E-commerce
August 19, 2026
An agentic commerce glossary is not a specification. It is a map: which word designates a purchase rail, which a connector, which a token, which a chatbot. Here: the terms a merchant needs to read a 2026 presentation without confusing MCP and checkout tunnel, mandate and cookie, merchant of record and measurement session. No gross merchandise volume, no context window in millions of tokens, no Ahrefs share of voice. It is not measured here, so it is not written here.
Google launched the Universal Commerce Protocol (UCP) on January 11, 2026 as an open standard for the shopping journey, from discovery to post-purchase. Google describes agentic commerce as when AI performs tasks on behalf of people. The retailer remains the merchant of record. UCP claims compatibility with A2A, AP2, and MCP. Stripe documents the Agentic Commerce Protocol (ACP) as an open standard created with OpenAI and Meta: how an agent interacts with a business to complete a purchase on behalf of a buyer. Five blocks: agent checkout tunnel, catalog and cart, delegated payment, delegated authentication, HTTP orders and notifications. Two publisher definitions. Not an ISO dictionary.
The fundamental idea: what is agentic commerce. The 2026 schedule: what has been delivered. National totals remain human shopping journeys: 2026 e-commerce statistics.
Summary
Read by layers, not by buzzwords
Read the layer first, then the word. A protocol term says how two machines talk to each other. A payment term says who has the right to debit. A catalog term says what a parser can compare. Mixing them up is signing an "MCP checkout" (MCP payment tunnel) that does not exist.
Layer | Examples of terms | What the term does not decide |
|---|---|---|
Idea | Agentic commerce, zero-click, conversational commerce | Which payment provider, which web application firewall, which GTIN |
Purchase rail | UCP, ACP, payment session, order notifications | How the LLM chooses a tool |
Payment / mandate | AP2, delegate payment, SCA, 3-D Secure | The search ranking of your product listing |
Transport / tools | MCP, JSON-RPC, tool use, A2A | Who the merchant of record is |
Product data | GTIN, JSON-LD Product, feeds, item_group_id | The dispute reason code |
Named agents (ChatGPT, Gemini, Copilot) are products, not protocols. They are categorized under AI shopping agents. An MCP server is a job, not a ranking: e-commerce MCP servers. A product can speak ACP one day and UCP the next. The word in the administration interface is not the legal contract, nor the feed, nor the web application firewall. Keep the three separate when you read a glossary page, and when you sign.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
The idea: agentic, conversational, zero-click
Agentic commerce
Customer journeys where a software agent performs all or part of the discovery, evaluation, and purchase on behalf of a person. Google: AI completes tasks on behalf of people. Stripe / ACP: the agent completes a purchase on behalf of a buyer. The useful definition for a merchant is narrower: comparison and, with a mandate, payment, without displaying your product page.
Conversational commerce
An older term (messaging, brand chat). A Business Agent in Search can respond in the brand's tone without ever placing an order. It is not a transactional rail. Google launched both on the same day, January 11, 2026: UCP (purchasing) and Business Agent (chat).
Zero-click commerce
A purchase completed without the buyer opening your website. On the merchant side, the artifact is often just the order and an HTTP notification, not a browser session. You can remain the merchant of record for the transaction and still lose the email and the measurement funnel.
Recommendation agent and transactional agent
The former provides a shortlisted selection to a human. The latter submits an order based on a mandate. Confusing the two is like treating a chat as a payment funnel.
AI agent
A system where a model chooses the next action (tools, APIs, browser) instead of following a fixed script. Autonomy is a spectrum. A production agent still often pauses before a payment. Human-in-the-loop: a human gatekeeper for irreversible actions. An autonomous agent in the marketing sense ("it buys on its own") is not what SCA, 3-D Secure, or a payment provider require: it is what a slideshow sells.
The rails: UCP, ACP, AP2, A2A, MCP
Several protocols carry different parts of the purchase. None has "won". The detail of the axes is in how the protocols differ.
UCP (Universal Commerce Protocol): Google open standard, January 11, 2026, purchasing journey (discovery, purchase, post-purchase). Co-developed with Shopify, Etsy, Wayfair, Target, Walmart. According to Google, it is compatible with A2A, AP2, and MCP. The merchant remains the seller of the transaction.
ACP (Agentic Commerce Protocol): Stripe, OpenAI, and Meta open standard. Agent payment funnel (create, update, terminate a session), catalog and cart, delegate payment, delegate authentication (OAuth 2.0), HTTP orders and notifications. Stripe points to an OpenAPI specification dated 2026-04-17. OpenAI cited as the first agent platform; Stripe as the first compatible payment provider. It is not the only candidate.
AP2 (Agent Payments Protocol): Google payment protocol (announced 2025), sub-layer. Signed mandates so that a network can verify that an agent expense has been authorized. Not a catalog. Not a storefront.
A2A (Agent-to-Agent): communication protocol between agents (HTTP, JSON-RPC, SSE, Agent Card). This is not a payment funnel. Google lists it as compatible with UCP.
MCP (Model Context Protocol): how a LLM host discovers tools, resources, prompts. JSON-RPC 2.0. Not a purchasing journey. UCP and ACP can be transported over it; this does not make it a commerce rail.
The platform work (catalog, robots, delegated payment) does not depend on the buzzword of the moment: what platforms need to change.
Money: tokens, tokens, operation vendor
As soon as no one is at the checkout, an object is needed to state who authorized what, for which cart, up to what limit.
Mandate: a signed, bounded authorization. AP2 describes three families of these: Intent (the brief), Cart (the exact approved cart), Payment (the payment instruction). Together, they are non-repudiable proof that the cardholder delegated, not that the agent improvised.
Delegate payment: ACP block: passing payment tokens between buyer, agent, and merchant via payment managers, without exposing the card number to the agent.
Shared Payment Token (SPT): a single-use token, linked to a cart, issued by the buyer's payment provider. The agent does not hold the card. The merchant charges the token once.
Network token: a card number substitute issued by a network (Visa, Mastercard, etc.), often restricted to a specific merchant or use. Useful for agent flows because the scope can be narrow.
Payment service provider / acquirer: the provider supplies the acceptance technology. The acquirer maintains the merchant account. This role does not disappear because the buyer is software. Metadata (agent identity, mandate reference) are added to the message.
Seller of record / merchant of record: who the legal seller is (tax, warranty, customer service). Google: the retailer remains the seller of record. ACP describes an interaction with the merchant, not an agent that has become a store. Remaining the seller of record does not prevent losing the relationship of attention.
After the purchase, the dispute vocabulary has not yet been written for "the agent got the wrong variant": which is where agentic commerce still breaks down.
Identity: agent, OAuth, SCA
Agent identity: verifiable identity of the agent, distinct from that of the human principal. A User-Agent is an allegation. An HTTP message signature, an OAuth token, a signed mandate are proofs. Without proof, the application firewall sees a scraper.
Agent Card: A2A JSON document, often under /.well-known/, which announces name, skills, authentication, transport. Entry point for another agent. Not a bank card.
Delegate authentication: ACP block: OAuth 2.0 for an agent to act on behalf of the buyer with a company.
SCA / 3-D Secure: in the EEA, PSD2 often requires strong authentication (two-factor). 3DS is the network protocol that carries it on a card. An agent at 3 a.m. does not respond to a challenge. Written exemptions for recurring transactions were not designed for a single-order third party. An acquirer question, not a launch slogan.
Attestation / verifiable credential: signed statement on properties (code, hardware, delegation). Agent identity candidates. Not yet the default for your delivery network.
If you do not log who called the catalog, you will not be able to separate agent and scraper tomorrow: what to log and why.
Catalog: what a machine can compare
An agent only compares fields. Data terms decide whether it sees you.
Structured product data: readable attributes without rendering: feeds, JSON-LD Product/Offer, catalog APIs. The accuracy of these fields is the limit of comparison.
GTIN: GS1 item identifier (EAN, UPC, etc.). Deduplicates across merchants. An internal SKU only deduplicates for you. Do not invent a GTIN.
schema.org/Product: page markup type. name, image, sku, gtin, brand, offers. An Offer without a typed price is an empty Offer for a machine.
Item group / variants: a group (item_group_id) plus dimensions (size, color). A merged row "for tables" is not a group.
The instruction manual: product feeds for AI agents. The blind spot of the product page: storefront ready for LLMs.
Payment: session, cart transfer, notifications, idempotency
Agentic checkout: checkout flow initiated and, potentially, completed by an agent via a programmatic interface, not a human form. This is not Shopify Checkout.
Checkout Session: server-side object of an attempt, identified by an id, of an authorized cart. ACP defines one. Stripe Checkout and other checkout funnels use the same pattern.
Cart handoff: transfer of a cart built elsewhere (agent, chat) to the merchant for completion. URL, ACP Cart object, or in-app payment.
Webhooks: HTTP notifications when an event occurs (paid, refunded, dispute). The agent does not maintain an open session. Without notification, you no longer have a source of truth after the purchase.
Idempotency key: client identifier to deduplicate a retry. Without it, a timeout plus a retry = two authorizations. Critical as soon as the buyer is a software program.
Decoupled storefront / Storefront API: catalog, cart, and checkout funnel exposed via API. Closer to an agent than a PHP monolith that only assembles the price in JavaScript. A public API is still not a rail: it does not prove the mandate.
MCP, tool use, JSON-RPC: the bus, not the payment tunnel
MCP standardizes a LLM's access to tools and context. A server exposes resources, prompts, tools. The host (Claude, Cursor, a ChatGPT app) discovers them. JSON-RPC 2.0. Tools are controlled by the model: the model can choose to call them. It is not a GTIN, not a reason code, not an operation seller.
The UCP claims it can be transported via REST or MCP. The ACP as well: payment configuration via traditional API or MCP. So "we do MCP commerce" can mean: we have wrapped an existing payment tunnel. Or: we let the model choose create_order all by itself. This is not the same thing. See MCP and API and choose an MCP server.
Tool use / function calling: the model issues a structured call, the host executes, the result returns. MCP is a bus for this. JSON-RPC is the wire. SSE is often used to send the stream continuously. None of these three words authorizes a card charge.
What presentations mix
We hear | We believe | It means |
|---|---|---|
“We are UCP” | All agents buy from us | You speak the Google language of the journey, on the surfaces that implement it, if you are eligible |
“We are ACP” | ChatGPT is a sales channel | You expose payment funnel, cart, delegated payment; each AI platform still has its own integration |
“We have MCP” | Agents pay | A LLM can call your tools. Payment is elsewhere |
“Seller of record” | We keep the customer | We handle tax and after-sales service. The session and email can remain with the agent |
“Tokenized” | No more PCI | The card number is no longer in the agent. You still have a payment service provider, a mandate, a possible dispute |
“Zero-click” | No more website | No more session on your origin. The HTTP notification and the feed remain the product |
A presentation that piles up GEO (being cited by a model), AI visibility, and “4,700% AI sessions” is not a glossary. It is a pitch. Citation share of voice does not have a single public standard. Do not treat them like a GTIN. GEO remains a content practice. It is not a purchasing protocol, and it does not add a mandate on a card.
How to ask a seller a question
When a vendor says "agentic", ask for five words: catalog, identity, mandate, merchant of record, HTTP notification. If they answer "MCP" to everything, it's not a rail. If they answer "UCP" when your feed has no typed price, you are not comparable. If they answer "ACP" when the application firewall blocks everything without a mouse, the agent won't arrive.
Keep the English terms of the specifications (UCP, ACP, mandate, seller of record) alongside a French sentence. Translating mandate as "mandat" is correct. Translating MCP as "payment tunnel protocol" is wrong.
Five questions are enough in a meeting. Which catalog does the agent actually read (feed, JSON-LD, API)? How does it identify itself at the entry point? What mandate or token object reaches the payment provider? What proof remains in the order if a dispute arises in six months? What notification tells you it's paid, refunded, disputed? If the vendor cannot name all five, the glossary has already done its job.
This glossary does not replace a specification. It prevents signing the wrong one. For the rest, open the UCP or the ACP, not a consulting firm's hypothesis.
Frequently Asked Questions
Are UCP and ACP the same thing?
No. UCP (Google, January 11, 2026) is a purchasing journey language, representing the seller side of the transaction for the brand. ACP (Stripe, OpenAI, Meta) describes the checkout funnel, cart, delegated payment and authentication, orders, and HTTP notifications. AP2 sits beneath the payment layer. MCP is none of these three.
What is a mandate?
A limited authorization, often signed, that the agent presents instead of the cardholder. Intent / Cart / Payment in AP2. Token and payment manager in ACP. Without this, you just have a scraping bot that knows your GraphQL.
Is MCP enough to sell?
No. MCP connects tools to an LLM. Selling requires a readable catalog, an identity at the entry point, a delegated payment, and proof. The MCP link of a commerce rail is not the rail itself.
"Seller of the transaction", does that mean I keep the customer?
It means you remain the legal seller. It does not mean you see the session, the email, or the journey. Zero-click: often the opposite.
Where to start on this list?
Agentic commerce (concept), UCP / ACP / AP2 / MCP (layers), mandate and delegated payment (money), GTIN and structured data (machine visibility), payment session and HTTP notifications (afterwards). The rest is framing vocabulary.
Why only two sources here?
Because a glossary of dozens of URLs is not a bibliography, it is noise. UCP and ACP are the two public texts that define agent purchasing in 2026. The rest of the terms are framed in relation to them, or referred to internal articles.
Sources

Enzo
August 19, 2026


