Live Demo · No sign-up
Try the MCP without signing up
The public demo-store endpoint responds without authentication. Call search_products, browse_categories, or get_product_details directly from your agent or terminal.
Tools available without an API key
Rate limit: 20 requests/min per IPsearch_products
Search products by query, category, or price range
get_product_details
Get full product details, variants, and availability
browse_categories
List all product categories and subcategories
get_merchant_profile
Merchant trust score, policies, and shipping SLA
Example: Agent Transcript
Send this cURL request or use it from any MCP agent
curl https://trusteed.xyz/demo-store/mcp/discovery \
-X POST \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "search_products",
"arguments": { "query": "sneakers" }
}
}'Example response
{
"products": [
{
"id": "prod-001",
"title": "Nike Air Max 90",
"price": 130,
"currency": "USD",
"category": "Sneakers",
"in_stock": true,
"vendor": "Nike",
"rating": 4.7
},
{
"id": "prod-002",
"title": "Adidas Ultraboost 23",
"price": 190,
"currency": "USD",
"category": "Sneakers",
"in_stock": true,
"vendor": "Adidas",
"rating": 4.5
},
{
"id": "prod-003",
"title": "The North Face Nuptse Jacket",
"price": 320,
"currency": "USD",
"category": "Jackets",
"in_stock": true,
"vendor": "The North Face",
"rating": 4.8
}
],
"total": 3,
"query": "sneakers"
}Tool contracts / Quick Tool Test
get_merchant_profile: response fields
Quick Tool Test
Click a tool: the request is sent live to the demo-store MCP endpoint. No sign-up required.
Click a tool to see the live response →
Checkout tools (simulated)
All six need a credential on demo-store, on the endpoint we recommend (/demo-store/mcp/checkout) and on the deprecated alias (/demo-store/mcp) alike: the sandbox key or the widget's cart token. A missing credential on a checkout tool comes back as a JSON-RPC error with error.data.code no_credentials (credentials_not_accepted if the one you sent was refused). Branch on that code, not on the HTTP status: on demo-store it arrives with HTTP 200 and no WWW-Authenticate header, and its remediation tells you to call create_sandbox_key; on a real merchant it is HTTP 401 with a WWW-Authenticate challenge. Get a temporary one (24h): POST /api/v1/sandbox/key
complete_checkout: what it returns
COMPLETED: The order exists and order_id is set. On demo-store the order is simulated: no money moves.
ALREADY_PLACED: This checkout_session_id already had an order: you get that same order back, never a second one.
PENDING_EXTERNAL_CONFIRMATION: A person still has to act before the order is final. Send the buyer to approval_url (demo-store: approve only, nothing is charged) or payment_url (a merchant that takes card payment on our page); on Shopify stores and with PAYPAL the link is in the text content. Then call complete_checkout again with the same checkout_session_id and the same idempotency_key.
Get a Sandbox Key
On demo-store, the discovery endpoint needs no key: browse and read the catalogue with no credential at all. The checkout endpoint needs one for every tool, `create_cart` included. Without it the call answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `no_credentials` (no WWW-Authenticate header): branch on that code, not on the HTTP status. A self-service sandbox key from the `create_sandbox_key` tool covers it. An `X-Payment-Mandate` header is also needed by the checkout tools that spend or settle (preview_checkout, complete_checkout, process_agent_payment, complete_visa_payment, ucp_complete_checkout); the other checkout tools (create_cart and attach_agent_identity and verify_age_over_n and verify_residence_country and verify_legal_person_authorization and apply_discount and get_shipping_rates and select_shipping_option and create_payment_mandate and update_payment_mandate and cancel_payment_mandate and ucp_create_checkout and ucp_update_checkout and ucp_add_items_to_checkout and ucp_get_checkout and ucp_cancel_checkout and get_trust_receipt) don't need it. Without it, demo-store answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `demo_sandbox_mandate_required` (`demo_sandbox_mandate_malformed` plus `remediation.mandate_issues` if it does not parse); branch on that code, not on the HTTP status. A real merchant answers 403 `payment_mandate_required`. Payment is simulated. Step by step: https://trusteed.xyz/.well-known/agent-checkout-guide.json
curl -X POST https://trusteed.xyz/api/v1/sandbox/key \
-H "Content-Type: application/json"
# Response:
# {
# "key": "agnt_sandbox_0123456789abcdef0123456789abcdef",
# "expires_at": "2026-03-23T12:00:00Z",
# "rate_limit": "50/hour"
# }Use the X-Agent-Api-Key header with your sandbox key against demo-store, and only demo-store: any real merchant rejects it.
Supported Protocols
The demo store exposes 12 protocols. The 4 MCP discovery tools work with no credential; the 6 on the checkout endpoint require a sandbox key, `create_cart` included. 4 in production (MCP, A2A, UCP, AG-UI), 2 in sandbox (ACP, x402), 6 coming soon (AP2, VIC, KYApay, PayPal, MCAP, WebMCP).
Model Context Protocol: discovery and checkout tools. Call tools/list on each bucket for the current set
Stripe-based fiat payments in test mode
Google Agent Payment Protocol: mandate-based confirmations
USDC stablecoin payments via HTTP 402
Visa Intelligent Commerce: tokenized card payments
Identity-linked JWT payments via Skyfire
PayPal Orders API v2: sandbox verified, buyer approval flow
Mastercard Agent Pay: Ed25519 signatures + Stripe pass-through
Agent-to-Agent protocol: task delegation and SSE streaming
Universal Commerce Protocol: 5 checkout tools, AP2 delegation, /.well-known/ucp discovery
Browser bridge for MCP over navigator.modelContext: bundle served, native mode unvalidated
Agent-User Interaction Protocol: real-time SSE, human-in-the-loop checkout, cryptographic confirmation (188 tests)
Guided Scenarios
Pre-built demos that run tool calls step by step
Search for sneakers, add to cart, and complete checkout, the simplest E2E flow. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
Search, cart, and checkout for boots on Demo Store. complete_checkout waits for the buyer's approval, then places a simulated order with payment_method MOCK: COMPLETED with an order_id, and no money moves.
Search products, compare two options by price and rating, then purchase the best match.
8-signal scoring pipeline in action: agent evaluates trust signals, tier assignment, and rule engine before purchasing. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
UCP identity linking provides a 10% gold-tier loyalty discount. Demonstrates legitimate discount vs. fraud detection. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
Agent uses UCP but the store only supports AP2/MCAP. Router selects AP2 with translationRequired=true. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
A bot-like agent (velocity 1500ms) with promo abuse signals (15 probes) is blocked by R003 + R004 before checkout. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
The store publishes a $500.00 cap per order in its agent policy. The agent puts a $2,499 item through: the preview passes — merchant rules are not evaluated there — and the denial lands at settlement, with CHECKOUT_BLOCKED_BY_POLICY and no order created. The agent then buys within the cap. The limit here belongs to the merchant; the sibling scenario covers the one the agent carries. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
The agent presents a payment mandate capped at $200 and tries a $260 order. Trusteed denies it with a structured explanation the agent can act on (the mandate's own limit, so nothing about the merchant leaks), and the agent corrects the cart and completes. The limit here is the one the agent brings; the merchant's own cap is a separate axis, covered by the high-value order scenario. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
The merchant's own price moves between the approved preview and the execution. Trusteed revalidates against the authoritative catalog and asks the agent to reconfirm the exact state before settling. A stock shortfall blocks instead, because reconfirming cannot fix it. If the demo payment options are enabled, complete_checkout charges the chosen method with test funds; with them off, nothing is charged.
Search products by keyword, category, or price range
Execute a tool to see the response here
Select a tool in the left panel and click Execute
Session State
Required for checkout & UCP tools. Valid 24h.
search_products
DOM declarativeSearch products by keyword
get_product_details
JS imperativeGet full details for a product by ID
browse_categories
JS imperativeList all product categories
No parameters required
get_merchant_profile
JS imperativeMerchant trust score, policies, and protocols
No parameters required
WebMCP also supports declarative tool registration via HTML attributes. Agents can discover tools by scanning the DOM.
Try a guided scenario
AG-UI Playground
ReadyNo events yet
No items in cart
Agent Presets
Merchant Config
Trust Tier
< 0.3 triggers KYAI trust gate
Total Transactions
Identity Signals
< 0.6 triggers low confidence block
< 24 h triggers new-key friction
Historical Risk Signals
< 1 triggers probation / first-purchase rules
> 3 triggers repeat-failed-checkout
> 3 triggers repeat-failed-checkout
> 2 triggers dispute-history block
> 3 triggers delivery-risk rule
> 0.5 triggers refund-abuse-guard
Cart & Checkout Signals
> 100 bps triggers price-change-guard
> 5 triggers coupon-anomaly
> 5000 bps triggers coupon-anomaly
> merchant max triggers gift-card limit
Shipping & Product Flags
Merchant Rules
0 / 46 activeIdentity
Risk
Cart
Geo / Address
Product
Merchant Controls
Verification Level
Min Buyer Trust
0.30Agents below this score are blocked
Order Amount
Currency
Protocol
Agent Scopes
Updates live as you change the controls above
{
"agentTrustScore": 50,
"orderContext": {
"cartTotalCents": 12000,
"currency": "EUR",
"itemCount": 1,
"lineItems": [
{
"productId": "prod_001",
"quantity": 1
}
],
"cartAttributes": {
"_agent_key_age_hours": "1",
"_provider_confidence": "0.9"
}
},
"merchantPolicies": {}
}Get a Sandbox Key
On demo-store, the discovery endpoint needs no key: browse and read the catalogue with no credential at all. The checkout endpoint needs one for every tool, `create_cart` included. Without it the call answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `no_credentials` (no WWW-Authenticate header): branch on that code, not on the HTTP status. A self-service sandbox key from the `create_sandbox_key` tool covers it. An `X-Payment-Mandate` header is also needed by the checkout tools that spend or settle (preview_checkout, complete_checkout, process_agent_payment, complete_visa_payment, ucp_complete_checkout); the other checkout tools (create_cart and attach_agent_identity and verify_age_over_n and verify_residence_country and verify_legal_person_authorization and apply_discount and get_shipping_rates and select_shipping_option and create_payment_mandate and update_payment_mandate and cancel_payment_mandate and ucp_create_checkout and ucp_update_checkout and ucp_add_items_to_checkout and ucp_get_checkout and ucp_cancel_checkout and get_trust_receipt) don't need it. Without it, demo-store answers HTTP 200 with a JSON-RPC error whose `error.data.code` is `demo_sandbox_mandate_required` (`demo_sandbox_mandate_malformed` plus `remediation.mandate_issues` if it does not parse); branch on that code, not on the HTTP status. A real merchant answers 403 `payment_mandate_required`. Payment is simulated. Step by step: https://trusteed.xyz/.well-known/agent-checkout-guide.json
curl -X POST https://trusteed.xyz/api/v1/sandbox/key \
-H "Content-Type: application/json"
# Response:
# {
# "key": "agnt_sandbox_0123456789abcdef0123456789abcdef",
# "expires_at": "2026-03-23T12:00:00Z",
# "rate_limit": "50/hour"
# }Use the X-Agent-Api-Key header with your sandbox key against demo-store, and only demo-store: any real merchant rejects it.
Frequently Asked Questions
What is the demo store?
Do I need an API key?
Which protocols are supported?
Is payment real?
What are the rate limits?
How do I integrate?
Ready to connect your real store?
Create your free account and connect Shopify, WooCommerce, or Odoo in less than 5 minutes.