UCP, starting at /.well-known/ucp.
The Universal Commerce Protocol (UCP) is an open standard for AI agents to discover a business and run catalog search, carts, checkout, identity linking, and orders with it. Google and Shopify founded UCP and released it on 11 January 2026. It is licensed under Apache 2.0, and the current version is 2026-08-25.
What happens on the wire.
- 01
The business publishes a profile
A JSON profile at /.well-known/ucp lists the services, transports, capabilities, and payment handlers the business supports, and can list public keys for signatures.
- 02
The agent’s platform presents its profile
The platform advertises the address of its own profile in the UCP-Agent header.
- 03
Both sides negotiate
The business computes the intersection of the two capability lists and uses the highest version both support.
- 04
Checkout runs on the business’s payment rails
The business stays merchant of record and captures funds through its own payment provider. Payment handlers are specifications for how each payment instrument is processed.
- 05
Orders flow back by webhook
The business pushes order updates to a webhook address from the platform’s profile. Webhooks must be signed.
What a valid result shows, and what it does not.
Shows
- When a platform signs its requests (RFC 9421, with a digest of the body), that a holder of a published key sent that exact request.
- With the AP2 mandates extension, that signed mandates authorized the purchase against checkout terms the business signed.
- Which capabilities and version both sides agreed on for the session.
Does not show
- A UCP-supplied signed user-authorization mandate when the optional AP2 mandates extension is absent. Another consent system can supply separate evidence.
- A portable signed record of the exact request when the platform uses API keys, OAuth, or mutual TLS (mTLS) instead of HTTP Message Signatures. These methods can authenticate a platform credential; they do not establish the human principal or provide the same request evidence.
- Why an order was disputed. Adjustments have no reason-code or evidence fields.
What it leaves on the record.
A UCP order can carry adjustments: refunds, returns, credits, disputes, and cancellations. The type is an open string, and dispute is one example value. An adjustment holds an ID, a time, a status, line items, totals, and a description, with no reason code or evidence fields.
The optional AP2 mandates extension is where the evidence is. UCP says it significantly reduces “risks of tampering and disputes,” and that mandates “may be retrieved and verified days or months later.” Who keeps them, and for how long, is left to the parties.
What to do now.
- 01
Check whether you already publish a profile: request /.well-known/ucp on your store’s domain. Shopify’s help center says agentic storefronts are on by default for eligible stores but does not name UCP. Check your own store rather than assuming that a UCP profile is available.
- 02
Read the capabilities and payment handlers in your profile. They are what agents negotiate against.
- 03
Find out whether the AP2 mandates extension is enabled. Without it, UCP supplies no AP2 mandate. Check whether another consent system supplies a signed authorization record.
- 04
Keep signed order webhooks and any mandates with the order.
What KYA does with UCP today.
Open standard for catalog, cart, checkout, identity linking, and orders. KYA publishes a UCP profile at /.well-known/ucp for its Shopify sandbox catalog demo; it does not carry traces through UCP checkout.
Short answers.
Is UCP only for Google?
No. Google and Shopify founded it, and Stripe holds a seat on its governing council. A business profile can offer REST, MCP, A2A, or embedded transports to any platform that implements UCP.
Does UCP replace my payment provider?
No. The business stays merchant of record and captures funds through its own payment provider.
What is the difference between UCP and ACP?
UCP, founded by Google and Shopify, covers discovery, catalog, cart, checkout, identity linking, and orders across four transports, with optional request signatures and AP2 mandates. ACP, maintained by OpenAI, Stripe, and Meta, centers on checkout sessions and a scoped payment token, and is still labeled beta.
Keep what each agent order leaves behind.
We’ll map what UCP and the other specs reaching your checkout produce to one record per order, with the gaps marked.