Agentic commerce readiness
Agent commerce involves product information, permitted actions and a supported checkout path. A readiness review records which steps work and where the test stops.
Automatic purchasing is one authorized path among several, not the default behaviour of every agent. A buyer grants it explicitly, often with a spending limit or a category restriction, and the agent then completes a checkout for that purchase without a person filling in the form. Agentic commerce readiness is the work of making a site one of those agents can actually transact with, rather than one it skips because the path is unclear or blocked.
What an agent needs to buy
An agent needs three things in machine-readable form. It needs to find the offer, with a price and currency it can parse rather than infer from a layout. An agent that works through an API needs a checkout it can drive through a protocol, since a page built for a mouse gives it nothing to call. A browser agent can fill in the same form a person uses, at the cost of reading a layout that can change under it. And it needs the purchase to behave predictably from the same starting state, so a repeated call with the same idempotency key returns the same result instead of creating a second order, and a price or balance that changes between the quote and the confirmation comes back as a fresh quote rather than a silent substitution. A catalog that looks perfect to a person can still be opaque to an agent on all three counts.
The protocols in play
Checkout is becoming a protocol rather than a page. OpenAI documents the Agentic Commerce Protocol as the connective layer between merchants and shoppers in ChatGPT. Google and Shopify introduced the Universal Commerce Protocol in early 2026, and it now carries its own discovery manifest at /.well-known/ucp. The discovery layer is settling on a small set of standards. An A2A Agent Card describes the interface, AP2 authorizes agent payments, ACP carries the checkout, and x402 lets an agent meet a price with HTTP 402 and continue. A site does not need all of them. It needs the ones its buyers' agents speak, declared where an agent looks.
Where the protocol draws the line
UCP writes down the boundary between what an agent may finish alone and what a person has to approve. Its checkout capability is a state machine, and one of its states, requires_escalation, means programmatic execution is blocked by something like age verification or a regulatory step. Escalation is not failure. The specification defines an Embedded Checkout Protocol, which is checkout's own use of the shared Embedded Protocol transport rather than a mechanism built for escalation alone. It can carry an embedded checkout through a whole session, including the steps where the buyer has to enter something or approve something. When the checkout state says requires_escalation, the platform can hand the buyer to a continue_url instead, so the session is not thrown away. The cart carries a signals object for abuse prevention, and the specification is explicit that its values must not be buyer-asserted claims. A site that treats escalation as a dead end loses the sale at the exact point where a human was willing to finish it.
Where sites fail the agent
Most catalogs lose the agent before checkout. A price that lives only in rendered HTML stops an agent that does not render JavaScript, a CAPTCHA wall stops one with no way to solve it, a maintenance interstitial stops any agent mid-flow, and a discovery file that claims a capability the endpoint does not answer stops one that trusted the file. Each one ends the purchase silently for the agent it stops. The agent does not complain, it moves to a competitor whose path resolves. The failure looks like no traffic rather than a broken page, which is why it goes unmeasured.
Readiness is testable
Whether an agent can buy is observable, the same way agent-readiness is. Declare the offer as structured data, expose a checkout an agent can call, publish the discovery files the protocols define, and back every claim with an endpoint that answers. Then test it the way an agent would, by driving the path end to end and watching where it stops. turva.dev built its own agent commerce surface this way, across A2A, AP2, ACP and x402, and an independent scanner checks its discovery files. The path stops on purpose before payment: the ACP checkout answers not_ready_for_payment and the x402 endpoint answers 402 whether or not a payment is sent, because turva.dev sells on a written quote. Tested 2026-09-28 by sending a POST to /api/acp/checkout_sessions and a GET to /x402: both answered exactly as described. The test shows where the path stops. It does not show a payment accepted or settled automatically.
For a Shopify store, the Shopify agent storefront check reads selected products across the browser WebMCP tools, the Storefront and UCP MCP and the Agentic Catalog, records the buyer journey up to the stop before payment, and delivers a correction plan. For a website or API, the audit covers the commerce surfaces among the rest.
Frequently asked
What does an AI shopping agent need in order to buy?
An offer with a price and currency it can parse rather than infer from a layout, a checkout it can drive, through a protocol for an API agent or through the page's own form for a browser agent, and a purchase that behaves predictably from the same starting state, so a repeated call with the same idempotency key does not create a second order and a changed price or balance comes back as a fresh quote.
What does requires_escalation mean in UCP?
That programmatic execution is blocked by something like age verification or a regulatory step. It is not failure. The Embedded Checkout Protocol lets a person complete the blocking step without the session being thrown away.
Why does a failed agent purchase look like no traffic?
A price that lives only in rendered HTML stops an agent that does not render JavaScript, a CAPTCHA wall stops one with no way to solve it, a maintenance interstitial stops any agent mid-flow, and a discovery file that claims a capability the endpoint does not answer stops one that trusted the file. The agent does not complain about any of them, it moves to a competitor whose path resolves.
Sources
- Universal Commerce Protocol (UCP)
- Agentic Commerce Protocol (ACP)
- Agent Payments Protocol (AP2) repository
- x402 protocol site