The buy-side checkout APIs that complete a purchase at any merchant — callable from any app or agent. Every one in a single registry, each capability sourced from the provider's own docs.
| # | Agent | Coverage | Execution | Protocols | Status | Verification |
|---|---|---|---|---|---|---|
| CartAI CartAI |
US retail | Browser | REST | Live | claimed | |
full profile/agents/cartai →
websitewww.cartai.ai
docsdocs.cartai.ai/
coverageWide range of US-based retailers (Shopify + major brands); curated sample, not exhaustive ↗
executionAgent navigates the merchant's live site like a human (cart → shipping → payment → confirm); no merchant integration ↗
paymentCaller supplies payment credentials; retailer stays merchant of record; cards not tokenized by default ↗
authAPI key in X-API-Key header ↗
accessSelf-serve signup; production (tokenization/VIC) gated by manual approval ↗
protocolsREST/JSON over HTTPS + webhooks; no MCP/ACP/AP2/UCP/x402 ↗
discoveryProduct page URL; optional search-then-resolve (search by name → directUrl) ↗
returnsNo automatic refunds; a cancellation does not refund; refunds are handled via your payment provider; returns follow the merchant's process. ↗
regionsUS only (UK/EU/CA/APAC not supported; expansion planned) ↗
pricingnot documented
sandboxNo separate sandbox — single environment; test cards in default test mode; base api.cartai.ai ↗
statusLive; accounts start in test mode; production (tokenization, VIC) gated by manual Request Go Live ↗
| ||||||
| Agentic Checkout Crossmint |
Universal + | API + Browser | x402MCP | Live | claimed | |
full profile/agents/crossmint →
websitewww.crossmint.com/products/agentic-checkout
docsdocs.crossmint.com/solutions/ai-agents/introduction
coverageAmazon (US), any Shopify (global), flights, plus browser-automation sites (Nike, Adidas, Crocs, Gymshark, On); 1B+ products ↗
executionSingle Create Order REST call; also exposed as an MCP server (create-order / check-order) ↗
paymentCard, stablecoin/USDC (EVM/Solana), or Crossmint credits; ~10 fiat currencies ↗
authServer-side API key in X-API-KEY header; scoped keys ↗
accessSelf-serve — create a server API key in the console ↗
protocolsREST API + MCP server; x402 for stablecoin payments. MPP, ACP, and AP2 listed as roadmap. ↗
discoveryLocator string — Amazon ASIN, Shopify URL+variant, or any site URL; Worldstore Search API for availability ↗
returnsSupported — refunds allowed. ↗
regionsAmazon US only; Shopify global; card currencies span US/EU/APAC; flights gated ↗
pricingPer-transaction, tiered by volume; no public numbers (contact sales) ↗
sandboxStaging at staging.crossmint.com/api; MCP ENV=test/prod; 300+ browser-automation staging sites ↗
statusLive (Amazon + Shopify); flights require sales approval; browser automation across 5 production + 300+ staging sites. ↗
| ||||||
| Firmly.ai Firmly |
Multi-platform | API | REST | Live | claimed | |
full profile/agents/firmly →
websitewww.firmly.ai
docsdevelopers.firmly.ai/introduction
coverage~11M merchants / $900B+ GMV via platforms (Shopify/BigCommerce/Magento); discovery limited to your account's merchant domains ↗
executionStandardization layer over merchant systems; order placed via a single Complete Order API call ↗
paymentCaller supplies card, JWE-encrypted with Firmly's rotating public key; Klarna express flow ↗
authTwo models — Browser Session (client) + Server-to-Server token; header-based ↗
accessMarketed self-serve ("self-onboard in minutes"); actual developer key access not documented ↗
protocolsREST/JSON API (developer docs). A broader protocol suite (UCP, ACP, MCP, AP2, TAP, KYA) is listed on firmly.ai/connect. ↗
discoveryMerchant PDP URL, product ID, or cross-merchant Discovery search ↗
returnsRead-only status (returned/partially_returned + refund breakdown); no endpoint to initiate a return ↗
regionsnot documented
pricingnot documented
sandboxnot documented
statusLive (per firmly.ai/connect). ↗
| ||||||
| Henry Labs Henry Labs |
Multi-merchant | SDK | REST | Live | claimed | |
full profile/agents/henry →
websitewww.henrylabs.ai
docsdocs.henrylabs.ai/
coverageMulti-merchant; per-merchant coverage status + lifetime success rates; total count not documented ↗
executionTwo modes — hosted (Henry collects details + places order) and headless (your server submits token + shipping); async default ↗
paymentBuyer supplies payment; Henry collects via hosted modal or takes a tokenized card (headless), then pays the merchant ↗
authAPI key via x-api-key header; server-side only ↗
accessSelf-serve — free tier (500 credits, no card required) ↗
protocolsREST (OpenAPI) + TypeScript SDKs; MCP named as a usage surface; no ACP/AP2/UCP/x402 ↗
discoveryProduct URL identifies items (no separate ID); search by text or image ↗
returnsnot documented (only a "cancelled" order state; no return/refund flow)
regionsnot documented (only test-card "countries and regions" text, about test simulation)
pricingUsage credits — Free 500 / Hobbyist $30 (3k) / Builder $250 (30k) / Scale custom; checkout = 50 credits ↗
sandboxnot documented (no sandbox environment in the docs; test cards provided for payment simulation)
statusLive / GA — stable v1.0.0 SDK shipped; some endpoints experimental ↗
| ||||||
| Universal Checkout API Rye |
Universal | Browser | x402MCPUCP | Live | claimed | |
full profile/agents/rye →
websiterye.com/products/universal-checkout-api
docsrye.com/docs
coverageUniversal — any product URL; ~15,000+ merchants ↗
executionSubmits the order to the merchant; no merchant integration (browser-automation runtime) ↗
paymentCaller supplies a tokenized payment method (tok_visa in staging); Rye handles pricing/tax/shipping ↗
authAPI key — Bearer token (checkout-intents / Universal Checkout); legacy sync API uses Basic ↗
accessSelf-serve — Developer plan ($149/mo, 30-day free trial) + staging keys; Enterprise custom ↗
protocolsREST (core API); x402 (via AgentCash), MCP, and UCP transports ↗
discoveryCaller supplies the PDP URL ↗
returnsYes — whole-order return to refund (Shopify orders only) ↗
regionsUS only — ships to US addresses ↗
pricingDeveloper $149/mo ($50 credits, $0.05/order, $0.02/product fetch, no markup); Enterprise custom ↗
sandboxYes — staging.api.rye.com; tok_visa test token ↗
statusLive / production. ↗
| ||||||
| Zinc API Zinc |
Major retailers | API | RESTMPP | Beta | claimed | |
full profile/agents/zinc →
websitewww.zinc.com
docswww.zinc.com/docs
coverage10+ named retailers (Amazon, Walmart, Target, Best Buy, Home Depot, Lowe's, Costco, eBay, Wayfair, Macy's) + more ↗
executionManaged async service — Zinc places the order with the retailer; queued + processed ↗
payment3 modes — prepaid Wallet (default), Stripe Connect (charge end-customer), MPP (per-request); Zinc fronts & reimburses ↗
authBearer token (API key); MPP path needs none ↗
accessSelf-serve — test keys (zn_test_ prefix); dashboard at app.zinc.com ↗
protocolsREST + MPP (Machine Payments Protocol, HTTP 402, by Tempo/Stripe); no MCP/ACP/AP2/UCP ↗
discoveryDirect retailer URL — "the URL is the contract"; no SKU/ASIN field ↗
returnsYes — POST create-return against a prior order; async, return labels provided ↗
regionsInternational supported; ISO 3166-1 alpha-2 destination, defaults US ↗
pricingFlat $1 API fee/order + funding fees (card 2.9%+$0.30; ACH 0.8% cap $5; wire $15); no subscription/markup ↗
sandboxYes — test mode via zn_test_ key prefix; isolated sandbox DB; same host ↗
statusv2 in active development (not GA); v1 in production; some endpoints beta ↗
| ||||||
Each capability carries a status — claimed, verified, failed, or unverifiable. See the methodology.
Every agent will run against the same frozen set of controlled storefronts — Shopify, WooCommerce, headless, and one deliberately hostile checkout. Reproducible, no real money, no merchant ToS exposure. A rotating hidden holdout will keep anyone from optimizing to the test.
Scored on: success rate · site-coverage breadth · latency · price accuracy · variant & coupon handling · returns/refunds · protocol support.
Each capability carries one status:
Method: read the methodology.
Every row on this page is a static, crawlable record and a JSON endpoint. No auth to read.
# the registry, machine-readable $ curl https://checkoutregistry.com/api/v1/agents { "registry": "Checkout Registry", "count": 6, "agents": [ { "id": "cartai", "vendor": "CartAI", "capabilities": { "coverage": { "value": "US retailers — Shopify + major brands", "status": "claimed", "source": "https://docs.cartai.ai/..." }, "execution": { "value": "Navigates the live site — cart → pay → confirm", "status": "claimed" }, ... } }, ... ] }
Structured data in the markup, plus a JSON API and an agent guide at the root:
# structured data, in the served HTML ‹script type="application/ld+json"› "@type": "Dataset" ‹/script› # machine-readable, at the root GET /api/v1/agents GET /llms.txt
The registry is served as static HTML and JSON, so a model fetching this page reads all 6 listings straight from the markup.
What is a checkout agent?
Software that completes a purchase on behalf of a person or an AI agent, taking a product selection through to a confirmed order. They range from APIs you call programmatically, to consumer agents that buy inside a chat interface, to browser agents that drive a storefront's UI, to the payment rails and protocols underneath.
What is Checkout Registry?
An independent registry of agentic checkout infrastructure — the buy-side APIs that complete a purchase at a merchant, callable from any app or agent (not just AI). It tracks each one's vendor, capabilities, protocols, and auth, sourced from their own docs, with independent verification planned. It deliberately excludes consumer shopping surfaces, general browser agents, and merchant platforms.
How are capabilities verified?
Each documented capability is executed — the documented call is made in the provider's own sandbox or against a controlled storefront, and the documented outcome must reproduce. Each capability then carries one status: claimed, verified, failed, or unverifiable. A single successful run marks it verified; measuring reliability across many runs is the separate benchmark. Full method: see the methodology.
What do "verified" and "claimed" mean?
Each capability carries one status. Claimed: stated in the vendor's documentation; not yet executed. Verified: executed; the documented outcome reproduced. Failed: executed; the documented outcome did not reproduce. Unverifiable: not testable (no accessible sandbox, endpoint, or documented method). A capability is shown as verified only when its status says so.
Which protocols does the registry track?
Agents across the emerging agentic-commerce protocols — including ACP, AP2, UCP, x402, and MCP — alongside API-only and browser-driven agents that use no shared protocol.
How do I get an agent listed?
Agent submission opens soon — you'll be able to submit an agent to be listed and verified. In the meantime, if a claim is wrong or your documentation has changed, email hello@checkoutregistry.com and we'll correct it.
Is the registry free to access?
Yes. Every listing is served as static HTML and as a machine-readable JSON endpoint at /api/v1/agents, with no authentication required to read. An llms.txt is also available for AI agents.
Submit it to get your agent listed and verified. Submissions open soon.
Register an agent · coming soon Read the methodology