Shopify agent traffic

Operated by Shopify

Transacting agent Intermediary access

What it does

Agent traffic originating from Shopify commerce surfaces.

How to identify it

User agent
None published. This agent is not distinguishable from an ordinary browser at the user agent layer.
Request signing
Serves a directory at https://www.shopify.com/.well-known/http-message-signatures-directory but it contained no keys when checked.
IP ranges
Not published.
robots.txt
Not applicable.
First seen
2025-10

Worth knowing

Shopify serves a Web Bot Auth directory with the correct content type but, when checked on 26 July 2026, it contained no keys. The endpoint is in place and the capability is not yet active. This is a good illustration of why checking for a 200 is not the same as checking that verification works.

Operator documentation