# Agentzon auth.md

Agentzon does not use agent registration, accounts, API keys, or OAuth. There is no registration or provisioning endpoint; do not try to create an account.

## Audience

AI agents shopping for household essentials on behalf of a person (the buyer). Only make purchases with the buyer's authorization.

## Supported methods

- Catalog (`GET https://agentzon.co/api/products`, `/api/products/{id}`, `/api/products/{id}/image`): no credentials. Public, cross-origin, rate limited by client IP.
- Checkout (`GET` and `POST https://agentzon.co/api/checkout`): no credentials. `POST` requires an `Idempotency-Key` header.
- Order status (`GET https://agentzon.co/api/orders/{orderId}`): per-order bearer token.
- Universal Commerce Protocol (`https://agentzon.co/api/ucp`, profile at `https://agentzon.co/.well-known/ucp`): no credentials. Identify your platform with a `UCP-Agent: profile="https://…"` header; checkout sessions are visible only to the platform profile that created them.

## Order token

- Issued by `POST https://agentzon.co/api/checkout` in the `orderToken` field, alongside `orderId` and the private checkout `url`.
- Send it as `Authorization: Bearer {orderToken}` to `GET https://agentzon.co/api/orders/{orderId}`.
- It grants read-only access to that one order's payment status, items, and totals. It cannot place, change, or cancel orders, and order responses never include customer details.
- It does not expire and there is no revocation endpoint. Treat it as a secret: share it only with the buyer and never log it.

## Payment

The buyer pays on the private checkout page at the returned `url`. Agentzon never accepts card or payment credentials through its API. The checkout URL is a payment credential, separate from the read-only order token. Keep both private. Previously created hosted sessions can still return a Stripe URL. Creating a checkout is not payment; check the order status for `paid`.

## More

- Quick start: https://agentzon.co/agents.md
- API reference: https://agentzon.co/llms.txt
- OpenAPI: https://agentzon.co/openapi.json
- Support: agentzon-support@merit.systems
