the most complete profile in the census. It runs 2026-08-25 with AP2 mandates on the new common.payment namespace, location search and lookup, identity linking and buyer consent. Its payment handler namespace, nl.zologic, is the WooCommerce plugin vendor behind it. It was one of three AP2 adopters in our June report, and it is on the current release.
One store is not a trend, and a declared token is not a transaction. But it is the first time the answer to August's question is yes. Everything else about payment stays where it was: the handler layer is dominated by three wallets and card handlers that platforms declare for their merchants (Google Pay on 10,678 stores, Shopify's card handler on 10,627, Shop Pay on 9,011), followed by a long tail of 50-odd namespaces. We'll take that layer apart in its own piece.
Verticals: lodging in draft, food in proposals
The first non-shopping profile on a live small business is a services one. A heating-and-cooling contractor's site on Wix publishes catalog, availability, bookings and paid bookings under the community dev.usp-protocol.services.* namespace, next to standard UCP checkout and dev.ucp.common.payment.terms. Alongside it, the census holds a travel profile (travel.ucp.*), an appointment-booking demo, and a food-ordering platform's demo storefront that uses the August release's location capability and AP2 mandates. No lodging profile has appeared yet. The primitives shipped in August; the implementations are starting to show up in ones.
On the specification side, lodging has pulled ahead of food. The Lodging Booking capability, dev.ucp.lodging.booking, now exists as a complete draft in the protocol's own repository, on a lodging/booking branch, with its schemas, REST and MCP bindings, and a cancellation-policy extension. It models a reservation as a session that is progressively enriched — property, stay, rate plan and dates first, then guests, booker and payment — before it is completed into an immutable booking. The business stays merchant of record, and unless the AP2 mandates extension is in play, the guest finalises the booking through a trusted UI. We covered the proposal when it was filed. Since then it has gone through review rounds on totals, warnings and guest identifiers. The latest revisions, on September 22, loosened hotel-specific room vocabulary so the same schema can describe other kinds of stay, and switched property images to the spec's media type. It is still in review, with changes requested, and not merged. A companion proposal (#808) adds deterministic schedules to lodging cancellation policies.
Food is a step behind. There is a Food Technical Council, but no food capability or branch yet. What exists are proposals about menus: nested options (#821) and selection rules for product options (#824). Both are open for discussion, and they tackle the modifier structure that makes restaurant menus hard to express with plain product variants.
dev.ucp.lodging.booking, on the lodging/booking branch: schemas, REST and MCP bindings, and a cancellation-policy extension. In review as #780, revised again on September 22. Not merged.We track each of these at ucpchecker.com/verticals, including the lodging and food pages and the services vertical we added this month.
Transport: settled
MCP is on 17,685 of 17,767 verified stores (99.5%). Embedded checkout is on 10,636 and REST on 7,091. REST rose by about as many stores as Wix added this month. A2A appears on 4 stores. Nothing moved this month, and nothing is likely to: MCP is the surface that reaches the whole fleet.
Beyond the census
Agent identity became a retail dispute. Meta launched Muse on September 8, a personal agent that shops by opening a browser and filling in forms, paying with a one-time card through Stripe's Link. On September 20–21, Amazon began blocking it. Amazon's stated reasons were that it wasn't told Muse would access the store, that the agent doesn't identify itself when it browses, and that it appears to capture and store customer credentials. Meta says Muse never sees passwords or payment details. The dispute is not about payment. It is about whether a store can know which agent is in front of it, and on what terms. That is the same question agent identification in protocols such as UCP is designed to settle before a checkout starts, and it will come up again wherever agents and stores meet without an agreed way to introduce themselves.
Salesforce named a date. UCP integration for Commerce Cloud is GA in October (our write-up).
Anthropic released Claude for Commerce on September 2: open-source reference agents for shoppers and for store operations. The blueprints are protocol-agnostic; UCP enters through Shopify's reference storefront, which connects them to a store through its Catalog, UCP and Shop Sign-in.
The size of it. Bernstein estimates agentic commerce at under 1% of e-commerce, even as generative-AI referrals approach a quarter or more of referral traffic at several large US retailers. Seventeen thousand verified storefronts is infrastructure waiting for traffic, not traffic.
Payments coalitions keep forming. Rain launched the Agentic Payments Alliance on August 18 with 26 founding members, including Visa, Mastercard, Fiserv and Circle, to work on agent authorisation, fraud signals and loyalty.
The spec and the councils
No new release this month; v2026-08-25 is still current. The Shopping Tech Council published its first minutes since the repository was reorganised for multiple councils (meetings from August 21 to September 18). The headlines:
- Next release: early December or January, timed to avoid the holiday freeze. Pillars include fulfillment, identity linking, returns and location, plus developer experience and WebMCP.
ask(#538) is high priority, with demand cited from large retailers. It must have no side effects and must not replace cart. Prompt-injection guidance is to be added to the spec alongside it.- Media variants (#690) and return policy (#634) are near sign-off. Returns and lodging cancellation will stay separate policies.
- Inventory stays out of public feeds. The council noted bots binary-searching checkouts to track sales velocity, and plans to decouple availability from sellability (pre-order and back-order).
- A UCP Summit is planned: one day on 2027 priorities, one on building with UCP.
- The Bulk Product Discovery working group kicked off on September 2 and meets weekly, targeting late October.
Adoption is also showing up as questions from outside the founding companies. In the spec's public discussions this month: an engineer whose GitHub profile lists Synchrony asked how BNPL and private-label credit cards sequence when the credential sits with an external provider (#832). An independent household-shopping app described evaluating UCP as its connection to grocery retailers (#830). And a developer asked about third-party access to a merchant's Cart API during a Home Depot pilot (#826).
What to watch in October
- Wix finishing cart, and whether order follows. Order is the last capability Wix's template doesn't declare. Its arrival would put the whole shopping core at ~99% of the fleet.
- Wix on 2026-08-25. The other half of the version split. When it moves, it will move in a day, like Shopify's did.
- The first Commerce Cloud manifest. GA is October. A single Salesforce template turning on would be the largest new-platform event since Wix.
- A second identity provider. Every external provider in the fleet today is the same one. The first store to name another would be the first sign of an identity layer rather than a single sign-in.
- A second production payment token. One merchant answered August's question. Two would be the start of a line.
- Shoptet's first valid profile. Five stores are publishing; the missing field is one line.
- Lodging Booking leaving review. A merged
dev.ucp.lodging.bookingwould put a second vertical capability into the next release, planned for December or January. The first live lodging profile would follow it. - The Muse dispute. Whether it resolves through agent identification, and where.
Eight months in, the argument has moved a third time. February asked whether stores would adopt. August asked whether the protocol could express a complete purchase. September showed how change actually arrives: four times in one month, a platform changed thousands of storefronts in a day, and the merchants didn't have to do anything. The question for the rest of the year is less whether the templates will move than which one moves next, and what it turns on when it does.
We'll see you in October.
About UCP Checker
UCP Checker is the independent validation and observability layer for the Universal Commerce Protocol. We crawl, validate and grade every public UCP manifest we can find, run the merchant directory, the UCP Score, live adoption stats, the vertical guides and the authority-bound vendor map, and track the spec as it evolves so you don't have to — measured from two vantages (what a business declares, and what actually happens when an agent transacts), the same way for everyone, without picking winners.
Check your domain's UCP status
See if your storefront is ready for agentic commerce in seconds.
Get the agentic commerce digest every Monday
Real adoption data, ecosystem trends, new spec versions, and the stores that broke or recovered this week. Read by founders and engineers building the next generation of commerce.

