Inspiration
AI agents are already good at finding products. What bothered me was what happens after they find one.
A person can approve a recommendation in chat, but that approval is still just another message. It does not clearly define the product, merchant, price, quantity, expiration time, or whether the action can be repeated. The agent is expected to interpret the person’s intent correctly and continue.
I wanted to explore a different model. What if human approval became an actual capability that was narrow enough to inspect, short lived enough to trust, and enforced when the agent acted?
That idea became Intent.
What it does
Intent is a shared decision room for human approved agent commerce.
A WebMCP agent can:
- Turn a shopping request into a versioned purchase mandate.
- Search live offers from Shopify’s Global Catalog.
- Compare candidates against the person’s budget, destination, rating, and review requirements.
- Explain why each candidate passes or fails.
- Stage one eligible offer for review.
The person sees the same mandate, evidence, and recommendation. They can change the rules or approve the exact staged offer.
Before approval, the agent has no checkout capability. It is not hidden or disabled. It does not exist.
When the person grants authority, Intent dynamically registers a temporary WebMCP tool frozen to the approved product, variant, merchant, price, currency, quantity, and mandate version. The waiting agent resumes automatically, uses the capability once, and receives a real merchant cart handoff.
The server revalidates the live offer before returning it. The capability then disappears. Replay, broader scope, stale prices, unavailable products, and mandate violations are rejected.
Intent never receives payment credentials and never submits payment.
How we built it
I built Intent with Codex as my primary development partner.
The decision room is hosted on ChatGPT Sites and exposes five WebMCP tools. Four collaboration tools are available while the agent is on the page:
intent_propose_purchase_mandateintent_compare_candidatesintent_read_purchase_mandateintent_stage_candidate_for_approval
The fifth tool, intent_open_approved_checkout_once, is registered only after human approval. Its input schema is constrained to the exact approved values. An AbortSignal removes it after use, expiry, cancellation, or failure.
The schema makes the authority understandable to the client, but it is not the security boundary. A Cloudflare Worker validates every request. A Durable Object issues and atomically consumes the one use lease.
Immediately before the handoff, the Worker resolves the exact Shopify variant again and checks availability, destination, price, identity, and the current mandate.
Shopify Global Catalog and UCP provide live product data from multiple merchants and real merchant checkout URLs. No owned Shopify store, seeded catalog, or shopper account is required.
We also built an optional Codex plugin that routes an ordinary physical product shopping request into Intent. Once the agent reaches the site, the page’s WebMCP tools take over.
Challenges we ran into
The hardest problem was making approval part of the agent’s current turn.
Our first flow required the person to approve on the page and then return to chat to send another message. It worked technically, but it felt like operating a demo instead of using a product.
We changed the staging tool into a bounded wait. The agent stages a proposal, pauses on the human decision, and resumes automatically when authority is granted.
Live catalog data created another challenge. Merchant evidence is often incomplete or inconsistent. Intent had to separate two different questions:
- Does an offer satisfy deterministic transaction rules such as price, availability, destination, rating, and review count?
- Does the merchant description explicitly support the person’s product requirements?
Missing evidence cannot quietly become a pass. Intent returns the evidence and numeric differences to the agent, marks merchant content as untrusted, and keeps the final proposal visible to the person.
The final challenge was enforcing the capability outside the browser interface. A constrained schema communicates the approved scope, but a caller could still send a different request directly to the server.
We therefore enforce the exact scope, expiration, replay protection, and live offer consistency again in the Worker and Durable Object.
Accomplishments that we're proud of
Intent is a complete live product rather than a simulated checkout demo.
- It searches real offers from real Shopify merchants.
- A person and an agent collaborate through the same versioned decision state.
- Checkout authority is genuinely absent before approval.
- The temporary capability appears after a human decision and disappears after one use.
- The server atomically rejects replay and broader authority.
- The approved offer is revalidated against live catalog data before handoff.
- Payment remains with the person and merchant.
- Refresh recovery restores useful decision context without restoring offers, proposals, leases, or authority.
- The repository passes 52 tests, including a 14 case boundary matrix and adversarial lifecycle checks.
The moment I am proudest of is also the simplest. The person clicks once, the waiting agent continues automatically, and seconds later the capability is gone forever.
What we learned
WebMCP is most interesting when tools are not treated as a permanent menu of website functions.
A tool can represent temporary authority. Its appearance can mean that a person approved something. Its disappearance can mean that the purpose ended.
This makes capability discovery, shared page state, and lifecycle events part of the product experience rather than hidden implementation details.
We also learned that human and agent collaboration works better when both participants have distinct responsibilities.
The agent is good at searching, comparing, and organizing evidence. The person should own the rules and consequential decisions. Intent connects those roles without pretending either side can safely replace the other.
Finally, we learned to separate what the agent can infer from what the system can enforce. Intent lets the agent reason over product descriptions, while the server independently enforces the exact transaction boundary.
What's next for Intent
The next step is turning Intent’s authority pattern into a reusable contract for agent enabled websites.
That includes merchant verifiable mandates, signed handoffs, standardized WebMCP annotations for human granted capabilities, agent identity binding, multiple item decisions, and support for additional commerce catalogs.
The longer term goal is broader than shopping. Any consequential agent action, such as booking travel, changing a subscription, approving a financial transfer, or sharing sensitive information, should be expressible as narrow authority that appears only when needed and disappears when its purpose is complete.
Built With
- chatgpt-sites
- cloudflare
- css3
- html5
- javascript
- next.js
- node.js
- react
- shopifyglobalcatalog
- ucp
- universal-commerce-protocol
- vite
- webmcp
- wrangler
Log in or sign up for Devpost to join the conversation.