Field Report

DialtoneApp | April 21, 2026

AI bot buying report: what agents can actually buy in 2026

Bot commerce is not one market. It is two markets wearing the same jacket. One side looks like retail stores teaching bots to read catalogs. The other looks like APIs teaching bots to pay for single HTTP actions.

That split matters. A shopping bot with a card and a budget can often get very far in a retail flow, but it still runs into checkout authority, fraud controls, shipping, and human consent. A wallet funded agent calling an x402 API can often finish the purchase in the protocol itself, but the goods are usually data, model calls, scraping, email, RPC, or agent skills.

This article is based on a local corpus of discovery examples, not a crawl of the whole internet. That limit is important. It is still enough to see the shape of the market: product discovery is becoming normal, autonomous settlement is ahead in API land, and credit card retail is close but still tangled in human checkout assumptions.

The corpus says the quiet part out loud

The internet is already publishing a lot of machine readable buying surface area, but it is uneven. Some files describe a product catalog. Some files describe a priced API. Some files describe an agent, a registry, or a marketplace. Some files only look useful until you inspect the payload and find an error wrapper or placeholder.

SurfaceCount
Total discovery files305
Site directories with discovery files148
well-known-ucp.json79
products.json77
Non empty product catalogs68
Product records in valid catalogs1,962
Variant price records in valid catalogs9,410
API like files93 across 59 sites
Agent like files43 across 28 sites
Total discovery files
305
Site directories with discovery files
148
well-known-ucp.json
79
products.json
77
Non empty product catalogs
68
Product records in valid catalogs
1,962
Variant price records in valid catalogs
9,410
API like files
93 across 59 sites
Agent like files
43 across 28 sites

The most useful retail signal is the UCP shopping pattern. It usually shows up beside a Shopify style products.json feed, which gives a bot product titles, vendors, types, tags, variants, prices, availability, and images.

UCP capabilities in the sample

CapabilityCount
dev.ucp.shopping.checkout77
dev.ucp.shopping.fulfillment77
dev.ucp.shopping.catalog.search75
dev.ucp.shopping.catalog.lookup75
dev.ucp.shopping.discount73
dev.ucp.shopping.order73
dev.ucp.shopping.cart72
dev.ucp.shopping.checkout
77
dev.ucp.shopping.fulfillment
77
dev.ucp.shopping.catalog.search
75
dev.ucp.shopping.catalog.lookup
75
dev.ucp.shopping.discount
73
dev.ucp.shopping.order
73
dev.ucp.shopping.cart
72

Payment handlers in the sample

HandlerCount
com.google.pay74
dev.shopify.card72
com.forter.tokenizer1
com.google.pay
74
dev.shopify.card
72
com.forter.tokenizer
1

Seven products.json files were not usable as normal catalogs. They were error wrappers, unrelated payloads, or site specific response objects instead of aproducts list. Two product lists were empty. That is useful too, because a serious buyer bot has to treat discovery files as evidence, not truth.

bot_purchase_readiness =
  discoverable_offer
  + explicit_price
  + callable_action
  + payment_authority
  + policy_boundary
  subtract checkout_ambiguity

Retail has the catalogs

The largest visible category is ordinary stores exposing bot readable catalogs and UCP shopping files. This is the world where an agent can browse variants, compare prices, prepare a cart, and sometimes initiate checkout.

CategoryExample sitesWhat they sell
Fashion, footwear, jewelry, bagswww.aloyoga.com, gymshark.com, www.reebok.com, www.campusshoes.com, redtape.com, giva.co, palmonas.com, mzwallace.com, www.davidsbridal.com, saya.pk, nishatlinen.com, libas.inApparel, shoes, bridal items, jewelry, bags, ethnicwear
Smart home, security, IoT, energyaugust.com, lockly.com, wyze.com, www.aosulife.com, kunasystems.com, shelly.cloud, www.brilliant.tech, www.ezlo.com, sensibo.com, ecoflow.com, avm.deSmart locks, cameras, routers, sensors, HVAC controls, power stations
Electronics, music, computing, media devicesboat-lifestyle.com, jbhifi.com.au, nzxt.com, fender.com, www.gibson.com, www.uaudio.com, nixplay.com, vaku.in, yotoplay.comAudio gear, instruments, plug ins, PCs, earbuds, photo frames, kids audio cards
Home, decor, kitchen, food, general goodsbrooklinen.com, parachutehome.com, daisonet.com, deodap.in, society6.com, www.pepstores.com, www.mccormick.comBedding, towels, kitchen goods, wall art, spices, home basics
Beauty, personal care, nutritiondiscoverpilgrim.com, glossier.com, innovist.com, www.gharsoaps.shop, bodybuilding.com, morenutrition.deMakeup, skincare, haircare, soaps, supplements, nutrition
Digital products and store softwaremyfonts.com, www.vwthemes.com, shrinetheme.com, www.hulkapps.comFonts, Figma templates, Shopify themes, Shopify apps
Books and publishingwww.versobooks.com, harpercollins.com, worldofbooks.comBooks, audiobooks, publishing catalog items
Travel, outdoor, sportawaytravel.com, www.decathlon.comLuggage, bags, tents, bikes, outdoor gear

Many retail feeds looked sampled. A lot of sites exposed exactly 30 products. That is a discovery entry point, not necessarily complete inventory. The correct bot behavior is to treat the feed as a start, then use the advertised lookup, search, cart, checkout, order, fulfillment, and discount capabilities to move toward a live transaction.

APIs have cleaner prices

The most automation ready category is not physical retail. It is paid API work. These services frequently publish OpenAPI specs with fixed endpoint prices, request schemas, response schemas, and payment requirements. A bot can often know the price before it calls the endpoint.

ServiceWhat it sellsPricing signal
anybrowse.devBrowser backed scraping, Google result crawling, SERP JSON, screenshots, MCP accessPrices such as $0.002, $0.003, and $0.005 USDC per request
stableemail.devEmail sends, inboxes, custom subdomains, message reads, top ups$0.02 to send email, $1 for an inbox, $5 for a subdomain, $0.001 to read messages
api.zeroreader.com, blockrun.ai, openrouter.ai, x402engine.appAI model access or AI tool callsPriced API work instead of a retail cart
x402stt.dtelecom.orgSpeech to text through an x402 proxyA narrow paid capability with a clean HTTP shape
publish.new, pull.mdDigital artifact publishing, purchase, and downloadsThe file is the product
well-knowns.resolved.shDatasets and queryable indexes of well known endpointsA very bot shaped data market
What it sells
Browser backed scraping, Google result crawling, SERP JSON, screenshots, MCP access
Pricing signal
Prices such as $0.002, $0.003, and $0.005 USDC per request
What it sells
Email sends, inboxes, custom subdomains, message reads, top ups
Pricing signal
$0.02 to send email, $1 for an inbox, $5 for a subdomain, $0.001 to read messages
What it sells
Speech to text through an x402 proxy
Pricing signal
A narrow paid capability with a clean HTTP shape
What it sells
Digital artifact publishing, purchase, and downloads
Pricing signal
The file is the product
What it sells
Datasets and queryable indexes of well known endpoints
Pricing signal
A very bot shaped data market

Crypto, chain, and financial data services are even more aligned with bot buying. The customer is already software. The buyer often has a wallet. The product is often one result, one request, one dataset, one signed fact, or one RPC call.

ServiceBot commerce shape
x402.quicknode.comPay per request blockchain RPC access with SIWX auth, credits, network discovery, and JSON RPC calls
api.nansen.aiSmart money and market analytics
emc2ai.ioAgentEinstein crypto intelligence skills including whale tracking, market movers, security scanning, and DeFi operations
api.myceliasignal.comSigned financial data and oracles across crypto, FX, commodities, and macro data
x402.aibtc.comInference and blockchain utilities using x402 v2 on Stacks
x402scan.comIndexed x402 payment data, merchants, transfers, and stats
Pay per request blockchain RPC access with SIWX auth, credits, network discovery, and JSON RPC calls
AgentEinstein crypto intelligence skills including whale tracking, market movers, security scanning, and DeFi operations
Inference and blockchain utilities using x402 v2 on Stacks
Indexed x402 payment data, merchants, transfers, and stats

The registry and routing layer is the third API shaped cluster. These products are not always selling the final good. They sell discovery, trust, routing, registration, and coordination for other agents or paid APIs.

ServiceWhat it coordinates
a2alist.aiDirectory of A2A and x402 implementations, registration, and discovery
agentndx.aiRegistry for MCP servers, A2A agents, and x402 services
agoragentic.comAgent OS and marketplace router with registration, routing, execution, and commerce surfaces
payanagent.comMarketplace for agents and SaaS services to discover, hire, and pay each other using x402
relai.fiMarketplace and management layer for x402 protected APIs, service keys, pricing, and analytics
asterpay.ioTrust scoring, merchant payment endpoint discovery, and settlement
scoutscore.aiTrust verification for x402 services
api.actiongate.xyzx402 plus Stripe billing proxy for APIs and MCP servers
Directory of A2A and x402 implementations, registration, and discovery
Registry for MCP servers, A2A agents, and x402 services
Agent OS and marketplace router with registration, routing, execution, and commerce surfaces
Marketplace for agents and SaaS services to discover, hire, and pay each other using x402
Marketplace and management layer for x402 protected APIs, service keys, pricing, and analytics
Trust scoring, merchant payment endpoint discovery, and settlement

Hybrid SaaS is messier. These files often name plans and prices, but the live flow still depends on browser checkout, account creation, recurring consent, or a billing provider that is not fully active yet.

SiteHybrid signal
dialtoneapp.comA commerce manifest for a $9.00/month membership, offer lookup, and a ready purchase intent endpoint with browser checkout fallback.
www.inerrata.aiPlan tiers from free to enterprise, card metadata, x402 support for API endpoints, auth and delegation details, and a pre launch billing state
www.hulkapps.comShopify app product catalog with prices
shrinetheme.comShopify theme and support products
A commerce manifest for a $9.00/month membership, offer lookup, and a ready purchase intent endpoint with browser checkout fallback.
Plan tiers from free to enterprise, card metadata, x402 support for API endpoints, auth and delegation details, and a pre launch billing state

What a bot can buy with a credit card and a budget

The strongest credit card pattern in this sample is UCP shopping plus a payment handler. The bot reads well-known-ucp.json, confirms shopping capabilities, loads product data, filters variants, builds a cart under budget, adds fulfillment details, and then tries a handler such as com.google.pay ordev.shopify.card.

retail_card_flow:
  read: well-known-ucp.json
  confirm: catalog, cart, checkout, fulfillment, order
  load: products.json
  filter: price, availability, variant, shipping_required
  enforce: caller_budget
  pay_with: com.google.pay | dev.shopify.card
  fallback: human_approval | browser_checkout | issuer_challenge
SiteCatalog strengthPayment signalBot can probably do
www.aloyoga.comApparel feed with variants and pricesUCP shopping, Google Pay, Shopify cardSearch apparel, choose represented size or color, build cart, start checkout
wyze.com / wyzecam.comCamera and smart home catalog with prices and availabilityUCP shopping, Google Pay, Shopify cardBuy cameras and accessories subject to account and payment checks
parachutehome.comBedding and towel catalog with bundles, prices, imagesUCP shopping, Google Pay, Shopify cardBuy home goods and bundles under budget
brooklinen.comBedding, towels, home catalogUCP shopping, Google Pay, Shopify cardBuy bedding, towels, robes, accessories
myfonts.comDigital font packages and bundlesUCP shopping, Google Pay, Shopify cardBuy digital font packages with less shipping friction
www.uaudio.comAudio plug ins, bundles, interfacesUCP shopping, Google Pay, Shopify cardBuy digital plug ins or hardware depending on fulfillment
fender.com / www.gibson.comGuitars, basses, pedals, accessoriesUCP shopping, Google Pay, Shopify cardBuild cart, but high value items should get review
www.decathlon.comOutdoor and sports productsUCP shopping, Google Pay, Shopify cardBuy gear under budget, subject to availability and shipping
Catalog strength
Apparel feed with variants and prices
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Search apparel, choose represented size or color, build cart, start checkout
Catalog strength
Camera and smart home catalog with prices and availability
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy cameras and accessories subject to account and payment checks
Catalog strength
Bedding and towel catalog with bundles, prices, images
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy home goods and bundles under budget
Catalog strength
Bedding, towels, home catalog
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy bedding, towels, robes, accessories
Catalog strength
Digital font packages and bundles
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy digital font packages with less shipping friction
Catalog strength
Audio plug ins, bundles, interfaces
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy digital plug ins or hardware depending on fulfillment
Catalog strength
Guitars, basses, pedals, accessories
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Build cart, but high value items should get review
Catalog strength
Outdoor and sports products
Payment signal
UCP shopping, Google Pay, Shopify card
Bot can probably do
Buy gear under budget, subject to availability and shipping

Budget enforcement is not standardized in retail. A bot can enforce the user budget locally by reading variant prices and refusing to choose products above the cap. That is useful, but it is not the same as a merchant level guarantee. API and x402 services usually have stronger budget semantics because endpoint prices are visible in the contract.

The working modes are therefore practical but limited. Assistant mode prepares the cart and asks the human. Delegated buying mode uses a stored tokenized card and spend cap until risk controls fire. Browser fallback opens Stripe Checkout or a merchant checkout page so the human can finish.

What a bot can buy without a credit card

The cleanest autonomous purchase loop in the sample is wallet funded API commerce. The server can return 402 Payment Required, the client attaches payment proof, and the same HTTP flow returns the product.

GET /v1/screenshot?url=https://example.com
response 402 Payment Required
price: 0.005 USDC
network: base

GET /v1/screenshot?url=https://example.com
X-PAYMENT: signed_payment_proof
response 200 application/json
SiteWhat the bot can buyPayment modelHuman approval likely
stableemail.devSend email, buy inbox, buy subdomain, read messagesx402 or MPP, USDC on Base, Solana, TempoUsually no, if wallet and policy are approved
anybrowse.devScrape, crawl, search, screenshot, MCP tool callx402, USDC on BaseUsually no, if budget allows
renderself.comPhysical apparel for humansx402, USDC on Base or SolanaMaybe, for shipping address, size, and physical delivery consent
x402.quicknode.comBlockchain RPC accessx402 and stablecoin creditsUsually no for low risk API calls
emc2ai.ioCrypto intelligence agent skillsx402, USDC, BTC Lightning, Stripe mentionedDepends on skill risk and spend cap
publish.newArtifact content downloadsx402 micropaymentsUsually no for low cost digital goods
well-knowns.resolved.shQueryable well known endpoint datasetsx402 micropaymentsUsually no for low cost datasets
x402.robtex.comDNS, IP, Lightning, network intelligencex402Usually no
api.myceliasignal.comSigned financial data and oracle outputsLightning or x402 style paymentDepends on financial policy
What the bot can buy
Send email, buy inbox, buy subdomain, read messages
Payment model
x402 or MPP, USDC on Base, Solana, Tempo
Human approval likely
Usually no, if wallet and policy are approved
What the bot can buy
Scrape, crawl, search, screenshot, MCP tool call
Payment model
x402, USDC on Base
Human approval likely
Usually no, if budget allows
What the bot can buy
Physical apparel for humans
Payment model
x402, USDC on Base or Solana
Human approval likely
Maybe, for shipping address, size, and physical delivery consent
What the bot can buy
Blockchain RPC access
Payment model
x402 and stablecoin credits
Human approval likely
Usually no for low risk API calls
What the bot can buy
Crypto intelligence agent skills
Payment model
x402, USDC, BTC Lightning, Stripe mentioned
Human approval likely
Depends on skill risk and spend cap
What the bot can buy
Artifact content downloads
Payment model
x402 micropayments
Human approval likely
Usually no for low cost digital goods
What the bot can buy
Queryable well known endpoint datasets
Payment model
x402 micropayments
Human approval likely
Usually no for low cost datasets
What the bot can buy
DNS, IP, Lightning, network intelligence
Payment model
x402
Human approval likely
Usually no
What the bot can buy
Signed financial data and oracle outputs
Payment model
Lightning or x402 style payment
Human approval likely
Depends on financial policy

This is why the API side feels farther along. A bot buying a $0.005screenshot or a $0.02 email send is not the same as a bot buying a guitar, a smart lock, a subscription, or a PC. The lower the physical, legal, and financial consequence, the easier it is to authorize in advance.

The best files are honest about status, price, and authority

The best examples are not necessarily the flashiest. They are the ones that tell a bot what is live, what costs money, what payment rail is expected, what auth is needed, and where the flow still falls back to a human.

RankSiteWhy it ranks highlyWhat a bot can buy or doCaveat
1stableemail.devExcellent OpenAPI, endpoint prices, x402 and MPP payment info, SIWX flows, refunds, and operational constraintsSend email, buy inboxes, buy subdomains, top up, read messagesWallet native and email has reputation risk
2renderself.comStrong agent only physical commerce with listings, agent registration, spending limits, order creation, x402 requirements, and order statusBuy physical apparel through an agent flowWallet payment plus shipping and size consent
3dialtoneapp.comTransparent hybrid SaaS example with commerce manifest, UCP style commerce, OpenAPI, offer lookup, legal links, and machine payment roadmapDiscover and initiate a $9/month membership flowLive state is human Stripe checkout fallback
4www.inerrata.aiBroad discovery surface with commerce, UCP, OpenAPI, agent card, plan tiers, card metadata, x402 support, and docs linksDiscover plans and interact with knowledge base APIspre_launch and billing provider pending_activation
5anybrowse.devClean paid OpenAPI with per endpoint prices and 402 responsesScrape pages, crawl and search, return SERP JSON, screenshots, MCP tool serviceWallet native and scraping needs governance
6x402.quicknode.comClear machine payable blockchain RPC access with auth, credits, drip, networks, discovery, and usageBuy RPC access across many networksRequires SIWX and stablecoin flow
7emc2ai.ioAgent and OpenAPI pairing with skill descriptions, examples, tags, and per request pricingBuy crypto analysis, whale tracking, smart money analysis, market data, security scansOutputs and risk boundaries need verification
8x402.aibtc.comClear x402 v2 service description, supported tokens, tiers, and useful endpointsBuy LLM inference, blockchain utilities, hashing, KV storageChain specific payment model
9well-knowns.resolved.shStrong data marketplace pattern with schemas, query endpoints, downloads, and daily deltasBuy or query datasets of well known endpoints, agent cards, MCP servers, OIDC providersNarrow audience, very clear for agents
10publish.newSimple artifact marketplace contract with list, upload, metadata, price, purchase, and content download endpointsPublish and buy digital artifactsNeeds policy for rights and content handling
11agoragentic.comBroad router and marketplace API with registration, execution, commerce, agent cards, and OpenAPI surfacesRegister agents, route tasks, invoke services, expose commerceTrust scoring and buyer policy matter
12a2alist.aiPublic directory for protocol implementations with search, detail, registration, A2A endpoint, and API keysDiscover and register A2A and x402 servicesMore discovery than direct buying
13api.myceliasignal.comSigned financial data with clear oracle use casesBuy price, FX, macro, commodity, and DLC oracle dataSpecialized financial buyer
14x402.robtex.comNetwork intelligence API with clear premium endpointsBuy DNS, IP, Lightning, and reputation dataSpecialized network intelligence
15agentndx.aiRegistry for agentic infrastructureDiscover MCP servers, A2A agents, and x402 servicesInfrastructure discovery
16payanagent.comAgent marketplace positioning is clearDiscover and invoke agent and SaaS servicesMarketplace trust remains the hard part
17relai.fiManagement API for x402 protected APIsRegister APIs, manage keys, pricing, analyticsSeller infrastructure more than buyer storefront
18scoutscore.aiTrust verification is directly relevant to autonomous purchasingCheck trust scores before paying x402 servicesDepends on score adoption
Why it ranks highly
Excellent OpenAPI, endpoint prices, x402 and MPP payment info, SIWX flows, refunds, and operational constraints
What a bot can buy or do
Send email, buy inboxes, buy subdomains, top up, read messages
Caveat
Wallet native and email has reputation risk
Why it ranks highly
Strong agent only physical commerce with listings, agent registration, spending limits, order creation, x402 requirements, and order status
What a bot can buy or do
Buy physical apparel through an agent flow
Caveat
Wallet payment plus shipping and size consent
Why it ranks highly
Transparent hybrid SaaS example with commerce manifest, UCP style commerce, OpenAPI, offer lookup, legal links, and machine payment roadmap
What a bot can buy or do
Discover and initiate a $9/month membership flow
Caveat
Live state is human Stripe checkout fallback
Why it ranks highly
Broad discovery surface with commerce, UCP, OpenAPI, agent card, plan tiers, card metadata, x402 support, and docs links
What a bot can buy or do
Discover plans and interact with knowledge base APIs
Caveat
pre_launch and billing provider pending_activation
Why it ranks highly
Clean paid OpenAPI with per endpoint prices and 402 responses
What a bot can buy or do
Scrape pages, crawl and search, return SERP JSON, screenshots, MCP tool service
Caveat
Wallet native and scraping needs governance
Why it ranks highly
Clear machine payable blockchain RPC access with auth, credits, drip, networks, discovery, and usage
What a bot can buy or do
Buy RPC access across many networks
Caveat
Requires SIWX and stablecoin flow
Why it ranks highly
Agent and OpenAPI pairing with skill descriptions, examples, tags, and per request pricing
What a bot can buy or do
Buy crypto analysis, whale tracking, smart money analysis, market data, security scans
Caveat
Outputs and risk boundaries need verification
Why it ranks highly
Clear x402 v2 service description, supported tokens, tiers, and useful endpoints
What a bot can buy or do
Buy LLM inference, blockchain utilities, hashing, KV storage
Caveat
Chain specific payment model
Why it ranks highly
Strong data marketplace pattern with schemas, query endpoints, downloads, and daily deltas
What a bot can buy or do
Buy or query datasets of well known endpoints, agent cards, MCP servers, OIDC providers
Caveat
Narrow audience, very clear for agents
Why it ranks highly
Simple artifact marketplace contract with list, upload, metadata, price, purchase, and content download endpoints
What a bot can buy or do
Publish and buy digital artifacts
Caveat
Needs policy for rights and content handling
Why it ranks highly
Broad router and marketplace API with registration, execution, commerce, agent cards, and OpenAPI surfaces
What a bot can buy or do
Register agents, route tasks, invoke services, expose commerce
Caveat
Trust scoring and buyer policy matter
Why it ranks highly
Public directory for protocol implementations with search, detail, registration, A2A endpoint, and API keys
What a bot can buy or do
Discover and register A2A and x402 services
Caveat
More discovery than direct buying
Why it ranks highly
Signed financial data with clear oracle use cases
What a bot can buy or do
Buy price, FX, macro, commodity, and DLC oracle data
Caveat
Specialized financial buyer
Why it ranks highly
Network intelligence API with clear premium endpoints
What a bot can buy or do
Buy DNS, IP, Lightning, and reputation data
Caveat
Specialized network intelligence
Why it ranks highly
Registry for agentic infrastructure
What a bot can buy or do
Discover MCP servers, A2A agents, and x402 services
Caveat
Infrastructure discovery
Why it ranks highly
Agent marketplace positioning is clear
What a bot can buy or do
Discover and invoke agent and SaaS services
Caveat
Marketplace trust remains the hard part
Why it ranks highly
Management API for x402 protected APIs
What a bot can buy or do
Register APIs, manage keys, pricing, analytics
Caveat
Seller infrastructure more than buyer storefront
Why it ranks highly
Trust verification is directly relevant to autonomous purchasing
What a bot can buy or do
Check trust scores before paying x402 services
Caveat
Depends on score adoption

Best retail UCP files

Retail is harder to rank because many stores share the same structure. The strongest examples combine a usable product feed with complete shopping capabilities and payment handler metadata.

RankSiteWhy it is strongBot buying note
1www.aloyoga.comClean UCP 2026-04-08 structure, search, checkout, cart, order, fulfillment, Google Pay, Shopify card, usable apparel dataGood for delegated apparel shopping if size, color, and budget are approved
2wyze.com / wyzecam.comSmart home catalog plus UCP shopping and payment capabilitiesGood for accessories and cameras, but home security devices deserve explicit approval
3myfonts.comDigital catalog with font packages and bundles plus UCP checkoutLess shipping friction than physical goods
4www.uaudio.comDigital plug ins and bundles plus interfacesDigital plug ins are lower friction, hardware needs shipping consent
5parachutehome.comHome goods catalog with bundles, prices, images, UCP checkoutGood for comparing towel and bedding bundles under budget
6brooklinen.comBedding, towels, robes, accessories with UCP checkoutGood for repeat household purchasing after preferences are known
7fender.comRich catalog and UCP shopping supportHigh value instruments should require approval
8www.gibson.comSimilar to Fender with high value instruments and gearStrong discovery, high purchase risk
9www.decathlon.comBroad sports and outdoor catalog with UCP checkoutGood for low cost gear, high value bikes require approval
10awaytravel.comClear luggage, bags, bundles, accessoriesGood for preference based luggage purchases with confirmation on high ticket items
11giva.co / palmonas.comJewelry catalogs with prices and product typesSubjective and should usually ask for approval
12www.vwthemes.com / shrinetheme.comDigital themes and templatesGood for budget capped digital purchases if license terms are acceptable
Why it is strong
Clean UCP 2026-04-08 structure, search, checkout, cart, order, fulfillment, Google Pay, Shopify card, usable apparel data
Bot buying note
Good for delegated apparel shopping if size, color, and budget are approved
Why it is strong
Smart home catalog plus UCP shopping and payment capabilities
Bot buying note
Good for accessories and cameras, but home security devices deserve explicit approval
Why it is strong
Digital catalog with font packages and bundles plus UCP checkout
Bot buying note
Less shipping friction than physical goods
Why it is strong
Digital plug ins and bundles plus interfaces
Bot buying note
Digital plug ins are lower friction, hardware needs shipping consent
Why it is strong
Home goods catalog with bundles, prices, images, UCP checkout
Bot buying note
Good for comparing towel and bedding bundles under budget
Why it is strong
Bedding, towels, robes, accessories with UCP checkout
Bot buying note
Good for repeat household purchasing after preferences are known
Why it is strong
Rich catalog and UCP shopping support
Bot buying note
High value instruments should require approval
Why it is strong
Similar to Fender with high value instruments and gear
Bot buying note
Strong discovery, high purchase risk
Why it is strong
Broad sports and outdoor catalog with UCP checkout
Bot buying note
Good for low cost gear, high value bikes require approval
Why it is strong
Clear luggage, bags, bundles, accessories
Bot buying note
Good for preference based luggage purchases with confirmation on high ticket items
Why it is strong
Jewelry catalogs with prices and product types
Bot buying note
Subjective and should usually ask for approval
Why it is strong
Digital themes and templates
Bot buying note
Good for budget capped digital purchases if license terms are acceptable

Weak or incomplete patterns

A discovery file can still be valuable even when it is incomplete. But a buyer bot should score these lower until live products, prices, purchase examples, or callable endpoints are visible.

PatternExamples
Empty product catalogsethnc.com, linksys.com
Product files that were not normal catalogsblurams.com, shields.io, umu.se, vevor.com, www.schadeautos.nl, zhipin.com, zr.ru
API docs that looked like 404 or placeholder payloadsSeveral Dolby and Umea University named files
UCP only with no local product catalogfashionnova.com, nightcafe.studio, swann.com, teltonika.lt, vevo.com, wiki.gg, www.forter.com

The human is still in the loop, just in a better place

The naive version of bot commerce says an agent asks for permission every time. The better version says a human approves policy once, then the bot operates inside that policy until it hits a boundary.

policy:
  web_scraping_budget: "$10/day"
  digital_artifacts: "$2 each"
  physical_goods: "ask first"
  email_sending: "allowlist only"
  recurring_billing: "human approval required"
  trading_or_defi: "blocked unless separately mandated"
Human checkpointWhat still needs policy or approval
Payment authorityAttach card, wallet, Google Pay, or billing account. Set spend limits and allowed categories. Decide whether recurring charges and wallet payments can run automatically.
Card issuer and fraud review3DS or SCA, issuer approval, CVV refresh, fraud review, account login, CAPTCHA, bot mitigation, and billing address checks can still interrupt checkout.
Physical fulfillmentShipping address, recipient data, delivery method, substitutions, returns, customs, age restrictions, and high value purchases need policy or approval.
Subscriptions and account creationRecurring billing, terms acceptance, account identity, email verification, team seats, cancellation, and refund policy still need human consent or prior mandate.
Consequential API actionsEmail sends, artifact publication, domains, code execution, trading, DeFi, and writes to shared systems need policy before automation.
Payment authority
Attach card, wallet, Google Pay, or billing account. Set spend limits and allowed categories. Decide whether recurring charges and wallet payments can run automatically.
Card issuer and fraud review
3DS or SCA, issuer approval, CVV refresh, fraud review, account login, CAPTCHA, bot mitigation, and billing address checks can still interrupt checkout.
Physical fulfillment
Shipping address, recipient data, delivery method, substitutions, returns, customs, age restrictions, and high value purchases need policy or approval.
Subscriptions and account creation
Recurring billing, terms acceptance, account identity, email verification, team seats, cancellation, and refund policy still need human consent or prior mandate.
Consequential API actions
Email sends, artifact publication, domains, code execution, trading, DeFi, and writes to shared systems need policy before automation.

This is the right place for systems like mandates, scoped payment tokens, wallet spend limits, merchant allowlists, category rules, and audit logs. The goal is not to remove humans from authority. The goal is to stop making them approve every harmless low cost request while still forcing approval for physical, recurring, expensive, or consequential actions.

A practical buying matrix

Buyer goalBest current patternCredit cardWallet or x402Human approval
Buy normal retail goodsUCP plus products.json plus payment handlersYes, if tokenized payment existsUsually noOften yes for final payment or shipping
Buy digital retail goodsUCP plus products.json, low shipping complexityYesSometimesLess often, but licenses still matter
Subscribe to SaaSCommerce manifest plus OpenAPI plus Stripe or card checkoutYes, often through browser checkoutSometimesUsually yes because recurring billing
Call an AI modelOpenAPI plus x402 or MPP price metadataUsually indirectlyYesUsually no if spend policy exists
Scrape, crawl, search webOpenAPI plus x402 pricesUsually noYesPolicy approval recommended
Send emailOpenAPI plus x402 prices plus ownership and auth rulesUsually noYesPolicy approval strongly recommended
Buy blockchain, RPC, dataOpenAPI plus x402 or SIWXUsually noYesDepends on risk and spend
Buy physical goods through agent APIProduct and order flow plus x402Usually noYesYes unless preapproved
Register or invoke agentsAgent card plus OpenAPI plus registry APIUsually noOftenDepends on trust score and spend
Buy normal retail goods
Best current pattern
UCP plus products.json plus payment handlers
Credit card
Yes, if tokenized payment exists
Wallet or x402
Usually no
Human approval
Often yes for final payment or shipping
Buy digital retail goods
Best current pattern
UCP plus products.json, low shipping complexity
Credit card
Yes
Wallet or x402
Sometimes
Human approval
Less often, but licenses still matter
Subscribe to SaaS
Best current pattern
Commerce manifest plus OpenAPI plus Stripe or card checkout
Credit card
Yes, often through browser checkout
Wallet or x402
Sometimes
Human approval
Usually yes because recurring billing
Call an AI model
Best current pattern
OpenAPI plus x402 or MPP price metadata
Credit card
Usually indirectly
Wallet or x402
Yes
Human approval
Usually no if spend policy exists
Scrape, crawl, search web
Best current pattern
OpenAPI plus x402 prices
Credit card
Usually no
Wallet or x402
Yes
Human approval
Policy approval recommended
Send email
Best current pattern
OpenAPI plus x402 prices plus ownership and auth rules
Credit card
Usually no
Wallet or x402
Yes
Human approval
Policy approval strongly recommended
Buy blockchain, RPC, data
Best current pattern
OpenAPI plus x402 or SIWX
Credit card
Usually no
Wallet or x402
Yes
Human approval
Depends on risk and spend
Buy physical goods through agent API
Best current pattern
Product and order flow plus x402
Credit card
Usually no
Wallet or x402
Yes
Human approval
Yes unless preapproved
Register or invoke agents
Best current pattern
Agent card plus OpenAPI plus registry API
Credit card
Usually no
Wallet or x402
Often
Human approval
Depends on trust score and spend

What a good buying bot should do before paying

  1. Discover the site surface: UCP, OpenAPI, agent cards, commerce manifests, product feeds.
  2. Classify the purchase: physical retail, digital retail, SaaS, API call, recurring use, agent invocation, data download, email, financial operation.
  3. Extract price and currency from variants, endpoint metadata, or plan data.
  4. Check budget and policy: single item cap, daily cap, merchants, categories, physical goods rule, recurring rule, email and code rules.
  5. Validate availability and terms: stock, shipping, taxes, fees, refunds, licenses, cancellation.
  6. Choose payment path: tokenized card, Google Pay, Shopify card, Stripe Checkout, x402, MPP, OAuth, bearer token, or SIWX.
  7. Ask for human approval when policy requires it.
  8. Record the transaction with source file, item or endpoint, price, payment method, approval token, order ID, or receipt.

Where this lands

The current state is not that bots can buy anything. It is more specific and more interesting. Bots can increasingly read what is for sale. They can price low cost digital actions. They can buy many API services autonomously if they have a wallet and a budget. They can prepare many retail purchases if they have card compatible payment handlers. They still hit human checkpoints for card authorization, fraud review, shipping, subscriptions, high value purchases, and risky actions.

The near term winning pattern is mixed: UCP for catalog, cart, checkout, fulfillment, discount, and order semantics; tokenized card or wallet handlers with explicit spend caps; OpenAPI for paid actions and SaaS account flows; agent cards for discovery and routing; human approval policies for anything recurring, physical, expensive, or consequential.