Articles

Agentic commerce protocols explained

Usually fixed by: E-commerce platform admin · Typical effort: weeks

Agentic commerce protocols let an AI assistant buy from your store on a person's behalf without filling in your checkout pages. The person says "yes, buy it" in the assistant, and the order arrives in your systems like any other. Several protocols have been announced in a short time, by different companies, and the names are easy to mix up. This guide explains what each one is for, what it means for your store, and what to ask your platform.

Why protocols, when agents can use checkout pages?

A browser agent can shop through your website, and for now that's how most agents buy. We cover that journey in how to make checkout work for AI shopping agents. But checkout pages were built for people. An agent filling them in has to guess at fields, cope with pop-ups and CAPTCHAs, and usually hand back to the person to pay.

A protocol replaces the page-filling with a structured conversation between the assistant and your store:

  • The assistant asks for a product, variant, quantity and delivery address.
  • Your store answers with the real total, shipping options, tax and any errors, in data rather than on a page.
  • The person approves the purchase inside the assistant.
  • Payment is passed in a form that proves the person authorized it, without the assistant seeing raw card numbers.
  • Your store creates the order and stays responsible for fulfillment, returns and customer service.

The protocols you'll hear about

This is a young and fast-moving area. The descriptions below are deliberately brief, and the protocols' own documentation is the place for detail. Programs, eligibility and regions change often.

ProtocolWho's behind itWhat it covers
Agentic Commerce Protocol (ACP)OpenAI and StripeCheckout between an AI assistant and a merchant. It's the protocol behind buying inside ChatGPT, and it has been published as an open specification.
Universal Commerce Protocol (UCP)Google, with industry partnersA broader standard for agents to discover what a store supports and complete checkout. A store publishes a profile at /.well-known/ucp.
Agent Payments Protocol (AP2)Google, with payments industry partnersThe payment step specifically: a way to prove that a person authorized an agent to make a purchase, designed to work with different payment methods and alongside other protocols.

Card networks and payment providers have also announced their own programs for payments made by agents. Most of these sit underneath the protocols above, at the payment layer, rather than competing with them.

Checkout and payment are different jobs. ACP and UCP are about the shopping conversation and creating the order. AP2 is about trusting the payment. A store may end up supporting more than one, often without knowing, because the platform and payment provider handle it.

What it means for your store

  • Assistants become a sales channel. Supporting a protocol can let a person buy from you without leaving the assistant they asked. That puts you in front of shoppers at the moment they decide.
  • You stay the merchant. In the protocols announced so far, the store keeps the order, the customer relationship and responsibility for fulfillment. Check the terms of any program you join.
  • Your data has to be right. An assistant will quote the price, stock and delivery date your feed or API returns. Mistakes become disappointed customers at scale. See product data AI shopping agents can read.
  • Fraud and risk rules need a second look. Orders arrive without the usual browser signals. Ask your payment provider how it scores them.
  • Returns and support still come to you. Make sure your team can see which orders came through an assistant.

How stores get support

Very few stores will build a protocol integration themselves. Support usually arrives in one of three ways:

  1. Through your commerce platform. Hosted platforms are adding protocol support for the stores they run, sometimes as a setting you switch on.
  2. Through your payment provider. Some providers handle the agent-facing checkout and payment for you.
  3. Through an AI platform's merchant program. Some assistants ask merchants to apply, and review product data and policies before listing them.

If you run a custom stack, the specifications are public, but budget for real engineering: order creation, tax, shipping, inventory and payment all have to behave exactly as they do on your site.

Questions to ask your platform and payment provider

  • Which agentic commerce protocols do you support today, and which are planned?
  • Is it on by default, or do we need to enable it or apply?
  • Which product data does it use, and how do we keep it in sync with the website?
  • How are agent orders marked in our order system and analytics?
  • How are fraud screening, chargebacks and refunds handled for agent orders?
  • Can we limit it to certain products, countries or order values while we learn?

What AgentScore checks

For stores, AgentScore includes the Access check "Agents can check out through an agentic commerce protocol". It's skipped for sites that aren't stores.

It can only see what a store publishes openly. Today that means a Universal Commerce Protocol profile: the scanner requests /.well-known/ucp, and if it gets back a JSON document, the check passes.

The Agentic Commerce Protocol is different. Integrations are set up privately between each store and each AI platform, so there's nothing on your site for a scanner to find. If you support ACP but not UCP, this check will still show a warning. That's a limit of what can be seen from outside, not a problem with your store. The advice in the report names both protocols.

A warning here costs little. The check has a small weight in the Access category, because most agents still shop through the website, and that's where the checks that decide whether agents can get in and get through checkout matter more. Those include bot protection, CAPTCHAs at the cart and checkout, and guest checkout.

Where to start

  1. Fix the website journey first. Make sure agents can get in, read your product pages and reach checkout. Every protocol relies on the same product data and policies.
  2. Get your product data in order. Accurate prices, variants, stock and delivery times in structured data and in any product feeds you publish.
  3. Ask the questions above of your platform and payment provider, and turn on what's available.
  4. Watch how agents arrive. Track agent visits and the orders that come from assistants, so you can tell whether a protocol is earning its keep. See how to measure AI agent traffic and tracking visits and sales from AI assistants.

Agentic commerce protocols will keep changing for a while. The stores best placed to benefit are the ones whose websites, data and policies already work for agents, because that's what every protocol is built on.

← All articles Test your site with AgentScore →

Can AI agents use your site?

Get your free AgentScore in under a minute. No sign-up needed.