checkout-registry v0.1

The registry of /checkout infrastructure.

The buy-side checkout APIs that complete a purchase at any merchant — callable from any app or agent. Every one in a single registry, each capability sourced from the provider's own docs.

registry ~ $ registry list

Registry

6 checkout agents · detailed profiles in verification review
#AgentCoverageExecutionProtocolsStatusVerification
CartAI
CartAI
US retail Browser REST Live claimed
full profile/agents/cartai → websitewww.cartai.ai docsdocs.cartai.ai/ coverageWide range of US-based retailers (Shopify + major brands); curated sample, not exhaustive executionAgent navigates the merchant's live site like a human (cart → shipping → payment → confirm); no merchant integration paymentCaller supplies payment credentials; retailer stays merchant of record; cards not tokenized by default authAPI key in X-API-Key header accessSelf-serve signup; production (tokenization/VIC) gated by manual approval protocolsREST/JSON over HTTPS + webhooks; no MCP/ACP/AP2/UCP/x402 discoveryProduct page URL; optional search-then-resolve (search by name → directUrl) returnsNo automatic refunds; a cancellation does not refund; refunds are handled via your payment provider; returns follow the merchant's process. regionsUS only (UK/EU/CA/APAC not supported; expansion planned) pricingnot documented sandboxNo separate sandbox — single environment; test cards in default test mode; base api.cartai.ai statusLive; accounts start in test mode; production (tokenization, VIC) gated by manual Request Go Live
Agentic Checkout
Crossmint
Universal + API + Browser x402MCP Live claimed
full profile/agents/crossmint → websitewww.crossmint.com/products/agentic-checkout docsdocs.crossmint.com/solutions/ai-agents/introduction coverageAmazon (US), any Shopify (global), flights, plus browser-automation sites (Nike, Adidas, Crocs, Gymshark, On); 1B+ products executionSingle Create Order REST call; also exposed as an MCP server (create-order / check-order) paymentCard, stablecoin/USDC (EVM/Solana), or Crossmint credits; ~10 fiat currencies authServer-side API key in X-API-KEY header; scoped keys accessSelf-serve — create a server API key in the console protocolsREST API + MCP server; x402 for stablecoin payments. MPP, ACP, and AP2 listed as roadmap. discoveryLocator string — Amazon ASIN, Shopify URL+variant, or any site URL; Worldstore Search API for availability returnsSupported — refunds allowed. regionsAmazon US only; Shopify global; card currencies span US/EU/APAC; flights gated pricingPer-transaction, tiered by volume; no public numbers (contact sales) sandboxStaging at staging.crossmint.com/api; MCP ENV=test/prod; 300+ browser-automation staging sites statusLive (Amazon + Shopify); flights require sales approval; browser automation across 5 production + 300+ staging sites.
Firmly.ai
Firmly
Multi-platform API REST Live claimed
full profile/agents/firmly → websitewww.firmly.ai docsdevelopers.firmly.ai/introduction coverage~11M merchants / $900B+ GMV via platforms (Shopify/BigCommerce/Magento); discovery limited to your account's merchant domains executionStandardization layer over merchant systems; order placed via a single Complete Order API call paymentCaller supplies card, JWE-encrypted with Firmly's rotating public key; Klarna express flow authTwo models — Browser Session (client) + Server-to-Server token; header-based accessMarketed self-serve ("self-onboard in minutes"); actual developer key access not documented protocolsREST/JSON API (developer docs). A broader protocol suite (UCP, ACP, MCP, AP2, TAP, KYA) is listed on firmly.ai/connect. discoveryMerchant PDP URL, product ID, or cross-merchant Discovery search returnsRead-only status (returned/partially_returned + refund breakdown); no endpoint to initiate a return regionsnot documented pricingnot documented sandboxnot documented statusLive (per firmly.ai/connect).
Henry Labs
Henry Labs
Multi-merchant SDK REST Live claimed
full profile/agents/henry → websitewww.henrylabs.ai docsdocs.henrylabs.ai/ coverageMulti-merchant; per-merchant coverage status + lifetime success rates; total count not documented executionTwo modes — hosted (Henry collects details + places order) and headless (your server submits token + shipping); async default paymentBuyer supplies payment; Henry collects via hosted modal or takes a tokenized card (headless), then pays the merchant authAPI key via x-api-key header; server-side only accessSelf-serve — free tier (500 credits, no card required) protocolsREST (OpenAPI) + TypeScript SDKs; MCP named as a usage surface; no ACP/AP2/UCP/x402 discoveryProduct URL identifies items (no separate ID); search by text or image returnsnot documented (only a "cancelled" order state; no return/refund flow) regionsnot documented (only test-card "countries and regions" text, about test simulation) pricingUsage credits — Free 500 / Hobbyist $30 (3k) / Builder $250 (30k) / Scale custom; checkout = 50 credits sandboxnot documented (no sandbox environment in the docs; test cards provided for payment simulation) statusLive / GA — stable v1.0.0 SDK shipped; some endpoints experimental
Universal Checkout API
Rye
Universal Browser x402MCPUCP Live claimed
full profile/agents/rye → websiterye.com/products/universal-checkout-api docsrye.com/docs coverageUniversal — any product URL; ~15,000+ merchants executionSubmits the order to the merchant; no merchant integration (browser-automation runtime) paymentCaller supplies a tokenized payment method (tok_visa in staging); Rye handles pricing/tax/shipping authAPI key — Bearer token (checkout-intents / Universal Checkout); legacy sync API uses Basic accessSelf-serve — Developer plan ($149/mo, 30-day free trial) + staging keys; Enterprise custom protocolsREST (core API); x402 (via AgentCash), MCP, and UCP transports discoveryCaller supplies the PDP URL returnsYes — whole-order return to refund (Shopify orders only) regionsUS only — ships to US addresses pricingDeveloper $149/mo ($50 credits, $0.05/order, $0.02/product fetch, no markup); Enterprise custom sandboxYes — staging.api.rye.com; tok_visa test token statusLive / production.
Zinc API
Zinc
Major retailers API RESTMPP Beta claimed
full profile/agents/zinc → websitewww.zinc.com docswww.zinc.com/docs coverage10+ named retailers (Amazon, Walmart, Target, Best Buy, Home Depot, Lowe's, Costco, eBay, Wayfair, Macy's) + more executionManaged async service — Zinc places the order with the retailer; queued + processed payment3 modes — prepaid Wallet (default), Stripe Connect (charge end-customer), MPP (per-request); Zinc fronts & reimburses authBearer token (API key); MPP path needs none accessSelf-serve — test keys (zn_test_ prefix); dashboard at app.zinc.com protocolsREST + MPP (Machine Payments Protocol, HTTP 402, by Tempo/Stripe); no MCP/ACP/AP2/UCP discoveryDirect retailer URL — "the URL is the contract"; no SKU/ASIN field returnsYes — POST create-return against a prior order; async, return labels provided regionsInternational supported; ISO 3166-1 alpha-2 destination, defaults US pricingFlat $1 API fee/order + funding fees (card 2.9%+$0.30; ACH 0.8% cap $5; wire $15); no subscription/markup sandboxYes — test mode via zn_test_ key prefix; isolated sandbox DB; same host statusv2 in active development (not GA); v1 in production; some endpoints beta

Each capability carries a status — claimed, verified, failed, or unverifiable. See the methodology.

The benchmark

coming soon

What we test

Every agent will run against the same frozen set of controlled storefronts — Shopify, WooCommerce, headless, and one deliberately hostile checkout. Reproducible, no real money, no merchant ToS exposure. A rotating hidden holdout will keep anyone from optimizing to the test.

Scored on: success rate · site-coverage breadth · latency · price accuracy · variant & coupon handling · returns/refunds · protocol support.

Verified vs. claimed

Each capability carries one status:

verifiedexecuted; the documented outcome reproduced claimedstated in the vendor's documentation; not yet executed failedexecuted; the documented outcome did not reproduce unverifiablenot testable (no accessible sandbox, endpoint, or documented method)

Method: read the methodology.

Agent-readable

available as JSON, JSON-LD, and llms.txt

JSON API

Every row on this page is a static, crawlable record and a JSON endpoint. No auth to read.

# the registry, machine-readable
$ curl https://checkoutregistry.com/api/v1/agents

{
  "registry": "Checkout Registry",
  "count": 6,
  "agents": [
    {
      "id": "cartai", "vendor": "CartAI",
      "capabilities": {
        "coverage": { "value": "US retailers — Shopify + major brands", "status": "claimed", "source": "https://docs.cartai.ai/..." },
        "execution": { "value": "Navigates the live site — cart → pay → confirm", "status": "claimed" },
        ...
      }
    },
    ...
  ]
}

Built for LLM discovery

Structured data in the markup, plus a JSON API and an agent guide at the root:

# structured data, in the served HTML
‹script type="application/ld+json"
  "@type": "Dataset"
‹/script›

# machine-readable, at the root
GET /api/v1/agents
GET /llms.txt

The registry is served as static HTML and JSON, so a model fetching this page reads all 6 listings straight from the markup.

FAQ

What is a checkout agent?

Software that completes a purchase on behalf of a person or an AI agent, taking a product selection through to a confirmed order. They range from APIs you call programmatically, to consumer agents that buy inside a chat interface, to browser agents that drive a storefront's UI, to the payment rails and protocols underneath.

What is Checkout Registry?

An independent registry of agentic checkout infrastructure — the buy-side APIs that complete a purchase at a merchant, callable from any app or agent (not just AI). It tracks each one's vendor, capabilities, protocols, and auth, sourced from their own docs, with independent verification planned. It deliberately excludes consumer shopping surfaces, general browser agents, and merchant platforms.

How are capabilities verified?

Each documented capability is executed — the documented call is made in the provider's own sandbox or against a controlled storefront, and the documented outcome must reproduce. Each capability then carries one status: claimed, verified, failed, or unverifiable. A single successful run marks it verified; measuring reliability across many runs is the separate benchmark. Full method: see the methodology.

What do "verified" and "claimed" mean?

Each capability carries one status. Claimed: stated in the vendor's documentation; not yet executed. Verified: executed; the documented outcome reproduced. Failed: executed; the documented outcome did not reproduce. Unverifiable: not testable (no accessible sandbox, endpoint, or documented method). A capability is shown as verified only when its status says so.

Which protocols does the registry track?

Agents across the emerging agentic-commerce protocols — including ACP, AP2, UCP, x402, and MCP — alongside API-only and browser-driven agents that use no shared protocol.

How do I get an agent listed?

Agent submission opens soon — you'll be able to submit an agent to be listed and verified. In the meantime, if a claim is wrong or your documentation has changed, email hello@checkoutregistry.com and we'll correct it.

Is the registry free to access?

Yes. Every listing is served as static HTML and as a machine-readable JSON endpoint at /api/v1/agents, with no authentication required to read. An llms.txt is also available for AI agents.

Run a checkout agent?

Submit it to get your agent listed and verified. Submissions open soon.

Register an agent · coming soon Read the methodology