Inspiration

Shopping agents are becoming capable of finding and recommending products, but two important pieces are still missing. Most merchants have websites designed for people rather than agents, and shoppers have little visibility or control when an agent is ready to act. We built DONE to solve both sides of that problem.

Our goal was a commerce experience that feels as simple as a conversation without becoming a black box: one merchant URL becomes an agent-ready storefront, and one precisely scoped approval turns a recommendation into a completed simulated purchase.

What it does

DONE is a two-sided conversational-commerce platform.

Merchant Studio

A merchant—or, in this independent hackathon demonstration, an operator using public product information—provides a storefront URL. DONE:

  • discovers public product pages through sitemaps and structured commerce data;
  • extracts products, variants, prices, availability, images, descriptions, and provenance;
  • flags missing or uncertain fields for human review;
  • publishes the approved catalogue as a structured, UCP-aligned agent interface; and
  • shows the human-readable catalogue beside the exact machine-readable response an agent receives.

Every imported fact retains its source URL and retrieval time. DONE does not claim affiliation with the referenced merchants, and the generated layer does not replace their official website or checkout.

DONE Shopper

A shopper describes an outcome in natural language—for example, comfortable noise-cancelling headphones under S$450 that can be obtained in Singapore before a flight.

The OpenAI-powered agent decides what it needs to search, queries the live web and the published merchant catalogue, opens material public pages in an isolated Chrome session, and streams that browser into the interface. It then:

  1. interprets the shopper's hard constraints;
  2. researches current candidates;
  3. rejects products that fail those constraints;
  4. compares the strongest eligible options;
  5. explains one evidence-backed recommendation; and
  6. lets the shopper inspect every source before selecting it.

The searches, URLs, and recommendation are generated at runtime rather than stored as a fixed demo path. When a page presents a CAPTCHA or access challenge, DONE does not bypass it; it excludes that page and chooses another public source.

Trusted approval and simulated payment

Selecting a recommendation creates an exact purchase preview containing the merchant domain, product, fulfilment, total, evidence, amount ceiling, expiry, and the action being authorized.

DONE signs a short-lived purchase mandate that is bound to the shopper session, agent, merchant, operation, cart hash, currency, amount ceiling, nonce, and expiry. The shopper presses Approve and completes a genuine WebAuthn/passkey ceremony using the authentication method offered by the device, such as Touch ID.

Only a verified approval mints a single-use demo payment credential. DONE then sends a signed, merchant-scoped request to a deterministic Visa payment simulator and displays the resulting receipt and redacted audit trail inside the conversation.

The payment and merchant order are explicitly simulated: no real money moves, no real order is placed, and DONE never collects, generates, stores, or displays a card number.

How we built it

DONE is built with Next.js 16, React 19, TypeScript, and Node.js.

The shopping agent uses the OpenAI Agents SDK with model-selected tools for public-web search, visible page inspection, and agent-ready merchant search. Playwright and Chrome DevTools Protocol control an isolated local Chrome profile and stream real screencast frames plus activity metadata into the shopper interface.

Merchant Studio uses multiple extraction paths, including sitemaps, JSON-LD/Schema.org commerce data, and common storefront formats. Network safety checks block private destinations, validate redirects, respect robots.txt, and limit crawl size and breadth.

The published merchant layer exposes an experimental UCP-aligned subset for catalogue search, product lookup, cart creation, and simulated checkout. We describe it as UCP-aligned rather than claiming formal conformance.

For trust, DONE uses SHA-256 cart binding, Ed25519 signatures, short-lived nonces, amount ceilings, single-use credentials, idempotency, replay protection, and WebAuthn through SimpleWebAuthn. A built-in safety proof demonstrates that changed totals, changed merchants, expired mandates, and second executions are rejected.

Challenges we ran into

The public web is inconsistent. Product data can live in JSON-LD, storefront APIs, sitemaps, rendered pages, or nowhere structured at all. We combined several extraction paths and made uncertainty visible instead of inventing missing prices or availability.

Live browsing meets bot protection. Search engines and merchant sites can present CAPTCHAs or block automation. We designed the agent to recognize those challenges, avoid bypassing them, and adapt to another source while keeping the evidence trail honest.

Making autonomy trustworthy was harder than making a chatbot. We had to bind approval to one exact cart and prove that nothing material could change after consent. This led to signed mandates, WebAuthn verification, a one-time credential, and explicit failure demonstrations.

Showing technical depth without cluttering the experience. DONE keeps the conversation calm and simple, while the live computer view, provenance, approval details, and expandable audit trail remain available when a shopper or judge wants to inspect them.

Accomplishments that we're proud of

  • We built the complete merchant-to-shopper loop rather than only a shopping chatbot.
  • Recommendations are grounded in pages opened during the current run.
  • The browser shown in DONE is a real streamed Chrome session, not a prerecorded animation.
  • Authentication uses a genuine platform WebAuthn ceremony.
  • The simulator cannot execute before approval and blocks cart changes, merchant changes, expiry, and replay.
  • The product stays transparent about what is live, what is independently imported, and what is simulated.

What we learned

Agentic commerce needs more than a capable model. Merchants need a predictable machine-readable surface, agents need current evidence, and customers need understandable control over the exact action that will occur.

The best interface is not one that hides the agent. It is one that reveals the right details at the right moment: quiet progress while researching, concise evidence while deciding, and precise scope when approving.

What's next for DONE

Next we would add merchant-authorized onboarding, persistent catalogue storage, scheduled refreshes, deeper category packs for fashion, food, and bookings, and production-grade evaluation of extraction and recommendation quality. We would also deploy the shopper on a stable HTTPS origin for cross-device iPhone approval and integrate a production payment provider when an authorized agent-payment capability is available.

DONE's long-term vision is simple: any merchant can become agent-ready without rebuilding their storefront, and any shopper can delegate a purchase without giving up transparency or control.

Built With

  • chrome-devtools-protocol
  • next.js
  • node.js
  • openai-agents-sdk
  • openai-api
  • passkeys
  • playwright
  • react
  • simplewebauthn
  • tailwind-css
  • typescript
  • ucp
  • webauthn
  • zod
Share this project:

Updates

Submission history