Agent-pickable goods

What it takes for another person's AI agent to find, trust, buy from and pay a business · reading pack for the Agency Lab question · October 2, 2026
Reading packStrengthen Harness › BuildingAgency Lab

The short answer

"Trivially pickable" means a shopper's agent can find your thing, understand it, act on it and pay for it, with no human clicking through your website. That takes four layers. 1. Be findable: a clean, machine-readable list of what you sell. 2. Be callable: a way for an agent to ask questions and place orders (an API or MCP server). 3. Know who's asking: the agent proves what it is, and the person proves they sent it. 4. Get paid: a checkout an agent can complete without seeing the card number.

For most small businesses this month, layers 1 and 4 come from flipping switches in Shopify, Stripe or Google Merchant Center and then cleaning up the product data. Layers 2 and 3 are where a consultancy earns its fee. The open question for the Agency Lab is not "how do we let every agent in" but "which agents do we let in, and on what terms": Amazon just showed that saying no is also a choice.

What's happening now

The four layers

1 · Be findable: machine-readable inventory

In plain words: a spreadsheet-like list of every product, with price, stock, photos, shipping and returns, kept fresh. Agents can't squint at a pretty web page; they read the list.

Current approaches. Schema.org Product/Offer markup (hidden labels on your product pages) per Google's merchant listing guide. Product feeds: OpenAI and Stripe's Agentic Commerce Protocol feed (CSV, TSV, XML or JSON, updates every 15 minutes) and Google's Universal Commerce Protocol, which added live catalog access in March and onboards through Merchant Center. Shopify's Catalog now syndicates products to ChatGPT, Copilot and Google AI Mode, switched on by default for eligible stores (Shopify). llms.txt (a short Markdown map of your site for AI) is on about 9% of top-1,000 sites, but there is no proof the big assistants use it (Rankability, llmstxt.org). Cheap to add; don't sell it as a growth lever.

This month: confirm the platform's agent channel is on; fill every product field (GTIN, size, colour, return policy); fix stale prices and stock; add Product markup and run Google's Rich Results Test.

2 · Be callable: an action surface

In plain words: a front door built for software, not for eyes. An agent can ask "is this in stock in size 10?" or "book Tuesday at 3" and get a structured answer.

Current approaches. An MCP server or an OpenAPI-described API (OpenAPI is a machine-readable menu of your API); ! Primers/api-mcp-primer.html covers when to use which, so it isn't repeated here. New this year: WebMCP, a proposed web standard from Google and Microsoft that lets a normal website label its forms and buttons as tools for in-browser agents, in a Chrome origin trial (a public test run) from Chrome 149 (Chrome). The platforms' own route is a merchant app inside ChatGPT, which is where OpenAI moved checkout.

This month: retailers on Shopify or Stripe can mostly wait; their platform is the action surface. Service businesses (booking, quotes, availability) are the gap: one small MCP server with three to five job-shaped tools is a realistic Agency Lab build.

3 · Know who's asking: agent-friendly auth

In plain words: two questions. Is this a real, named agent, not a scraper? And did a real customer send it, with what permissions? Muse was blocked on the first question.

Current approaches. Agent identity: Web Bot Auth, where an agent signs every web request with a key it publishes, so sites can check it; Cloudflare's signed-agents program launched with ChatGPT agent, Block's Goose and Browserbase, and site owners can allow or block signed agents as a group (Cloudflare). Customer delegation: OAuth 2.1 (the "approve this app" screen, with scoped tokens that limit what it can do). The MCP authorization spec builds on it for protected servers and favours requesting the smallest scope first. Sign in with ChatGPT is the same plumbing with ChatGPT as the identity provider. Account linking: UCP lets a shopper's loyalty pricing follow them into an agent.

This month: write an agent policy (who's allowed, what they may do, what needs a human); if on Cloudflare, turn on bot management and decide on signed agents; for any API, use OAuth with narrow scopes, never shared passwords.

4 · Get paid: agent payment rails

In plain words: the agent pays you without ever holding the customer's card number, and there's a signed record of what the customer actually approved.

Current approaches. Stripe's Shared Payment Token is a one-use stand-in for the card, locked to one merchant and one cart total, sold through its Agentic Commerce Suite with Wix, Squarespace, Etsy and WooCommerce on board (Stripe). Shop Pay is the Shopify route, live in Muse. Google's AP2 uses signed "mandates" (a signed note of what the buyer asked for and approved) to prove intent, cart and payment (Google Cloud). Card-network tokens and x402 micropayments are in ! Primers/agent-payments-primer.html.

This month: use the processor you already have; turn on its agentic option if offered; check fraud rules don't auto-decline agent traffic; decide who eats the refund when an agent buys the wrong thing.

Readiness checklist

Score each 0 (no), 1 (partly), 2 (yes). Under 10 of 24 is "invisible to agents"; 18+ is "pickable". This is the seed of an Agency Lab audit.

#QuestionLayer
1Every product or service has price, availability, photos and an ID in one structured list.Findable
2Prices and stock in that list update at least daily.Findable
3Product pages carry schema.org Product/Offer markup that passes Google's test.Findable
4Shipping, returns and terms are published as data, not only in prose.Findable
5The store's agent channel (Shopify Catalog, Merchant Center/UCP, ACP feed) is switched on.Findable
6An agent can check availability and place an order or booking without a browser (API, MCP or platform app).Callable
7Tool or API descriptions are written for a model: few, job-shaped, plain.Callable
8There is a written agent policy: who's allowed, what they may do, what needs a human.Who's asking
9The site can tell a signed agent from a scraper and allow or block by group.Who's asking
10Customer access uses OAuth with narrow scopes, never shared passwords.Who's asking
11Checkout accepts an agent payment token (Stripe SPT, Shop Pay or similar).Get paid
12There's a rule for refunds and disputes on agent purchases, and agent orders are tagged so they can be counted.Get paid

Reading list

  1. Start here: Shopify, How agentic commerce works: the clearest picture of the "list once, show up in every agent" model most small sellers will live in.
  2. Digital Commerce 360, OpenAI shifts checkout plans: the reality check. Discovery works; in-agent checkout stumbled.
  3. Tech Times, Amazon blocks Muse: why "who's asking" is now a business decision, not just a technical one.
  4. Google, UCP updates: catalog access, carts and identity linking in one open standard.
  5. ACP product feed spec: what a feed an agent can read actually contains, field by field.
  6. Cloudflare, Signed agents: the plainest explanation of agents proving who they are.
  7. MCP authorization spec: skim the overview for how a customer hands an agent narrow permissions.
  8. Stripe, Agentic Commerce Suite: the one-integration route to agent payments for small sites.
  9. Chrome, WebMCP origin trial: the likely future for ordinary websites; worth watching, not selling yet.

What I couldn't verify