Skip to content

Live Demo · No sign-up

Try the MCP without signing up

The public demo-store endpoint responds without authentication. Call search_products, browse_categories, or get_product_details directly from your agent or terminal.

Public endpoint:POST /demo-store/mcp/discoveryLive

Agent Presets

Merchant Config

Trust Tier

Trust Score0.5

< 0.3 triggers KYAI trust gate

Total Transactions

Identity Signals

Provider Confidence (R006)0.9

< 0.6 triggers low confidence block

Key Age (hours): R004
1 h

< 24 h triggers new-key friction

Historical Risk Signals

Completed Orders (R010/R021)0

< 1 triggers probation / first-purchase rules

Velocity Count (R003/R011)0

> 3 triggers repeat-failed-checkout

Failed Checkouts (R011)0

> 3 triggers repeat-failed-checkout

Dispute Count (R009/R024)0

> 2 triggers dispute-history block

Cancel Count (R014)0

> 3 triggers delivery-risk rule

Refund Ratio (R023)0

> 0.5 triggers refund-abuse-guard

Cart & Checkout Signals

Price Delta (bps): R0150

> 100 bps triggers price-change-guard

Discount Codes Tried (R017)0

> 5 triggers coupon-anomaly

Discount Amount (bps): R0170

> 5000 bps triggers coupon-anomaly

Stored Value Cents (R027)0

> merchant max triggers gift-card limit

Shipping & Product Flags

Merchant Rules

0 / 46 active

Identity

Risk

Cart

Geo / Address

Product

Merchant Controls

Verification Level

Min Buyer Trust

0.30

Agents below this score are blocked

Order Amount

$

Currency

Protocol

Agent Scopes

Configure agent profile and click Evaluate
API JSONPOST /api/v1/rules/evaluate

Updates live as you change the controls above

{
  "agentTrustScore": 50,
  "orderContext": {
    "cartTotalCents": 12000,
    "currency": "EUR",
    "itemCount": 1,
    "lineItems": [
      {
        "productId": "prod_001",
        "quantity": 1
      }
    ],
    "cartAttributes": {
      "_agent_key_age_hours": "1",
      "_provider_confidence": "0.9"
    }
  },
  "merchantPolicies": {}
}

Get a Sandbox Key

On demo-store, the discovery endpoint needs no key: browse and read the catalogue with no credential at all. The checkout endpoint needs one for every tool, `create_cart` included. Without it the call answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `no_credentials` (no WWW-Authenticate header): branch on that code, not on the HTTP status. A self-service sandbox key from the `create_sandbox_key` tool covers it. An `X-Payment-Mandate` header is also needed by the checkout tools that spend or settle (preview_checkout, complete_checkout, process_agent_payment, complete_visa_payment, ucp_complete_checkout); the other checkout tools (create_cart and attach_agent_identity and verify_age_over_n and verify_residence_country and verify_legal_person_authorization and apply_discount and get_shipping_rates and select_shipping_option and create_payment_mandate and update_payment_mandate and cancel_payment_mandate and ucp_create_checkout and ucp_update_checkout and ucp_add_items_to_checkout and ucp_get_checkout and ucp_cancel_checkout and get_trust_receipt) don't need it. Without it, demo-store answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `demo_sandbox_mandate_required` (`demo_sandbox_mandate_malformed` plus `remediation.mandate_issues` if it does not parse); branch on that code, not on the HTTP status. A real merchant answers 403 `payment_mandate_required`. Payment is simulated. Step by step: https://trusteed.xyz/.well-known/agent-checkout-guide.json

POST /api/v1/sandbox/key
TTL: 24 hoursRate: 50 req/hourMax 25 keys per IP per day
cURL
curl -X POST https://trusteed.xyz/api/v1/sandbox/key \
  -H "Content-Type: application/json"

# Response:
# {
#   "key": "agnt_sandbox_0123456789abcdef0123456789abcdef",
#   "expires_at": "2026-03-23T12:00:00Z",
#   "rate_limit": "50/hour"
# }

Use the X-Agent-Api-Key header with your sandbox key against demo-store, and only demo-store: any real merchant rejects it.

Frequently Asked Questions

What is the demo store?
It is a public test MCP server with a fictional catalog. It lets you try search, checkout, and payment protocol tools without registration or authentication.
Do I need an API key?
Not for read tools (search_products, browse_categories, get_product_details, get_merchant_profile). Checkout tools require a free 24-hour temporary key obtained via POST /api/v1/sandbox/key.
Which protocols are supported?
MCP (Model Context Protocol), A2A (Agent-to-Agent), and UCP (Universal Commerce Protocol) are live in production. ACP (Stripe fiat), AP2 (Google mandates), and PayPal (Orders API v2) are available in sandbox mode. VIC (Visa cards), KYApay (identity-linked), x402 (USDC stablecoin), WebMCP, and A2UI are in development.
Is payment real?
No. All payment protocols (MCP, ACP, x402, UCP, Visa VIC, MCAP, PayPal, SCP) operate in sandbox/test mode on the demo store. No real charges are processed and no funds are moved.
What are the rate limits?
Read tools: 20 requests/min per IP. Sandbox keys: 50 requests/hour, max 25 keys per IP per day, each key expires after 24 hours.
How do I integrate?
Send JSON-RPC 2.0 requests to POST /demo-store/mcp/discovery. For cart and checkout use /demo-store/mcp/checkout with a sandbox key; payments are simulated. Check the developer docs for TypeScript and Python SDKs.

Ready to connect your real store?

Create your free account and connect Shopify, WooCommerce, or Odoo in less than 5 minutes.

Live Demo: Try the MCP without signing up | Trusteed