Skip to content
Universal Commerce Protocol Brand hub · en

Framework

Four layers, one contract, one audit.

The UCP framework breaks down the agentic commerce stack into four mappable layers. Each layer describes its objects, standards, maturity and audit checkpoints.

Layer I

Semantic Layer

Make the catalog machine-addressable.

Key objects

  • Product
  • Offer
  • Policy
  • Availability
  • Brand
  • Review
  • Shipping

Standards & protocols

Standard Role Maturity
schema.org Product / Offer Open web semantic contract Established
GS1 / GTIN Global product identifiers Established
Google Merchant Feed De facto commerce feed standard Established
JSON-LD + microdata Structural vehicle in HTML Established

Audit checkpoints

  • 01 Rate of product pages with GTIN, brand, canonical category.
  • 02 Return policy and delivery time exposed in JSON-LD.
  • 03 Consistency across Merchant feed, PIM and HTML DOM.
  • 04 % of pages with enriched attributes (sizes, materials, compatibility).

Layer II

Agent Layer

Open surfaces that agents can query, propose to, and confirm through.

Key objects

  • Tools
  • Resources
  • Prompts
  • Capabilities
  • Identity

Standards & protocols

Standard Role Maturity
MCP (Model Context Protocol) Agent-tool context contract Established
A2A (Agent-to-Agent) Horizontal agent cooperation Emerging
OpenAI Apps SDK Application surface in the ChatGPT client Emerging
ActivityPub / ActivityStreams Candidate open surfaces Prospective

Audit checkpoints

  • 01 Does a typed entry point exist for querying the catalog?
  • 02 Are tools discoverable (manifest, registry)?
  • 03 Can sensitive actions be scoped and audited?
  • 04 What is the end-to-end agent response latency?

Layer III

Transaction Layer

Make payment and identity compatible with a delegated buyer.

Key objects

  • Intent
  • Credential
  • Limit
  • Confirmation
  • Dispute

Standards & protocols

Standard Role Maturity
Stripe Agentic Commerce (ACP) Agent intents and tokens Emerging
Visa Intelligent Commerce Agent-linked card identifiers Emerging
Mastercard Agent Pay Network-side agent rail Emerging
3DS agent-aware Authentication adapted for agents Prospective

Audit checkpoints

  • 01 Can a delegated payment go through with limits and revocability?
  • 02 Is the agent identity traceable in accounting?
  • 03 Are disputes attributed to the correct actor (human / agent)?
  • 04 Does checkout remain deterministic under agentic constraints?

Layer IV

Governance Layer

Expose, version and control the rules that govern the offer.

Key objects

  • Pricing rule
  • Eligibility
  • Territory
  • Audit log
  • Consent
  • Retention

Standards & protocols

Standard Role Maturity
OPA / Rego Policy as code Established
W3C VC (credentials) Verifiable attribute presentation Emerging
ODRL Rights and constraints expression Emerging
ISO 20022 / EDI taxonomy Existing standards to reuse Established

Audit checkpoints

  • 01 Are pricing, eligibility and shipping policies exposed for reading?
  • 02 Does a versioned log of governance decisions exist?
  • 03 Can you opt out a category of agent for a product line?
  • 04 Are retention and consent verifiable by a third party?

The framework in one sentence

A merchant is UCP-ready when an agent can read its offer, interact without ambiguity, pay under control, and the merchant can audit every decision.