Skip to content

Agentic commerce

Agentic commerce lets AI shopping agents, such as those built on ChatGPT, Claude, Perplexity or Gemini, find your Magento store, read your catalogue and prices, and buy from you on a shopper’s behalf. It is an addition to your existing store: it does not change how your normal customers check out. Everything it adds is for agents.

This is a standalone Magento plugin. It holds its own payment credentials, so you do not need a separate Musqet payment module installed first. Agents transact with your store over the open UCP (Universal Commerce Protocol) standard, so any agent that speaks it can buy from you without a bespoke integration.

  1. Install the agentic module and run the Magento setup:

    Terminal window
    bin/magento module:enable Musqet_AgenticUcp
    bin/magento setup:upgrade
    bin/magento setup:di:compile
    bin/magento cache:flush
  2. Add two short redirects to your webserver so agents can reach the standard discovery paths. Magento cannot serve the /.well-known/ paths itself, so point them at the plugin’s internal endpoints. For nginx, inside your Magento server block:

    location = /.well-known/ucp { return 301 /ucp/wellknown; }
    location = /.well-known/agents.json { return 301 /ucp/wellknown/agents; }

    For Apache, the equivalent RewriteRule directives in the Magento vhost:

    RewriteRule ^\.well-known/ucp$ /ucp/wellknown [R=301,L]
    RewriteRule ^\.well-known/agents\.json$ /ucp/wellknown/agents [R=301,L]

    Reload the webserver afterwards.

  3. Open Stores > Configuration > Services > Musqet Agentic UCP and fill in your merchant details: your support email, your returns, shipping and privacy policy links, and the countries you ship to.

  4. In the Payment Rail Credentials section of the same settings, enter the credentials for the rails you want to offer: your Bitcoin Business ID and Musqet API Key to settle over Lightning, and additionally a Cardstream Merchant ID and Cardstream Shared Secret to accept a customer-authorised card. These card fields belong to this plugin; the standalone Cardstream gateway plugin labels the same two credentials Gateway Merchant ID and Gateway Signature Key. Leave the card fields blank to run Lightning-only.

You can then run the plugin’s built-in check, bin/magento musqet:agentic:check on your server, which reports each agent-facing surface as OK or tells you exactly what to fix. Most surfaces (the MCP server, product feeds and SEO) can be turned off individually if you do not want them.

The plugin’s MCP server (Model Context Protocol) gives agents tools to read your store (search products, check stock, look up prices) and to start a checkout. An API key gates the read tools; checkout is open, as set out below.

  • In the MCP server section of the Musqet Agentic UCP settings, generate an API key and paste it in. This one key authorises the MCP read tools (when you require a key for them) and the order-update subscriptions below.
  • To revoke access, replace the key. The old key stops working immediately, and any agent using it must be given the new one.
  • You choose whether the read-only MCP tools may be used without a key, using the “Allow anonymous read tools” setting. Checkout needs no key at all: the MCP checkout tool, like the underlying open UCP checkout API, is anonymous by design, and the payment is authorised by the customer’s own card authorisation or the Lightning payment itself, not by this key.

With agentic checkout enabled, an agent can complete a checkout on the shopper’s behalf. The agent opens a checkout session for the items, and the payment settles through Musqet on one of three rails:

  • Lightning, which is instant and has no chargebacks,
  • a customer-authorised card, settled through the Musqet gateway using the card credentials in the plugin’s settings, or
  • a manual checkout handoff, on by default, where the agent passes the shopper a link to finish the checkout themselves.

Which rails settle a payment depends on which credentials you entered: Lightning needs the Bitcoin Business ID and Musqet API Key, and the card rail additionally needs the Cardstream Merchant ID and Cardstream Shared Secret. The manual handoff needs no payment credentials and stays on unless you turn it off, so an agent can always complete an order even before you have set up Lightning or cards. The shopper’s order then appears in your Magento admin like any other order.

Agents can subscribe to updates so they do not have to keep polling your store. Using the API key above, an agent registers a webhook and the events it cares about, such as a price change or a new order, and your store pushes those updates to it as they happen. Deliveries that fail are retried automatically.

The plugin publishes the standard files agents look for so they can find and read your store on their own:

  • a UCP advert and an agent manifest at the well-known paths, listing your store’s identity, contact details, policies, shipping countries and the interfaces agents can use, and
  • an llms.txt summary for agents that read plain text rather than a structured manifest.

Alongside these, the plugin keeps product feeds (for Google, Bing, Meta and OpenAI) and structured data on your pages up to date as your catalogue and stock change, so agents and AI search see current products and prices. Submit the feed URLs to each provider once, and they stay fresh.

What you seeWhat it meansWhat to do
The check reports the UCP advert as failedNo checkout rail is configured at all: Lightning, card and the manual handoff are all off (or the module or base URL is wrong)Enable at least one rail: enter Lightning or Cardstream credentials in Payment Rail Credentials, or leave the manual checkout handoff on, then confirm the module is enabled and your base URL is correct
The well-known paths report a warningThe webserver redirects are not in placeAdd the two redirects for /.well-known/ucp and /.well-known/agents.json, then reload your webserver
An agent cannot check outNo checkout rail is configured, or the checkout endpoint is unreachableSet up at least one rail (Lightning or Cardstream credentials, or leave the manual handoff on) and confirm the well-known discovery paths resolve. Checkout itself needs no API key
Your details are wrong in the manifestThe config cache is staleClear the Magento config cache so the manifest and llms.txt pick up your changes
Products are missing from a feedOut-of-stock items are excluded, or the feed cache is oldTurn on “Include out-of-stock products” if you want them, or wait for the cache to refresh (it also refreshes on a product change)