GAIPGoverned Agentic Intelligence Platform

The agent-commerce record

Publish what your shop commits to agents, in one file.

An agent asks
What does shop.example commit to agents on returns?
GAIP answers
What its file says (returns: 30 days, say), the date GAIP read it, the file's hash and a signed receipt; or that the shop has published no file.
The call
GET /v1/free/agent-commerce/check?host=shop.example or the MCP tool gaip_check_agent_commerce

One small file on your own domain says what your shop commits to agents: checkouts, returns, delivery, which agents it admits. GAIP reads it and answers any agent that asks. Publishing it is also your opt-in to GAIP's scheduled reads of your public product pages.

  1. Make the file. Choose from the lists below; the JSON is built in your browser.
  2. Publish it. At /.well-known/agent-commerce.json on your domain, by hand, with the Action, or in one click in GAIP's Shopify app (coming soon, not yet available).
  3. Agents read the record. The check answers with your commitments as read, the file's hash and a signed receipt.
SIGNED 2026-10-10
Agent-commerce recordac81b5805b47

The shop's file, read on 2026-10-10, says what is listed below.

Checked 2026-10-11T12:28:58Z

shop
www.gaipagents.com
state
PUBLISHED_AS_INDEXED
checkouts
OWN_SITE
agents admitted
ALL
reference price
NONE_SHOWN
read
2026-10-10T18:30:41Z
file sha256
3499f5928c2e41247c8db25b7924f1e765c3345e71acaf3be8356ab16983f9f3
signature
OwTid9b_NKyQ6GxCTEjeMCkZR3ER6Y1IW7vRg8uzClb7TXdaEok5C77E3NaKHXU-1zMT0kEFVrTb6Gn-nChlDw

Signature checks against GAIP's public keys /.well-known/gaip-receipt-keys.json

The shop's own agent-commerce file as GAIP read it at the stated time; the shop may not have published one, or may have changed it since. Not a statement that the shop accepts, admits or honours anything.

GAIP's own record, read as every shop's is. The shop's file says; GAIP records what it said and when. Not a statement that any shop accepts, admits or honours anything.

Details everything else about this product

The file

JSON, schema gaip.agent-commerce.v1, at most 64 KiB, at https://<your host>/.well-known/agent-commerce.json (a Shopify-hosted shop: the app writes it at /apps/gaip/agent-commerce.json, the second place GAIP looks). Fields: host, published_at, version, commitments, an optional signature (yours; provenance only) and gaip_indexing (the notice, word for word). commitments: price_honoured_against_feed (true, false or null, with feed_url); returns {days, url}; delivery {regions[], url}; checkouts_supported[] (OWN_SITE, UCP, ACP, SHOPIFY_AGENTIC, PAYPAL_ACS, OTHER); agents_admitted (ALL, SIGNED_ONLY, LISTED_ONLY, NONE) with listed[]; reference_price_policy {basis (PRIOR_30_DAY_LOW, RRP, OWN_PRIOR_PRICE, NONE_SHOWN), url}; dispute_contact {url or email}; evidence_custodian {verifier_url, keys_url}. Free text nowhere except URLs: every value is from a vocabulary or a number, and a file with free text is refused. Schema: /agent-commerce/schema.json.

GAIP's own file

The first record on record is GAIP's, labelled as the example: /.well-known/agent-commerce.json. GAIP sells nothing, so it names its own site as the checkout, admits every agent, shows no reference prices and names its own verifier as custodian.

{
  "schema": "gaip.agent-commerce.v1",
  "host": "www.gaipagents.com",
  "published_at": "2026-10-10",
  "version": "1",
  "commitments": {
    "price_honoured_against_feed": null,
    "feed_url": null,
    "returns": {
      "days": null,
      "url": "https://www.gaipagents.com/terms"
    },
    "delivery": {
      "regions": [
        "WORLDWIDE"
      ],
      "url": "https://www.gaipagents.com/terms"
    },
    "checkouts_supported": [
      "OWN_SITE"
    ],
    "agents_admitted": "ALL",
    "listed": [],
    "reference_price_policy": {
      "basis": "NONE_SHOWN",
      "url": "https://www.gaipagents.com/terms"
    },
    "dispute_contact": {
      "url": "https://www.gaipagents.com/v1/free/observatory/corrections"
    },
    "evidence_custodian": {
      "verifier_url": "https://www.gaipagents.com/receipt-verifier",
      "keys_url": "https://www.gaipagents.com/.well-known/gaip-receipt-keys.json"
    }
  },
  "signature": null,
  "gaip_indexing": "GAIP reads every file published at /.well-known/agent-commerce.json (or, on a Shopify-hosted shop, at /apps/gaip/agent-commerce.json) on the hosts it watches, weekly and on a host named in a check, and indexes it: the host, the commitments as published, the dates GAIP first and last saw the file, its sha256, version and read time. A dispute e-mail address is kept only as present. Publishing it is the shop's opt-in to GAIP's scheduled reads of its public product pages. A host's owner can ask for its rows to be removed through https://www.gaipagents.com/corrections."
}

Make your file

Choose from the lists and give your URLs; the file is built in your browser as you type and nothing you enter is sent to GAIP. Save it at https://<your host>/.well-known/agent-commerce.json (a Shopify-hosted shop: the app writes it at /apps/gaip/agent-commerce.json), or let the Action below publish it from your repository.

  • OWN_SITE: The shop's own website checkout.
  • UCP: The Universal Commerce Protocol checkout (Google).
  • ACP: The Agentic Commerce Protocol checkout (OpenAI and Stripe).
  • SHOPIFY_AGENTIC: Shopify's agentic storefront checkout.
  • PAYPAL_ACS: PayPal's agentic commerce services.
  • OTHER: A checkout the file does not name with one of the other words.

  • ALL: The file says any agent may use the checkouts it lists.
  • SIGNED_ONLY: The file says only agents that sign their requests (for example RFC 9421 or Web Bot Auth) may.
  • LISTED_ONLY: The file says only the agent endpoints in listed[] may.
  • NONE: The file says no agent may; a person completes the purchase.

  • PRIOR_30_DAY_LOW: A struck-through or 'was' price is the lowest price the shop charged in the prior 30 days.
  • RRP: A struck-through or 'was' price is a recommended retail price.
  • OWN_PRIOR_PRICE: A struck-through or 'was' price is a price the shop itself charged before.
  • NONE_SHOWN: The shop shows no struck-through or 'was' prices.

GAIP keeps an e-mail address only as present.

(the file appears here as you fill in the form)

The format, its schema, the Action template and GAIP's example file are published under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/), as every GAIP format is.

Publish it from your repository

A GitHub Action you copy to .github/workflows/agent-commerce.yml: on every change to agent-commerce.json it checks the file against GAIP's schema with a small dependency-free script and commits it to .well-known/agent-commerce.json, which your site then serves. Template: /agent-commerce/action.yml. Nothing is sent to GAIP; GAIP reads the published file like anyone.

The check

GET /v1/free/agent-commerce/check?host=<shop> and the record by date GET /v1/free/record/agent-commerce?host=<shop>&on=<YYYY-MM-DD>, or the MCP tool gaip_check_agent_commerce on /mcp/all. Free, no key. Every answer is one of three states with the commitments as read, the file's sha256, read time and version history, and carries a receipt signed by GAIP (purpose gaip.agent_commerce_check.receipt_sha256.v1; check it with the receipt verifier):

  • PUBLISHED_AS_INDEXED: The shop's file, as GAIP last read it on or before the date, was published; its commitments are shown as read, with the file's sha256 and read time.
  • WITHDRAWN_AS_INDEXED: The shop had published a file, and on the date GAIP's last read had found it gone (the date is stated).
  • NO_RECORD: GAIP had read no file at this shop's path on or before the date. No record is not a bad sign: most shops have not published one yet.

Try it: https://www.gaipagents.com/v1/free/agent-commerce/check?host=www.gaipagents.com

The shop's own agent-commerce file as GAIP read it at the stated time; the shop may not have published one, or may have changed it since. Not a statement that the shop accepts, admits or honours anything.

What GAIP keeps

GAIP reads every file published at /.well-known/agent-commerce.json (or, on a Shopify-hosted shop, at /apps/gaip/agent-commerce.json) on the hosts it watches, weekly and on a host named in a check, and indexes it: the host, the commitments as published, the dates GAIP first and last saw the file, its sha256, version and read time. A dispute e-mail address is kept only as present. Publishing it is the shop's opt-in to GAIP's scheduled reads of its public product pages. A host's owner can ask for its rows to be removed through https://www.gaipagents.com/corrections.

Privacy: /privacy#agent-commerce; terms: /terms#agent-commerce. The format, its schema, the Action template and GAIP's example file are published under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/), as every GAIP format is.