How an AI agent buys from your site
An agent sent to buy something does six things in order, and it abandons at the first one it cannot complete. It does not retry, it does not report, and nothing in your analytics records that it was here. This is the sequence, step by step, with the published specification behind each one and the day we last read it.
Sources last read 2026-09-13No account needed to check your own site
What this page covers
- The order an agent works in, and what it needs to see at each step.
- The specification that governs each step, by name, with the date we last confirmed its published version.
- What your site looks like from the agent's side when a step is missing.
What it is not
- A way into any assistant's own checkout. Completing a purchase inside ChatGPT is a separate programme with its own approval, open in the United States only on the date above — nobody can sell you a place in it.
- A ranking technique. Everything here is about being operable by software. None of it buys a position in an assistant's answer.
- A copy of anyone's specification. Each step links the primary source; the versions below are pinned with the day a person read them.
The sequence, in the order an agent meets it
Read this as a pipeline with six gates rather than a checklist with six items. An agent that cannot establish your terms does not go on to attempt a payment and find out whether that would have worked — it leaves, and the buyer it was working for never learns your name. That is why the order matters more than the count.
Establish that you exist and what you sell
The agent does not start at your home page. It starts from a person's sentence — "a waterproof jacket, under two hundred, delivered to Montreal this week" — and assembles a set of merchants it believes can answer it. You are either in that set or you are not in the conversation.
What your site has to show: A statement of what your business is and what it sells, in a form that does not require running your storefront's JavaScript to read. A human reader is persuaded by a page. Software is not reading your page; it is reading what your page declares about itself.
If it is not there: You are absent from the set. This is not ranking low — there is no position to be low in. The buyer sees three merchants and you are not one of them.
Governed by: UCP — discovery (Google) (2026-04-08, read 2026-09-01)
Read the offer
Having shortlisted you, the agent needs the specific thing: this item, this price, this currency, in stock or not, right now. It is building a comparison it will show its principal, and every field it cannot fill is a reason to drop you from the comparison rather than to ask a question.
What your site has to show: Per-item price, currency and availability, published as data rather than as layout. An agent does not infer a price from a styled element the way a person does, and it will not guess at a currency.
If it is not there: You appear in the shortlist and lose the comparison, every time, to the merchant whose numbers were legible. Nothing tells you a comparison happened.
Governed by: UCP — discovery (Google) (2026-04-08, read 2026-09-01)
Read the terms before it commits to anything
Shipping, returns, taxes, and who you will and will not sell to. The agent settles these BEFORE it attempts a purchase, because its principal asked for a delivered jacket, not a jacket. Terms it cannot establish are treated as terms it cannot accept.
What your site has to show: Delivery, returns and tax handling stated where software can find them, in the same place for every item rather than in a paragraph on one product page. For a Canadian shop this is also where sales tax by province and duty on cross-border returns belong — the two things a United States-built audit routinely gets wrong about us.
If it is not there: The agent gets as far as your catalogue and stops. From your side this is indistinguishable from never having been found, which is why this step is the most commonly missed and the least commonly suspected.
Governed by: Merchant profiles — terms (Stripe) (2026-07-29.preview, read 2026-08-31)
Prove it is allowed to spend the money
A serious agent arrives carrying a mandate: a verifiable statement that its principal authorised this purchase, up to this amount, for this purpose. It expects to present that rather than to be trusted. Separately, and increasingly, it expects to be able to prove that it is the agent it claims to be.
What your site has to show: Somewhere to present the mandate, and a way to tell a real agent from anything else claiming its name. The second half matters even before you sell anything to software: if you count agent traffic by the name in its user agent, that number is whatever a stranger typed.
If it is not there: You either refuse a legitimate buyer or you accept a forged one. Both are quiet, and the second one is quiet for longer.
Governed by: Agent Pay — payment mandates (Mastercard) (Agent Pay 2025-04-29 (Agentic Tokens); Verifiable Intent 2026-03-05; Agent Pay for Machines 2026-06-10; merchant enrolment via acquirer/PSP, read 2026-09-03) · Trusted Agent Protocol (Visa) (announced 2025-10-14; in development and deployment, no GA date, read 2026-09-03) · Web Bot Auth — agent identity (IETF draft) (draft-ietf-webbotauth-httpsig-protocol-00, read 2026-09-03)
Negotiate and complete
Agents do not fill in forms. They exchange offers — comparing, applying a stated preference for speed over cost, settling a final total — as a stateful conversation, and then they complete. Your multi-step checkout is not a smaller version of this. It is a different mechanism.
What your site has to show: A path that completes a purchase without a human touching anything, on the rails you already use. Not an assistant's own checkout: yours, made completable.
If it is not there: The most expensive failure available, because it happens after you won the comparison. The agent chose you and then could not finish.
Governed by: Shared payment tokens — completion (Stripe) (2026-04-22.preview, read 2026-08-31)
Confirm, so the order can be referred to again
After paying, the agent hands its principal something durable: a reference the purchase can be checked against later, by a person or by the same agent asked "where is my jacket". An order it cannot refer to again is an order it half-remembers.
What your site has to show: A permanent address for the order that shows nothing to anyone who cannot prove they own it. Both halves are load-bearing: without the first you have gone quiet after taking money, and without the second you have published your customers' purchases.
If it is not there: The sale completes and the relationship ends there. Every follow-up question becomes a support ticket a human has to answer.
Governed by: No single published specification — every programme above assumes it.
What the five outcomes sound like
We grade this on a five-point scale, and the free report prints one of the following sentences about your site. They are reproduced here word for word, because a developer sent this page and then handed a report should find the same sentences in both. What composes each level is not published anywhere and is not on this page — the honest use of the scale is as a description of where an agent stops, and the definition of the scale lives on the methodology page beside the limits we put on it.
- Level 0 — invisible: An AI agent cannot establish what you sell or on what terms. It has nothing to quote.
- Level 1 — listed: An agent can read your offer and find your terms — it cannot yet act on either.
- Level 2 — discoverable: An agent can find your catalog and knows how to deal with you. It still cannot complete a purchase.
- Level 3 — buyable: An agent can complete a purchase from you today, on the path buyers in your category actually use.
- Level 4 — operated: An agent can buy from you, and you are running the channel — feed fresh, promotions dated, policies live.
Note what the top of the scale is not. Level 4 is not a certification, it is not a placement, and it is not permanent: a catalogue that goes stale drops back down it without anything on your site changing.
The scale is defined, with the limits we put on it, on the methodology page. The longer explainer — what each level means for a shop, and why this is a different question from AI visibility — is the readiness levels guide.
Three things we most often find in the way
Not thresholds and not a checklist — these are the three shapes of problem that turn up most often in real audits, described as what they cost you.
The catalogue exists, in a form only a browser can read
The shop is beautiful and the products are in it. Everything an agent needs is assembled by JavaScript after the page loads, so the data is real and arrives too late to be read. This is the single most common finding, and the one that feels most unfair to the people who built the site, because from a human's seat nothing is wrong.
The terms are written for a person to be reassured by
A returns page that says "we'll always sort you out" is good copy and unusable input. The agent is not being reassured, it is filling in fields. Stating the same promise as values it can hold costs nothing and changes the outcome.
Agent traffic is counted by asking the agent who it is
Analytics tools mostly show human sessions, and the agent reads that leave no session are invisible in them. Where a count does exist it is usually taken from the name the caller supplied, which anyone can type. We count these reads ourselves and publish our own number with the unverified share shown separately, because a confirmed-reader figure nobody can audit is worse than no figure.
The third one is ours too, and we publish our own number with its unverified share beside it — what we found reading our own logs.
The specifications, as published
Every version string below was read from the linked page on the date shown. Nothing here is a prediction and nothing here is a claim about placement in any assistant.
| Specification | As published | Last read |
|---|---|---|
| Instant Checkout availability (OpenAI) | US | 2026-09-01 |
| Agent Pay — payment mandates (Mastercard) | Agent Pay 2025-04-29 (Agentic Tokens); Verifiable Intent 2026-03-05; Agent Pay for Machines 2026-06-10; merchant enrolment via acquirer/PSP | 2026-09-03 |
| Catalog imports (Stripe) | 2026-08-26.preview | 2026-08-31 |
| Merchant profiles — terms (Stripe) | 2026-07-29.preview | 2026-08-31 |
| Shared payment tokens — completion (Stripe) | 2026-04-22.preview | 2026-08-31 |
| x402 — machine payments (Stripe) | 2026-05-27.preview | 2026-08-31 |
| UCP — discovery (Google) | 2026-04-08 | 2026-09-01 |
| Trusted Agent Protocol (Visa) | announced 2025-10-14; in development and deployment, no GA date | 2026-09-03 |
| Web Bot Auth — agent identity (IETF draft) | draft-ietf-webbotauth-httpsig-protocol-00 | 2026-09-03 |
The full watch, including what changed and why a change did or did not matter, is on the protocol watch page. — the protocol watch.
Questions developers actually ask
Do I have to implement all three protocols?
No, and the useful way to think about it is that each one you skip leaves a specific silence rather than a partial result. Discovery alone makes you findable and unbuyable. Checkout alone makes you buyable by nobody, because nothing found you. Payment authority alone makes you a merchant agents get all the way to and then stop at. Which order to do them in depends on where an agent currently stops on your site, which is the one thing a report can tell you and a checklist cannot.
Is this the same as being listed inside ChatGPT?
No. Completing a purchase inside an assistant's own surface is a separate programme with its own approval and, on the date at the top of this page, its own geographic limit. Everything on this page is about being operable on your own rails, which is a thing you control, can verify yourself, and keep whatever any assistant does next.
Our site scores well on SEO tools. Why does this fail?
Because they answer different questions. Search optimisation asks whether a person who is shown your page will click it. This asks whether software sent to buy something can complete the purchase. A page can be fast, well-ranked, well-written and entirely unbuyable — the two disciplines share a vocabulary and almost nothing else.
How would I know an agent tried and failed?
Today, mostly, you would not — which is the honest answer and the reason this page exists. There is no error raised on your side, no bounce recorded, and no abandoned cart to email about, because no cart was created. The reads themselves can be counted server-side; the abandonment cannot be, by anyone.
Does any of this help a business that does not sell online?
The first three steps do, and they are most of the work. Being establishable — what you do, on what terms, for whom — is what gets you into an assistant's answer at all, and that is worth having whether or not anything can be bought at the end of it. The last three steps only apply if you take money.
Where do the versions in the table come from?
Each one was read from the source page linked beside it, on the date shown, by a person. A weekly job re-reads those pages and flags the ones that have moved. A page we cannot reach is recorded as unconfirmed and never as a change, because somebody's server being down is not their specification changing.
Check yours
The free report answers twenty-two questions about a domain in plain English, dated, with the evidence under each one, and it prints the sentence above that applies to you. It takes a URL and no account. If you want the fixes done rather than listed, that is an engagement and a person does it.