
Official MCP RegistryListed
xyz.trusteed/mcp-gateway
Agentic commerce gateway: discovery, search, checkout across Shopify/Woo/Odoo/PrestaShop.
First seen 2 Oct 2026. Evidence as of 7 Oct 2026.
23
Tools
From an anonymous probe
1
Source listings
Each with its own history
9
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| apply_discount | Apply a discount or promo code to the cart. SKYFIRE TOKEN (optional): Pass a kya or kya-pay token in the skyfire-pay-id header to boost trust score. No token required — request proceeds normally if omitted. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| browse_categories | List all product categories in Demo Store with product counts. | Read-only |
| compare_products | Compare 2 to 5 products side-by-side with normalized attribute table and best-value recommendation. | Read-only |
| complete_checkout | Complete the purchase. Provide buyer.name and buyer.email from the conversation before opening approval; ask in chat if either is missing. The approval page only reviews these details. PREFER THE CART CARD: if there is an interactive card for this cart, let the buyer confirm and (when the store offers a choice) pick the payment method there — including retrying after a declined payment or switching method — instead of calling this tool yourself. Each call you make here opens a new card in the transcript instead of updating the one already open. Only call it yourself when there is no interactive card or the buyer explicitly asks you to complete it in chat. Idempotent — replay is keyed on checkout_session_id: any retry against a session that already has an order returns that same order (COMPLETED or PENDING_EXTERNAL_CONFIRMATION) without re-charging. The provided idempotency_key is recorded on the session for audit and short-circuits a repeated call with the same key. If the response has status PENDING_EXTERNAL_CONFIRMATION, no purchase has completed yet: read `order_placed` and `next_action` — a person has to approve or pay at its `url`; `next_action` says whether calling again with the same checkout_session_id and idempotency_key can read the outcome. SKYFIRE TOKEN (payment_method=KYAPAY): Requires a Skyfire pay or kya-pay token. Preferred: pass the JWT in the skyfire-pay-id request header. Alternative: pass as kyapay_token parameter. Claims validated: sub (account ID), jti (replay prevention), amount (USD, matched against cart total), cur (must be USD), sps (pricing scheme). Missing token with KYAPAY method → error. Invalid token → error 'Invalid Skyfire token'. For other payment methods (MOCK, PAYPAL) no Skyfire token is required. PAYMENT MANDATE: this tool also requires one. Send it as the `payment_mandate` argument if your client cannot set headers, or as an `X-Payment-Mandate` header. It must carry `mandate_id`, `max_amount_cents`, `currency`, `exp`, `sub`, `aud`. Two of these are rejected outright if guessed: `exp` is an INTEGER of Unix seconds (not an ISO 8601 date), and `aud` is this store's slug (the one in the URL you are calling, not a domain). Its `currency` must match the cart's currency. Demo Store enforces `max_amount_cents` against the cart total; a real merchant may only observe that boundary, so enforce the buyer's limit in the agent too. The mandate is a spending cap you declare to limit yourself — it authorises nothing and does not prove the buyer's consent — and its `sub` must be the identity you authenticate as. `max_amount_cents` is the spending limit the person you are buying for gave you: ask them if they gave none. Schema: https://trusteed.xyz/.well-known/payment-mandate.schema.json. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| create_cart | Create a shopping cart in Demo Store. Returns a cart_id (the same value as checkout_session_id in preview_checkout, complete_checkout and get_trust_receipt) for use with get_shipping_rates, preview_checkout, and complete_checkout. SKYFIRE TOKEN (optional): Provide a kya or kya-pay Skyfire token in the skyfire-pay-id request header to boost your agent trust score (up to +0.35), which may unlock better pricing or priority service. No token required — request proceeds with neutral trust score (0.50) if omitted or invalid. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| create_sandbox_key | Get a temporary sandbox credential for this demo store, valid 24h. Present it as an `Authorization: Bearer` header, or — when your client cannot set headers — as the `agent_key` argument of the checkout tools. Payments here are simulated: this credential settles nothing and works only on the demo store. No human login is involved at any point. | Not declared |
| get_merchant_profile | Get the complete profile — trust score, policies, compliance, and protocol support — of the merchant this MCP endpoint belongs to. Takes NO parameters: the merchant is fixed by which store's /:storeSlug/mcp endpoint you connected to, not by an argument. To read a different merchant's profile, call this same tool on that merchant's own endpoint instead. | Read-only |
| get_page_content | Get a SUMMARY of a specific page on Trusteed: its title, description, keywords, related tools and the link to the full page. It returns a summary, not the full page text: read the linked URL when the whole page is needed. `content_scope` says what came back. Pass the page slug (e.g. 'for-agents', 'pricing', 'blog') or a blog post slug (returns its excerpt). Use get_site_map first to discover available slugs. Pass page='blog' to list all blog posts. | Read-only |
| get_product_details | Get detailed information about a specific product in Demo Store, including all variants, sizes, colors, and availability. | Read-only |
| get_shipping_rates | Get available shipping rates for the cart. Requires shipping_address — pass it in the call. If the buyer requests the cheapest option, use cheapest_shipping_handle when non-null; it is null when rates cannot be compared in the cart currency. Rates marked authoritative=false are estimates, not the final charge. PREFER THE CART CARD: if create_cart returned an interactive card (the buyer can see and click it), let them enter the address and pick shipping there instead of calling this tool yourself — each top-level call you make here opens a new card in the transcript instead of updating the one already open. Only call it yourself when there is no interactive card (text-only client) or the buyer explicitly asks you to handle it in chat. SKYFIRE TOKEN (optional): Pass a kya or kya-pay token in the skyfire-pay-id header to boost trust score. No token required — request proceeds normally if omitted. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| get_site_map | Returns the complete site map of Trusteed: all public pages organized by category. Use this to discover what sections are available (docs, blog, integrations, legal, marketing) and find the right path before calling get_page_content. | Read-only |
| get_store_trust | Get Demo Store's signed trust score (v4.1, 0-100) with per-signal data quality, confidence level, and a detached JWS for offline verification. Don't trust the number — verify it: download the JWKS at jwks_snapshot_uri, validate jws_compact with signing_kid, and recompute payload_hash_sha256. | Read-only |
| get_trust_receipt | Retrieve the signed trust receipt for a checkout. A receipt records the complete_checkout call; read `order_placed` before telling anyone a purchase happened. Returns the receipt id, the JWS signature and how to verify it. Issuance is asynchronous: right after complete_checkout this may answer `status: "pending"` with a retry delay. `pending` with code `receipt_pending` means the purchase completed and the receipt is on its way; `checkout_in_progress` means it has not settled yet. Only the credential that made the purchase can read its receipt. PREFER THE CART CARD: if the purchase was completed on an interactive card, it already fetches and shows this receipt itself right after the order — calling this tool yourself right after is usually redundant and opens a new card in the transcript. Call it yourself only when there is no interactive card, or the buyer asks for the receipt later in a new turn. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Not declared |
| preview_checkout | Preview the complete order summary before payment. Advances the session to ready-for-payment state. PREFER THE CART CARD: if there is an interactive card for this cart, let it compute and show the summary instead of calling this tool yourself — it keeps the flow in one card. SKYFIRE TOKEN (optional): Pass a kya or kya-pay token in the skyfire-pay-id header to boost trust score. No token required — request proceeds normally if omitted. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| search_docs | Full-text search across all Trusteed public documentation: pages, blog posts, and FAQ entries. Returns ranked results by relevance. Use this to find answers about protocols, pricing, integration guides, trust scores, and more. | Read-only |
| search_products | Search products in Demo Store. Returns matching products with prices, images, availability, and direct links. Results include data for generating a visual product carousel artifact with category filtering. | Read-only |
| search_products_enriched | Search products with enriched data including structured attributes, variants, GTIN, and images. Ideal for comparison and detailed product discovery. Matching is keyword/substring-based (title, description, tags, vendor) with rating-then-review ordering — the rating and review count it orders by are asserted by the merchant and are not verified by Trusteed. Use this when you have concrete keywords, a category, or a price range. | Read-only |
| select_shipping_option | Select a shipping method for the cart. Must call get_shipping_rates first and provide idempotency_key. Reuse the same key for retries of the same cart and option; use a new key if either changes. PREFER THE CART CARD: if there is an interactive card for this cart, let the buyer pick shipping there instead of calling this tool yourself — it keeps the flow in one card instead of opening a new one per step. SKYFIRE TOKEN (optional): Pass a kya or kya-pay token in the skyfire-pay-id header to boost trust score. No token required — request proceeds normally if omitted. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the `create_sandbox_key` tool first (it is in this tool list and needs no credential), then pass the key you get back as the `agent_key` argument — or as an `Authorization: Bearer` header if your client can set headers. Do not ask a person to log in: there is no human login for this store. | Changes data |
| ucp_cancel_checkout | Cancel a UCP checkout session. Transitions to 'canceled' status. Cannot cancel already completed checkouts. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Destructive |
| ucp_complete_checkout | Complete a UCP checkout session. Transitions to 'completed' status. Idempotent — safe to retry with the same idempotency_key. PAYMENT MANDATE: this tool also requires one. Send it as the `payment_mandate` argument if your client cannot set headers, or as an `X-Payment-Mandate` header. It must carry `mandate_id`, `max_amount_cents`, `currency`, `exp`, `sub`, `aud`. Two of these are rejected outright if guessed: `exp` is an INTEGER of Unix seconds (not an ISO 8601 date), and `aud` is this store's slug (the one in the URL you are calling, not a domain). Its `currency` must match the cart's currency. Demo Store enforces `max_amount_cents` against the cart total; a real merchant may only observe that boundary, so enforce the buyer's limit in the agent too. The mandate is a spending cap you declare to limit yourself — it authorises nothing and does not prove the buyer's consent — and its `sub` must be the identity you authenticate as. `max_amount_cents` is the spending limit the person you are buying for gave you: ask them if they gave none. Schema: https://trusteed.xyz/.well-known/payment-mandate.schema.json. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Changes data |
| ucp_create_checkout | Create a UCP checkout session from line items. Returns a UCP checkout object with status 'incomplete'. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Changes data |
| ucp_get_checkout | Retrieve a UCP checkout session by ID. Returns the current state of the checkout. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Read-only |
| ucp_update_checkout | Update a UCP checkout session. Send line_items to replace all lines (each line may name a variant_id), and/or fulfillment to set the delivery address (fulfillment.destination, which returns the shipping options) and choose one (fulfillment.selected_option_id, which adds shipping to the totals). Only allowed when status is 'incomplete'. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. | Changes data |
Change history
- ucp_update_checkout: input schema changed
- ucp_get_checkout: input schema changed
- ucp_create_checkout: input schema changed
- ucp_complete_checkout: input schema changed
- ucp_cancel_checkout: input schema changed
- preview_checkout: input schema changed
- get_shipping_rates: input schema changed
- complete_checkout: input schema changed
- ucp_complete_checkout: tool added
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | xyz.trusteed/mcp-gateway | 2 Oct 2026 | 7 Oct 2026 | 1 |