2026-10-07 · Guides
Is your WooCommerce store ready for ChatGPT checkout?
A shopper asks ChatGPT for a linen apron and buys one without ever opening a browser tab. That flow is real now, and it runs on open standards rather than a deal with any one shop. Which means the question "is my store ready?" has an answer you can check, instead of an answer you have to wait for.
There are two protocols, they do different jobs, and almost every confused article about this conflates them.
ACP and UCP are not competitors in the way people think
ACP — the Agentic Commerce Protocol. Maintained by OpenAI and Stripe, Apache-2.0, currently in beta. This
is the one behind ChatGPT's checkout. It is a REST API that your store exposes: ChatGPT calls
POST /checkout_sessions to start a cart, updates it, and calls /complete to turn it into an order. The
important part, and the part most people miss: you stay the merchant of record. The order lands in your
system, the payment runs on your payment provider's rails, and tax and compliance stay yours. OpenAI is not
becoming the shop.
UCP — the Universal Commerce Protocol. Apache-2.0, at ucp.dev. This one is about discovery. Your store
publishes a JSON profile at /.well-known/ucp saying what it can do — which checkout capabilities, which
payment handlers, which protocol version — and any agent platform can read it and configure itself. No
integration call, no onboarding form.
A useful way to hold them apart: UCP is how an agent finds out what your store can do. ACP is how ChatGPT actually puts an order through it.
What WooCommerce gives you today, honestly
Neither protocol is in WooCommerce core. There is no setting to switch on.
- ACP comes from your payment provider. Stripe co-maintains the spec, so if you take payments through Stripe that is the path to watch. Check your provider's agentic-commerce or Instant Checkout documentation rather than waiting for a WooCommerce release.
- UCP needs something to publish the profile and answer the endpoints it advertises. Today that means a checkout integration that implements UCP. Very few WooCommerce stores have one.
If an article tells you to "enable ACP in WooCommerce settings", it is describing a screen that does not exist.
So what is actually worth doing this week
Here is the part that matters, and it is slightly annoying: the protocol work is not where your risk is. Both ACP and UCP assume an agent has already decided your product is the right one. That decision happens earlier, from your product pages, and it is where almost every store fails.
When we checked 100 WooCommerce stores from the WooCommerce showcase in September, 55 of the 76 reachable product pages had Product structured data — a good number. Four of them carried a GTIN or an MPN. An agent that cannot identify your product will not get as far as your checkout, however good your checkout is.
So, in order:
1. Give every product an identifier and a brand
A SKU is an internal code and means nothing outside your business. The identifiers that travel are the GTIN
(the barcode, from the manufacturer or GS1) and the MPN (the manufacturer's part number, which needs a brand
alongside it). WooCommerce 9.2 added GTIN, UPC, EAN and ISBN as a built-in field on the product's Inventory
tab.
Do not invent barcodes. A fabricated GTIN either collides with a real product or fails validation, and it gets the product disapproved in Google Merchant Center. An empty GTIN field is a truthful statement that a product has no barcode; a wrong one is a problem you get to find twice.
2. Check that the data reaches your page's structured data
Filling the field in is half of it. Open a product page, view source, find the application/ld+json block and
look for gtin, mpn and brand. Whether they appear depends on what generates that schema — your theme, an
SEO plugin, or WooCommerce itself — and having all three is the usual reason a page ends up with two Product
blocks that contradict each other.
3. Check that agents can reach you at all
Three things quietly block the whole thing:
- robots.txt.
GPTBotis how OpenAI crawls for training and discovery;OAI-SearchBotandChatGPT-Userare how ChatGPT fetches pages for a user. Blocking the first is a reasonable choice; blocking the other two makes you invisible in the answer. - Your CDN or firewall, which can rate-limit a bot to a 429 while every browser sails through. This is separate from robots.txt and does not show up in WordPress at all.
- A byte-order mark. If a theme or plugin file was saved as "UTF-8 with BOM", three invisible bytes go out before every response, including the WooCommerce Store API's JSON. Browsers ignore them. Strict JSON parsers — which is to say, every machine reading your store — reject the response. We have seen this cost a real store a whole check.
4. Then, and only then, look at a UCP profile
If your checkout integration supports UCP, the profile at /.well-known/ucp must be JSON whose ucp member
carries three things: version, services and payment_handlers. The last two are required even when they
are empty objects — that trips people up. capabilities is optional, and capability names use reverse-domain
form like dev.ucp.shopping.checkout. Service endpoints must be https and should not end in a slash.
If you support older protocol versions, declare supported_versions mapping each one to its own complete
profile URL, so a platform can pick a version you both speak.
Pin the version you checked against
Both specs move. ACP has shipped dated releases through 2026 and is still marked beta; UCP versions its protocol by date too. A "we're ACP-ready" claim with no date on it is not worth much in six months. When you check, write down which version you checked against — our free plugin names the spec version in the audit for exactly this reason.
The short answer
Your store is "ready for ChatGPT checkout" when:
- every product has a brand and a real identifier, and those reach the page's structured data;
OAI-SearchBotandChatGPT-Userare not blocked in robots.txt or by your CDN;- the Store API returns clean JSON with no BOM;
- and your payment provider supports ACP, which is the one part you cannot do yourself.
Three of those four are yours today. The fourth is worth one email to your provider.
Check your store in 10 seconds
The free online checker runs 5 outside checks on your store, including this one, and gives you a score out of 5.
The free plugin runs all of these from inside WordPress, including the UCP profile check and an information-only note on ACP, and names the specification version it judged you against.