Inspiration

AI agents can act, but merchants still need to control what they are allowed to do. Shopify’s agentic-commerce direction and Visa’s emphasis on spending limits, approvals, authentication, and transparency highlighted the same gap: useful autonomy needs enforceable boundaries. AutoShop explores that problem without claiming customer validation.

What it does

AutoShop is a seller-controlled authority layer for agentic commerce.

A seller defines a numerical mandate covering order quantity, value, discount, and remaining stock. Routine orders can proceed automatically. Orders outside the mandate stop as pending actions until the seller reviews and approves that exact exception.

Our demo requests six RAM modules against a five-item limit. WebMCP returns APPROVAL_REQUIRED, prevents an immediate stock change, and allows commit_action only after visible human approval. A successful commit creates an auditable receipt recording the decision path and mandate version.

Everything shown is synthetic; AutoShop processes no real payment or shipment.

How we built it

We built two ordinary web portals with seven role-scoped WebMCP tools:

  • Buyer: browse_products, manage_cart, and submit_order
  • Seller: get_mandate, list_orders, accept_order, and commit_action

The frontend uses framework-free HTML, CSS, and JavaScript. Netlify Functions enforce validation and authorization, while Netlify Database stores versioned mandates, orders, pending actions, inventory, approvals, and receipts.

Strict schemas, page-held authorization secrets, authenticated seller sessions, atomic transactions, and idempotency checks prevent the model from expanding its own authority. We verified the complete workflow in ChatGPT’s in-app Browser and maintained 65 automated regression tests.

Challenges we ran into

The hardest problem was making human control, agent capability, and server authority agree. Buyer and seller tools had to appear only in the correct role and disappear after logout, expiry, or navigation. Confirmation secrets also had to remain outside the model-visible tool schema.

The final recording produced an honest safety test: our prompt contained a mistyped pending-action ID. The agent detected the mismatch, displayed the live alternative, and requested explicit human confirmation instead of guessing. Its browser-tool connection later expired, but it disclosed the reconnect and completed the confirmed, idempotent commit exactly once. We preserved that recovery in the demo while removing only inactive waiting.

Accomplishments that we're proud of

  • Seven deployed, role-scoped WebMCP tools
  • Two visible human authorization boundaries
  • Server-enforced mandate decisions and stale-state protection
  • Token-private order submission and exception approval
  • Atomic inventory mutation with durable receipts
  • Seller-tool removal after logout
  • A reproducible public demo requiring no real customer or payment data

What we learned

Agent safety becomes understandable when people can see and test the boundary. A written instruction is weaker than a refused tool call, and a promise to ask permission is weaker than a contract that cannot execute without current human authorization.

We also learned that identifiers inside natural-language prompts must be treated as untrusted input. Detecting and confirming a correction was safer than silently rewriting the request.

What's next for AutoShop

Our next step is an observed test with an independent small-store order approver. After validating the workflow, we would build a narrow adapter that places the same mandate → exception → approval → receipt boundary in front of an existing merchant order API.

Built With

  • agentic
  • agents
  • ai
  • automation
  • chatgpt
  • commerce
  • context
  • e-commerce
  • elevenlabs
  • firecrawl
  • human-in-the-loop
  • javascript
  • model
  • netlify
  • node.js
  • openai
  • postgresql
  • protocol
  • seller
  • webmcp
Share this project:

Updates

Submission history