Your Shopify store publishes an instruction file for AI shopping agents — and nothing in admin mentions it

Short answer. Every Shopify store already serves five agent-facing URLs that Shopify turns on for you: /agents.md, /llms.txt, /llms-full.txt, /.well-known/ucp and /sitemap_agentic_discovery.xml. The first three are the same document. None of them carries your product data (that travels a second path, Shopify Catalog) and the robots.txt rules written to keep AI crawlers out do not govern it.

Want to know if your store has this right now? Check my store, free 2 min · read-only

There is no screen in Shopify admin called "AI agents". There is no setting that created these files and no notification that they appeared. They are simply there, on your domain, answering any agent that asks.

This page is a reference for what those URLs actually contain, checked against Shopify's own documentation and against eight live storefronts fetched on 23 September 2026. It is deliberately not a list of things to change: Shopify maintains most of this surface, and says so. What it asks of you is to know the files exist, because the one decision that transfers them to you is easy to take by accident.

The five URLs your store already serves

Shopify's help documentation states plainly that "Every Shopify store automatically serves the following discovery URLs that AI agents can read to learn how your store works", and names three of them: /agents.md, described as "your canonical agent discovery URL, which is the source of truth and the primary location for agent discovery information", plus /llms.txt and /llms-full.txt, which it describes as "compatible with older AI crawlers that search for the specific URL conventions".

Two more sit alongside them. /.well-known/ucp is a machine-readable profile for the Universal Commerce Protocol, which its own site describes as "the common language for platforms, agents, and businesses" and lists as co-developed by a group that includes Shopify and Google. And /sitemap_agentic_discovery.xml is a child of your ordinary sitemap index, sitting next to the products, collections, pages and blogs children you already know about.

I fetched all five paths on eight live Shopify storefronts on 23 September 2026, as Googlebot, following redirects by hand. All five returned 200 on all eight stores, with bodies between 4,192 and 4,602 bytes for the four text and JSON files. Separately, of ten storefronts whose sitemap index I requested, nine returned one, the tenth reset the connection, and all nine listed sitemap_agentic_discovery.xml as a child. Eight and nine stores are small samples and I am not presenting them as a rate; what they establish is that this is platform behaviour rather than something a particular theme or app added, which is the only claim the rest of this page needs.

The agentic sitemap itself is the smallest file on your store. On the four I opened it ran between 205 and 220 bytes and contained exactly one URL, /agents.md, with a changefreq of weekly. It is not a catalogue. It is a signpost, so that an agent-first crawler can find the discovery file without walking a sitemap index that ran to 181 children on the largest of the stores checked here.

The three "different" files are one document

The filenames mislead here, so it is worth being precise. /llms-full.txt sounds like a fuller export of /llms.txt. It is not.

Shopify says so first: by default, "all three URLs return the same content". And the measurement agrees, more precisely than the sentence does. On one store I downloaded all three and compared them byte for byte: /agents.md was 4,388 bytes, /llms.txt 4,431 and /llms-full.txt 4,436. The diff between them is a single line, line 66, and that line differs only in naming which file you happen to be reading. /llms.txt says the canonical description is at /agents.md and that you are reading a mirror of it; /agents.md says it is that canonical description. Everything else is identical.

So the practical reading is: there is one agent-facing document per store, served at three addresses for compatibility. If you have been told to audit three files, you have one file to read. And if you were expecting /llms-full.txt to contain your catalogue, nothing generates that for you: you would have to write it, by adding the matching Liquid template to your theme.

What the discovery file actually says

The managed document is written for an agent, not for a shopper. It opens by identifying the store and its URL, then covers four things:

  • How a personal shopping assistant should transact: through Shopify's own Shop skill, rather than by scripting your storefront.
  • The Universal Commerce Protocol endpoints, the protocol versions the store supports, and a six-step flow running from discovery through search, cart and checkout.
  • The rules an agent has to respect. Two are worth knowing as a merchant: checkout requires explicit buyer approval, and the endpoint is rate-limited per IP.
  • Read-only ways to browse the store, such as the product page and the product JSON endpoints.

The UCP discovery document at /.well-known/ucp is the machine-readable version of the middle part. On the two stores I opened it, it returned application/json and named a current protocol version of 2026-08-25, with 2026-04-08 and 2026-01-23 still listed as supported. Three dated versions inside eight months is the detail the last section of this page turns on.

One detail is worth checking rather than assuming: on both of those stores the transaction endpoint named in the discovery document was on the myshopify.com domain, not the custom domain I had requested. Shopify's developer documentation notes separately that the file itself is "served at the bare primary domain, without a locale or Shopify Markets subfolder prefix", so the document and the endpoint it advertises do not necessarily live on the same host.

StoreCanary checks this on your store

Curious what your storefront actually returns when it isn't you asking? Our scan reads your public storefront the way a crawler does: product by product, read-only, no admin access, about 2 minutes. It checks the markup, prices, availability and indexing directives on your product pages; it does not read the agent discovery files described here.

Scan my store for free

Shopify Catalog is a second path, and robots.txt does not reach it

Here is where a reasonable assumption goes wrong, and it goes wrong in a direction that matters if you have ever tried to opt out.

The discovery files are not your product data. Shopify states that "Shopify Catalog is the authoritative product data feed to your agentic channels" and that "The agent discovery files are separate from Shopify Catalog, and they don't replace any Shopify Catalog capabilities". Catalog is described as syndicating products "with their title, description, options, images, price, availability, and other key attributes".

So there are two paths into an AI channel. One is the open web: a crawler fetches your pages, reads your markup, follows your sitemap. The other is Catalog: a feed leaving Shopify directly. And the sentence that decides how you reason about the pair is this one, from the same page: "Blocking AI crawlers at the /robots.txt or network layer affects only open-web discoverability. It doesn't stop your product data from being sent by Shopify Catalog to the agentic storefronts that you've activated."

That is worth reading twice if you have ever added a Disallow for an AI user agent to robots.txt.liquid and considered the question settled. It was settled for one path. Shopify also notes, in the same section, that "The rules that you set in your /robots.txt file are directional and advisory, and not all crawlers are guaranteed to follow them", the same property that makes an accidental Disallow on your product pages such an effective way to disappear from Google, working here in the opposite direction.

The genuinely blunt instrument is on the product itself, and it is blunt in both directions. Shopify's guidance for completely hiding a product from AI channels is to set its status to Unlisted, with an explicit caution attached: doing so "also hides the product from sitemaps, search engines such as Google, and your online store search". That is not an AI setting. That is a visibility setting, and a product set Unlisted for one reason will quietly stop being findable on Google for every other reason too.

One narrower exclusion applies automatically: "Products that are sold exclusively to business or wholesale customers are automatically excluded from AI channels when Shopify can identify them". Note the closing clause: it is a conditional, not a guarantee, and it is Shopify's own wording rather than a hedge of mine.

How to read your own store's agent surface in five minutes

None of this requires a tool, an app or admin access. It is five requests against your own domain and one comparison.

  1. Open your sitemap index and look for the agentic child. Request /sitemap.xml on your primary domain. Alongside the products, collections, pages and blogs children you should see sitemap_agentic_discovery.xml. Read the host on each child URL while you are there: on one of the nine stores checked here, the agentic child was listed on a different hostname from the one I had requested. If the index itself does not answer, that is a separate and more urgent problem.
  2. Fetch the three discovery files and compare them. Request /agents.md, /llms.txt and /llms-full.txt. Expect 200 and a few kilobytes each. Then diff them. By default they are one document; if one of them differs substantially, your theme carries a template overriding that URL and somebody on your side owns its contents from that moment on.
  3. Read what the file says about your store. Check that the store name, the store URL and the policy links are the ones you want an agent quoting. The managed file deliberately carries no contact details. Anything wrong here is wrong in the document Shopify itself calls the canonical agent discovery URL.
  4. Fetch the UCP discovery document and check the host. Request /.well-known/ucp. It returns JSON naming the protocol version your store advertises, the older versions it still supports, and the endpoint an agent is told to transact against. On both stores I checked, that endpoint was on the myshopify.com domain rather than the custom one.
  5. Separate the two paths before changing anything. Work out which path you are actually trying to control: the open web, or Catalog. Shopify states that crawler blocking affects only the first. Editing the wrong one changes nothing while looking exactly like it worked, which is the worst outcome available here.
  6. Re-read the files after any theme or domain change. A theme swap can introduce or remove an overriding template; a domain change moves the address these files describe. Nothing in admin lists these URLs, so re-reading them on a schedule is the only thing that tells you they still say what you expect.

What changes under you

Most of this surface is maintained for you, and that is genuinely good news: Shopify's developer documentation says "Shopify manages an agents.md file by default for every store. For most stores, the managed file is all you need." Left alone, it tracks the platform.

The decision that changes that is adding a custom template. Shopify supports it: agents.md.liquid overrides all three URLs, while llms.txt.liquid and llms-full.txt.liquid override one each, and a URL-specific template wins over the general one. The same documentation attaches the cost in one sentence: "When you add this template, you hand-edit the Liquid template and take responsibility for keeping its content current."

Now put that next to the three dated protocol versions in the discovery document: 2026-08-25, 2026-04-08, 2026-01-23. A managed file follows that movement. A hand-written one describes the day it was written, and it will keep describing that day through every subsequent version, theme update and domain change, because nothing in Shopify admin displays these URLs and no report anywhere flags a stale one. The template is not the risk. The template plus the absence of any signal that it has drifted is the risk, and it is the same shape as every other failure this blog covers: not hard to fix, impossible to notice.

So if an app or an agency offers to "optimise" these files for you, there is one question worth asking before you agree: who re-reads it, and how often. Taking ownership of a file the platform was maintaining is a trade, not a free upgrade.

Where this leaves the product data you already check

It would be neat to conclude that everything this blog documents about product markup now matters twice over. That is not what the documentation says, and the honest version is more useful.

Because Catalog is the authoritative feed to agentic channels, a defect in your page's structured data is not automatically a defect in what an agent is told. The two paths take different inputs. A price of zero in your JSON-LD, an availability value disagreeing with your real stock, or a merchant-listing field your theme never emits are failures on the open-web path, where Google's crawler and its structured-data reports live. They are the reason a product can be perfectly in stock in admin and absent, or wrong, in a search result.

What the arrival of a second path changes is the shape of the question. There is now more than one description of your catalogue in circulation, each maintained by a different mechanism, each invisible from the same admin screen, and only one of which you can inspect by looking at your own page source. Shopify's own advice for the Catalog path is not a trick, it is to focus on "having complete and well-structured product information in Shopify Catalog", but "complete and well-structured" is a claim about thousands of records that no screen summarises.

Being clear about our own boundary, because the temptation to claim otherwise is obvious: StoreCanary does not read /agents.md, the UCP endpoints or Shopify Catalog. We read your public storefront the way a crawler does, product page by product page, and report the markup, pricing, availability and indexing directives that decide whether a page a crawler can reach is one Google can actually list. That is the open-web path, and it is the one you can still inspect from outside. For the agent path, the files above are what you have, and reading them yourself twice a year is not a bad habit, because nothing is going to remind you.

Is this happening on your store right now?

AI agents and shopping assistants read your catalog through the same feed and the same markup as Google's own crawlers, not through a chat window. If a product is unreadable to Google, it is unreadable to them too, and nothing in Shopify admin will tell you. The only way to know is to check the pages the way a crawler sees them.

  • 90+ checks, the way crawlers and AI agents read your store. Structured data, feed data, redirects, noindex.
  • Read-only. No app to install, no admin access, nothing changes on your store.
  • The exact fix for each page, in plain English, so you or your developer can act the same day.

Across full-catalog scans of more than 90,000 Shopify product pages, roughly 46% of stores had at least one critical Google visibility issue.

Scan my store for free

Free scan: issue types, counts and first fixes. Full report on every product page, not a sample: $49 once, no subscription.

Next in this cluster