Commerce Guide

Agentic Checkout in 2026: What Merchants Have to Implement to Sell Inside ChatGPT

ChatGPT does not become your shop. It becomes a front end calling yours. OpenAI's checkout spec is public and precise, and the most important line in it for an Indian brand is the list of accepted payment methods.

Distk Editorial Oct 2026 13 min read

OpenAI's Agentic Checkout Spec lets shoppers buy inside ChatGPT while orders, payments and compliance stay on your stack. You host five HTTPS endpoints that ChatGPT calls to create, update, complete, cancel and retrieve a checkout session, each returning the full cart with strict arithmetic: subtotal equals base amount minus discount, total adds tax. Requests arrive signed, with an idempotency key and an API version you must verify. Payment uses your existing PSP, with a single-use delegated token capped by a maximum amount and expiry, and you remain merchant of record for refunds and chargebacks, syncing them back by webhook. The constraint to read first: the current spec lists stripe, adyen and braintree as providers and card as the only accepted payment method, so a UPI-led Indian brand should check fit before scoping a build. Checkout also requires a separately enabled integration on top of approved-partner feed access.

What Is the Agentic Checkout Spec in 2026?

The Agentic Checkout Spec is OpenAI's published contract for letting a shopper buy your product inside ChatGPT while the order, payment and compliance stay on your own commerce stack. You implement five REST endpoints that ChatGPT calls, you return an authoritative cart state on every call, you process payment with your existing payment service provider, and you send order events back to OpenAI by webhook. ChatGPT never becomes the shop. It becomes a front end calling yours.

Checkout sits on top of discovery. OpenAI states that onboarding product feeds in ChatGPT is currently available to approved partners, and its feed specification says checkout requires a separately enabled integration. This guide is the checkout spoke in our guide to the Agentic Commerce Protocol product feed.

Read this before scoping a build in 2026

In the published spec, the PaymentProvider object lists three possible providers, stripe, adyen and braintree, and one accepted payment method, card. The Delegated Payment Spec likewise states the only accepted credential type is card. There is no UPI, wallet or bank-transfer value in the current spec. For an Indian D2C brand whose customers pay mostly by UPI, that is the first fact to put in front of the business case.

How Does an Agentic Checkout Flow Work in 2026?

OpenAI describes the flow in six steps, and the direction of each call matters: ChatGPT calls you, and you call OpenAI only for webhooks. Every session response must return the full cart state, including items, pricing, taxes and fees, shipping, discounts, totals and status.

  1. Create session. ChatGPT calls your POST /checkout_sessions with cart contents and buyer context.
  2. Update session. As the shopper changes items, shipping or discounts, ChatGPT calls POST /checkout_sessions/{checkout_session_id} and you return the full cart again.
  3. Order events. Your system publishes lifecycle events such as order created and order updated to the webhook OpenAI provides.
  4. Complete checkout. ChatGPT finalises with POST /checkout_sessions/{checkout_session_id}/complete, and you confirm the order and return the final cart and order identifiers.
  5. Cancel or retrieve. Optionally, POST /checkout_sessions/{checkout_session_id}/cancel and GET /checkout_sessions/{checkout_session_id}.
  6. Payments on your rails. You process payment with your existing PSP, accepting the delegated token if you use Delegated Payments.

OpenAI also notes that in the future the Agentic Checkout Spec will support MCP servers.

What Must Every Checkout Endpoint Handle in 2026?

Every endpoint must use HTTPS and return JSON, and every request from ChatGPT arrives with the same set of headers. Those headers are where most of the security and reliability work lives, because they carry authentication, the signature over the request body, the idempotency key, and the API version you must check.

HeaderWhat it carriesWhat you must do with it
AuthorizationAPI key used to make requestsAuthenticate every request.
SignatureBase64-encoded signature of the request bodyVerify it before acting.
TimestampRFC 3339 timeUse it as part of request validation.
Idempotency-KeyKey ensuring requests are idempotentReturn the same result for safe duplicates; echo it in the response.
Request-IdUnique key for tracingLog it and echo it in the response.
API-VersionAPI version, for example 2025-09-12Confirm it is present and matches a supported version.
Accept-LanguagePreferred locale for messages and errorsLocalise customer-facing messages.

What Does the Cart State Have to Contain in 2026?

Your create, update, complete and cancel responses all return the same shape: an ID, a status, a currency, line items, fulfilment options, totals, messages and links, with buyer and address details where present. The status values are not_ready_for_payment, ready_for_payment, completed and canceled. Currency follows ISO 4217 in lower case.

The arithmetic is specified, not left to interpretation. A line item's subtotal must equal base_amount - discount, and its total must equal base_amount - discount + tax, with every amount an integer of zero or more. Totals use types such as items_base_amount, items_discount, subtotal, discount, fulfillment, tax, fee and total, expressed in minor units. If your platform rounds tax per order but the spec expects per-line values that sum, this is where a build discovers it.

POST Request to /checkout_sessions

{
   "items": [
       {
           "id": "item_123",
           "quantity": 1
       }
   ]
}

That is OpenAI's own first example: a session created with a single item and no fulfilment address, which therefore cannot yet be completed. One detail worth checking when you implement: the example response in the same document shows a status of in_progress, which is not among the four status values the response table lists. Confirm the expected value with OpenAI during onboarding rather than coding to either.

How Do Shipping, Messages and Errors Work in 2026?

Fulfilment options come in two types, shipping and digital. A shipping option needs a title, a subtitle describing the timeline, a carrier, earliest and latest delivery times in RFC 3339, and a subtotal, tax and total where total equals subtotal plus tax. OpenAI's production guide notes the protocol models a single shipping address and one selected shipping option per session, and advises consolidating split shipments into a single buyer-visible selection with aggregate totals.

Problems are surfaced to the shopper as messages, not just HTTP errors. An error message carries a code from missing, invalid, out_of_stock, payment_declined, requires_sign_in and requires_3ds, plus an RFC 9535 JSONPath such as $.line_items[1] pointing at the part of the session it concerns. When a request cannot succeed at all, you return an error object with a 4xx or 5xx status.

ObjectKey fields in 2026Constraint worth knowing
Addressname, line_one, city, state, country, postal_codeline_one and city max 60 characters; state and country follow ISO 3166-1.
Buyername, email, optional phone_numberPhone numbers follow E.164.
Linktype and urlTypes are terms_of_use, privacy_policy, seller_shop_policies.
PaymentDatatoken, provider, optional billing_addressProvider is stripe, adyen or braintree.
Orderid, checkout_session_id, permalink_urlCustomers should reach the order by providing at most their email address.

How Do Delegated Payments Work in 2026?

The Delegated Payment Spec lets OpenAI share payment details securely with you or your PSP. The shopper saves a payment method in ChatGPT, a single-use payload with an allowance is sent to your PSP or vault, the PSP returns a token scoped to that payment, and OpenAI forwards the token on the complete call. OpenAI is not the merchant of record, and settlement, refunds, chargebacks and compliance stay with you and your PSP.

Who should integrate directly is stated precisely: direct integration is only for PSPs or PCI DSS level 1 merchants using their own vaults. For everyone else, OpenAI points to Stripe's Shared Payment Token as the first compatible implementation. The allowance is tight by design, with a reason that must be one_time, a max_amount, a currency, the checkout session and merchant IDs, and an expires_at timestamp.

On PCI scope, OpenAI's production guide says the feed and checkout specs are deliberately kept out of PCI scope and do not transmit cardholder data. Using your PSP's implementation of delegated payments may avoid any change in scope, while forwarding APIs or direct integration involve cardholder data and will likely be in scope. OpenAI says it may require your attestation of compliance before enabling production access, and recommends consulting your PSP and Qualified Security Assessor.

What Do the Webhooks Have to Send in 2026?

You send OpenAI webhook events on order creation and update so the buyer's view stays in sync, signed with an HMAC signature in a request header. Event types are order_created and order_updated. Order status values are created, manual_review, confirmed, canceled, shipped and fulfilled, and each event carries a list of refunds typed as store_credit or original_payment.

OpenAI's production FAQs add the operational consequence: because you are the merchant of record, you handle refunds and chargebacks, and you should use the order update webhook to notify ChatGPT when a refund or chargeback status changes. Customers see your name on their card statement, as if they bought directly from your site.

Who Should Build Agentic Checkout in 2026?

Teams whose payments already run on Stripe, Adyen or Braintree, whose customers mostly pay by card, and whose products and market are within what OpenAI has confirmed for their integration. For many Indian D2C brands, at least one of those conditions fails today. That does not make the specification irrelevant: the feed work is reusable, and knowing exactly what checkout requires lets you decide when it becomes worth building rather than guessing.

Readiness question for 2026If yesIf no
Accepted as an approved partner?Proceed to integration planning.Apply at chatgpt.com/merchants; prepare the feed meanwhile.
PSP is Stripe, Adyen or Braintree?Use the PSP's delegated payment path.Checkout is not buildable on the current spec.
Customers pay mostly by card?Checkout matches demand.Weigh demand before building; the spec accepts card only.
Can you compute per-line tax and totals that sum exactly?Cart state is straightforward.Fix pricing logic first.
Can you sign, verify, and handle idempotency?Security work is incremental.Plan engineering time for it.

Our production checklist guide covers the certification tests OpenAI requires before launch.

What Are the Common Mistakes With Agentic Checkout in 2026?

Key Takeaways for 2026

Distk helps D2C and e-commerce teams in India and internationally work out whether agentic checkout is buildable on their current payment stack, scope the integration honestly, and prepare the product feed that has to exist first. If agentic checkout is on your 2026 roadmap, that assessment is where we start.

Sources

Agentic Checkout in 2026: FAQs

What do merchants need to build for ChatGPT checkout?

Five HTTPS JSON endpoints that ChatGPT calls: create, update, complete and cancel a checkout session, and retrieve it. Each returns the full cart state. You also send signed order_created and order_updated webhooks, and process payment through your existing PSP.

Does ChatGPT checkout support UPI in 2026?

Not in the current published spec. The PaymentProvider object lists stripe, adyen and braintree, the accepted payment method is card, and the Delegated Payment Spec states card is the only accepted credential type. Indian brands whose customers mainly use UPI should weigh that before building.

Is OpenAI the merchant of record?

No. OpenAI states the merchant selling the goods and taking payment is the merchant of record. Customers see the merchant's name on their card statement, and the merchant handles refunds and chargebacks.

Who can integrate the Delegated Payment Spec directly?

OpenAI states direct integration is only for PSPs or PCI DSS level 1 merchants using their own vaults. Others should use their PSP's implementation, and OpenAI names Stripe's Shared Payment Token as the first compatible one.

Does agentic checkout put me in PCI scope?

OpenAI says the feed and checkout specs are kept out of PCI scope. Using your PSP's delegated payment implementation may avoid a change in scope, while forwarding APIs or direct integration involve cardholder data and will likely be in scope. Confirm with your PSP and QSA.

Can I ship one order in multiple packages?

The protocol currently models one shipping address and one selected shipping option per checkout session. OpenAI advises consolidating split shipments into a single buyer-visible selection and returning aggregate shipping and tax totals.

Check the payment fit before you scope the build

Distk helps D2C teams work out whether agentic checkout is buildable on their current PSP and payment mix, scope the integration honestly, and get the product feed ready that has to exist first.

Start the conversation →