Skip to main content
Glama

complete_checkout

Idempotent

Complete the purchase. Provide buyer.name and buyer.email from the conversation before opening approval; ask in chat if either is missing. The approval page only reviews these details. PREFER THE CART CARD: if there is an interactive card for this cart, let the buyer confirm and (when the store offers a choice) pick the payment method there — including retrying after a declined payment or switching method — instead of calling this tool yourself. Each call you make here opens a new card in the transcript instead of updating the one already open. Only call it yourself when there is no interactive card or the buyer explicitly asks you to complete it in chat. Idempotent — replay is keyed on checkout_session_id: any retry against a session that already has an order returns that same order (COMPLETED or PENDING_EXTERNAL_CONFIRMATION) without re-charging. The provided idempotency_key is recorded on the session for audit and short-circuits a repeated call with the same key.

If the response has status PENDING_EXTERNAL_CONFIRMATION, no purchase has completed yet: read order_placed and next_action — a person has to approve or pay at its url; next_action says whether calling again with the same checkout_session_id and idempotency_key can read the outcome. SKYFIRE TOKEN (payment_method=KYAPAY): Requires a Skyfire pay or kya-pay token. Preferred: pass the JWT in the skyfire-pay-id request header. Alternative: pass as kyapay_token parameter. Claims validated: sub (account ID), jti (replay prevention), amount (USD, matched against cart total), cur (must be USD), sps (pricing scheme). Missing token with KYAPAY method → error. Invalid token → error 'Invalid Skyfire token'. For other payment methods (MOCK, PAYPAL) no Skyfire token is required. PAYMENT MANDATE: this tool also requires one. Send it as the payment_mandate argument if your client cannot set headers, or as an X-Payment-Mandate header. It must carry mandate_id, max_amount_cents, currency, exp, sub, aud. Two of these are rejected outright if guessed: exp is an INTEGER of Unix seconds (not an ISO 8601 date), and aud is this store's slug (the one in the URL you are calling, not a domain). Its currency must match the cart's currency. Demo Store enforces max_amount_cents against the cart total; a real merchant may only observe that boundary, so enforce the buyer's limit in the agent too. The mandate is a spending cap you declare to limit yourself — it authorises nothing and does not prove the buyer's consent — and its sub must be the identity you authenticate as. max_amount_cents is the spending limit the person you are buying for gave you: ask them if they gave none. Schema: https://trusteed.xyz/.well-known/payment-mandate.schema.json. Checkout guide: https://trusteed.xyz/.well-known/agent-checkout-guide.json. CREDENTIAL: this store needs one. Call the create_sandbox_key tool first (it is in this tool list and needs no credential), then pass the key you get back as the agent_key argument — or as an Authorization: Bearer header if your client can set headers. Do not ask a person to log in: there is no human login for this store.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
buyerNoOptional buyer contact information
agent_keyNoSandbox credential from `create_sandbox_key`. Use this when your client cannot set an `Authorization: Bearer` header.
cel_contextNoOptional enforcement context for Trusteed native MCP flows (no Shopify/WooCommerce/PrestaShop/Magento plugin). Providing these fields enables full evaluation of rules R004, R006, R008, R012-R013, R015-R017, R026-R028. See each field's own description for what it means and whether the server verifies it. These values are not signed into the receipt — do not include values you cannot substantiate.
kyapay_tokenNoSkyfire pay or kya-pay JWT for autonomous payment via Skyfire (payment_method=KYAPAY). Alternative to passing the token in the skyfire-pay-id request header — the header takes precedence if both are provided. Claims required: sub, jti, amount (USD), cur=USD, sps.
payment_methodNoPayment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement; when enabled it charges the Stripe Shared Payment Token passed as shared_payment_token. X402 is available through the configured x402 protocol flow, not this checkout tool. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified.
payment_optionNoPayment method THE PERSON chose, when preview_checkout returned payment_options. Ask the person; never choose for them. Card numbers and wallet keys are never sent here: the person approves (and, with own_wallet, signs) on the approval page.
idempotency_keyYesUnique key to prevent duplicate charges on retry. Generate once per purchase attempt. Replay is enforced primarily on checkout_session_id (the existing order is returned). The first key seen for a session is recorded; reusing the same key short-circuits to the existing order.
payment_mandateNoPayment mandate with `mandate_id`, `max_amount_cents` (integer, minor units), `currency` (3 letters, must match the cart's), `exp` (expiry as an INTEGER of Unix seconds — not an ISO 8601 date string), `sub` (the identity you authenticate as — it is compared against it) and `aud` (the store slug this mandate is for, e.g. the slug in the URL you are calling — not a domain). It is a spending cap you declare to limit yourself: it authorises nothing and does not prove the buyer's consent. Use this when your client cannot set an `X-Payment-Mandate` header.
checkout_session_idYesCheckout session ID from preview_checkout — the same value as create_cart's cart_id (must be a valid UUID)
shared_payment_tokenNoStripe Shared Payment Token (spt_…) granted by the buyer's agent wallet for payment_method=ACP. Issued by Stripe, scoped to this merchant, amount and currency, and consumed when used: it can be charged once. Only honoured when this deployment enables native ACP settlement.
reconfirmed_state_hashNoSHA-256 of the authoritative merchant state, as returned in details.reconfirm_state_hash by a previous STATE_RECONFIRMATION_REQUIRED error. Required to proceed when the merchant state moved after the approved preview. Passing a stale hash is refused: it means the state moved again and must be reconfirmed anew.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYes
currencyYes
order_idYes
idempotentYes
store_nameYes
test_fundsNo
money_movesNo
next_actionNo
payment_urlNo
total_centsYes
approval_urlNo
order_placedNo
funding_sourceNo
payment_methodNo
shipping_sourceNo
payment_capturedNo
external_order_idNo
checkout_session_idYes
shipping_authoritativeNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • changedInput schema / properties / buyer / properties / email / description
      Previous value: -"Buyer email address"New value: +"Buyer email address (e.g. ana@example.com). Prefilled in the store checkout."
    • changedInput schema / properties / buyer / properties / name / description
      Previous value: -"Buyer full name"New value: +"Buyer first name and surname(s) as one string, e.g. \"Ana García López\". Prefilled in the store checkout."
  2. Changed2 schema fields changed
    • changedInput schema / properties / payment_option / enum
      Previous value: -[
      -  "demo_card",
      -  "demo_wallet",
      -  "own_wallet"
      -]New value: +[
      +  "demo_card",
      +  "demo_wallet",
      +  "own_wallet",
      +  "merchant_card"
      +]
    • changedOutput schema / properties / payment_method / enum
      Previous value: -[
      -  "ACP",
      -  "KYAPAY",
      -  "PAYPAL",
      -  "MOCK",
      -  "X402"
      -]New value: +[
      +  "ACP",
      +  "KYAPAY",
      +  "PAYPAL",
      +  "MOCK",
      +  "X402",
      +  "MERCHANT_CARD"
      +]
  3. Changed2 schema fields changed
    • addedOutput schema / properties / funding_source
      Added value: +{
      +  "enum": [
      +    "platform_test_card",
      +    "platform_test_wallet",
      +    "buyer_wallet"
      +  ],
      +  "type": "string"
      +}
    • addedOutput schema / properties / test_funds
      Added value: +{
      +  "type": "boolean"
      +}
  4. Changed1 schema field changed
    • addedInput schema / properties / payment_option
      Added value: +{
      +  "description": "Payment method THE PERSON chose, when preview_checkout returned payment_options. Ask the person; never choose for them. Card numbers and wallet keys are never sent here: the person approves (and, with own_wallet, signs) on the approval page.",
      +  "enum": [
      +    "demo_card",
      +    "demo_wallet",
      +    "own_wallet"
      +  ],
      +  "type": "string"
      +}
  5. Changed4 schema fields changed
    • changedOutput schema / properties / next_action / properties / reuse_arguments / items / enum
      Previous value: -[
      -  "checkout_session_id",
      -  "idempotency_key"
      -]New value: +[
      +  "checkout_session_id",
      +  "checkout_id",
      +  "idempotency_key"
      +]
    • removedOutput schema / properties / next_action / properties / then_call / const
      Removed value: -"complete_checkout"
    • addedOutput schema / properties / next_action / properties / then_call / maxLength
      Added value: +64
    • addedOutput schema / properties / next_action / properties / then_call / minLength
      Added value: +1
  6. Changed5 schema fields changed
    • changedInput schema / properties / payment_method / description
      Previous value: -"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement; when enabled it charges the Stripe Shared Payment Token passed as shared_payment_token. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified."New value: +"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement; when enabled it charges the Stripe Shared Payment Token passed as shared_payment_token. X402 is available through the configured x402 protocol flow, not this checkout tool. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified."
    • changedInput schema / properties / payment_method / enum
      Previous value: -[
      -  "ACP",
      -  "KYAPAY",
      -  "PAYPAL",
      -  "MOCK"
      -]New value: +[
      +  "ACP",
      +  "KYAPAY",
      +  "PAYPAL",
      +  "MOCK",
      +  "X402"
      +]
    • addedOutput schema / properties / money_moves
      Added value: +{
      +  "type": "boolean"
      +}
    • addedOutput schema / properties / payment_captured
      Added value: +{
      +  "type": "boolean"
      +}
    • addedOutput schema / properties / payment_method
      Added value: +{
      +  "enum": [
      +    "ACP",
      +    "KYAPAY",
      +    "PAYPAL",
      +    "MOCK",
      +    "X402"
      +  ],
      +  "type": "string"
      +}
  7. Changed2 schema fields changed
    • changedInput schema / properties / payment_method / description
      Previous value: -"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified."New value: +"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement; when enabled it charges the Stripe Shared Payment Token passed as shared_payment_token. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified."
    • addedInput schema / properties / shared_payment_token
      Added value: +{
      +  "description": "Stripe Shared Payment Token (spt_…) granted by the buyer's agent wallet for payment_method=ACP. Issued by Stripe, scoped to this merchant, amount and currency, and consumed when used: it can be charged once. Only honoured when this deployment enables native ACP settlement.",
      +  "pattern": "^spt_[A-Za-z0-9_]+$",
      +  "type": "string"
      +}
  8. Changed35 schema fields changed
    • changedInput schema / properties / cel_context / description
      Previous value: -"Optional enforcement context for Trusteed native MCP flows (no Shopify/WooCommerce/PrestaShop/Magento plugin). Providing these fields enables full evaluation of rules R004, R006, R008, R012-R013, R015-R017, R022, R026-R029. Fields are validated and signed — do not include values you cannot substantiate."New value: +"Optional enforcement context for Trusteed native MCP flows (no Shopify/WooCommerce/PrestaShop/Magento plugin). Providing these fields enables full evaluation of rules R004, R006, R008, R012-R013, R015-R017, R026-R028. See each field's own description for what it means and whether the server verifies it. These values are not signed into the receipt — do not include values you cannot substantiate."
    • addedInput schema / properties / cel_context / properties / agent_provider_id / description
      Added value: +"Your provider identifier (e.g. \"openai\", \"anthropic\"), lowercase — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / autorenew_consent / description
      Added value: +"True if the buyer explicitly consented to auto-renewal for a subscription — send only if it applies to you."
    • removedInput schema / properties / cel_context / properties / cart_total_cents
      Removed value: -{
      -  "maximum": 100000000,
      -  "minimum": 0,
      -  "type": "integer"
      -}
    • removedInput schema / properties / cel_context / properties / completed_orders
      Removed value: -{
      -  "maximum": 1000000,
      -  "minimum": 0,
      -  "type": "integer"
      -}
    • addedInput schema / properties / cel_context / properties / completed_orders_24h / description
      Added value: +"Orders this agent has completed with this merchant in the last 24 hours. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • addedInput schema / properties / cel_context / properties / cross_merchant_abuse / description
      Added value: +"True if you have flagged this same buyer/agent for abuse at another merchant. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • addedInput schema / properties / cel_context / properties / digital_good_types / description
      Added value: +"Digital-good categories present in this cart — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / discount_bps / description
      Added value: +"Discount applied to this cart, in basis points — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / discount_codes_tried / description
      Added value: +"Number of discount codes you attempted before this checkout — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / dispute_count / description
      Added value: +"Number of payment disputes this agent has had with this merchant. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • addedInput schema / properties / cel_context / properties / is_b2b / description
      Added value: +"True if you are buying on behalf of a business — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / is_subscription / description
      Added value: +"True if this checkout creates a recurring subscription. The server checks this itself; a value you send cannot hide what it detects."
    • removedInput schema / properties / cel_context / properties / item_count
      Removed value: -{
      -  "maximum": 10000,
      -  "minimum": 0,
      -  "type": "integer"
      -}
    • addedInput schema / properties / cel_context / properties / key_age_hours / description
      Added value: +"Age in hours of the API key/credential you are using with this store. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • addedInput schema / properties / cel_context / properties / lowest_stock / description
      Added value: +"Lowest remaining stock you observed across this cart's line items. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • removedInput schema / properties / cel_context / properties / merchant_avg_order_cents
      Removed value: -{
      -  "maximum": 100000000,
      -  "minimum": 0,
      -  "type": "integer"
      -}
    • addedInput schema / properties / cel_context / properties / merchant_orders_1h / description
      Added value: +"Orders this merchant has received from any agent in the last hour. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • removedInput schema / properties / cel_context / properties / payment_method
      Removed value: -{
      -  "maxLength": 64,
      -  "minLength": 1,
      -  "type": "string"
      -}
    • addedInput schema / properties / cel_context / properties / price_delta_bps / description
      Added value: +"Difference, in basis points, between the price you discovered earlier and the cart's current price. The server may recompute this from the catalogue and replace your value."
    • addedInput schema / properties / cel_context / properties / product_categories / description
      Added value: +"Product categories present in this cart, as you understand them — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / provider_confidence / description
      Added value: +"Your confidence (0-1) in your own agent-provider identification — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / purchase_order_hash / description
      Added value: +"Hash of a purchase order backing a B2B purchase — send only if it applies to you."
    • removedInput schema / properties / cel_context / properties / qty_per_sku_max
      Removed value: -{
      -  "maximum": 10000,
      -  "minimum": 0,
      -  "type": "integer"
      -}
    • addedInput schema / properties / cel_context / properties / refund_ratio / description
      Added value: +"This agent's refund ratio with this merchant (0-1). Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • removedInput schema / properties / cel_context / properties / regulated_evidence_present
      Removed value: -{
      -  "type": "boolean"
      -}
    • addedInput schema / properties / cel_context / properties / requested_scopes / description
      Added value: +"OAuth/permission scopes you requested when authenticating with this store — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / return_policy_mismatch / description
      Added value: +"True if the return policy you were shown does not match what this store publishes elsewhere. Merchant/platform fact — send only with evidence; it can only make a check stricter, never looser."
    • addedInput schema / properties / cel_context / properties / shipping_freight_forwarder / description
      Added value: +"True if the shipping address is a freight-forwarder address — send only if it applies to you."
    • addedInput schema / properties / cel_context / properties / shipping_po_box / description
      Added value: +"True if the shipping address is a PO box. The server checks this itself; a value you send cannot hide what it detects."
    • addedInput schema / properties / cel_context / properties / stored_value_cents / description
      Added value: +"Stored-value amount (e.g. gift card) applied to this cart, in cents. The server checks this itself; a value you send cannot hide what it detects."
    • changedInput schema / properties / checkout_session_id / description
      Previous value: -"Checkout session ID from preview_checkout (must be a valid UUID)"New value: +"Checkout session ID from preview_checkout — the same value as create_cart's cart_id (must be a valid UUID)"
    • changedInput schema / properties / payment_method / description
      Previous value: -"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Agentic Commerce Protocol / Stripe-native settlement) is NOT enabled by default: unless MCP_ACP_NATIVE_SETTLEMENT_ENABLED=true, a non-zero non-Shopify ACP cart returns an explicit 'not enabled' response instead of a mock completion. Defaults to MOCK if not specified."New value: +"Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Stripe-native settlement) returns a 'not enabled' response unless this deployment enables native settlement. MOCK moves no money: it completes the order without charging. Whether a store accepts it depends on the store's configuration (it is the default on demo-store). Defaults to MOCK if not specified."
    • addedOutput schema / properties / next_action
      Added value: +{
      +  "additionalProperties": true,
      +  "properties": {
      +    "actor": {
      +      "const": "buyer",
      +      "type": "string"
      +    },
      +    "do": {
      +      "enum": [
      +        "approve",
      +        "pay"
      +      ],
      +      "type": "string"
      +    },
      +    "instruction": {
      +      "type": "string"
      +    },
      +    "reuse_arguments": {
      +      "items": {
      +        "enum": [
      +          "checkout_session_id",
      +          "idempotency_key"
      +        ],
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    "then_call": {
      +      "const": "complete_checkout",
      +      "type": "string"
      +    },
      +    "url": {
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "actor",
      +    "do",
      +    "url",
      +    "instruction"
      +  ],
      +  "type": "object"
      +}
    • addedOutput schema / properties / order_placed
      Added value: +{
      +  "type": "boolean"
      +}
  9. Changed1 schema field changed
    • changedInput schema / properties / payment_mandate / description
      Previous value: -"Payment mandate with `mandate_id`, `max_amount_cents` (integer, minor units), `currency` (3 letters, must match the cart's), `exp` (expiry as an INTEGER of Unix seconds — not an ISO 8601 date string), `sub` (your agent id) and `aud` (the store slug this mandate is for, e.g. the slug in the URL you are calling — not a domain). Use this when your client cannot set an `X-Payment-Mandate` header."New value: +"Payment mandate with `mandate_id`, `max_amount_cents` (integer, minor units), `currency` (3 letters, must match the cart's), `exp` (expiry as an INTEGER of Unix seconds — not an ISO 8601 date string), `sub` (the identity you authenticate as — it is compared against it) and `aud` (the store slug this mandate is for, e.g. the slug in the URL you are calling — not a domain). It is a spending cap you declare to limit yourself: it authorises nothing and does not prove the buyer's consent. Use this when your client cannot set an `X-Payment-Mandate` header."
  10. Changed2 schema fields changed
    • addedOutput schema / properties / shipping_authoritative
      Added value: +{
      +  "type": "boolean"
      +}
    • addedOutput schema / properties / shipping_source
      Added value: +{
      +  "enum": [
      +    "platform",
      +    "merchant_policy",
      +    "estimated"
      +  ],
      +  "type": "string"
      +}
  11. Changed1 schema field changed
    • addedOutput schema / properties / approval_url
      Added value: +{
      +  "type": "string"
      +}
  12. Changed1 schema field changed
    • changedInput schema / properties / payment_mandate / description
      Previous value: -"Payment mandate with `mandate_id`, `max_amount_cents`, `currency`, `exp`, `sub`, `aud`. Its `currency` must match the cart's. Use this when your client cannot set an `X-Payment-Mandate` header."New value: +"Payment mandate with `mandate_id`, `max_amount_cents` (integer, minor units), `currency` (3 letters, must match the cart's), `exp` (expiry as an INTEGER of Unix seconds — not an ISO 8601 date string), `sub` (your agent id) and `aud` (the store slug this mandate is for, e.g. the slug in the URL you are calling — not a domain). Use this when your client cannot set an `X-Payment-Mandate` header."
  13. Changed2 schema fields changed
    • addedInput schema / properties / agent_key
      Added value: +{
      +  "description": "Sandbox credential from `create_sandbox_key`. Use this when your client cannot set an `Authorization: Bearer` header.",
      +  "type": "string"
      +}
    • addedInput schema / properties / payment_mandate
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": {},
      +      "type": "object"
      +    },
      +    {
      +      "type": "string"
      +    }
      +  ],
      +  "description": "Payment mandate with `mandate_id`, `max_amount_cents`, `currency`, `exp`, `sub`, `aud`. Its `currency` must match the cart's. Use this when your client cannot set an `X-Payment-Mandate` header."
      +}
  14. Changed4 schema fields changed
    • changedInput schema / additionalProperties
      Previous value: -falseNew value: +true
    • changedInput schema / properties / buyer / additionalProperties
      Previous value: -falseNew value: +true
    • changedInput schema / properties / cel_context / additionalProperties
      Previous value: -falseNew value: +true
    • changedOutput schema / additionalProperties
      Previous value: -falseNew value: +true
  15. Changed1 schema field changed
    • addedOutput schema / properties / payment_url
      Added value: +{
      +  "type": "string"
      +}
  16. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "$schema": "http://json-schema.org/draft-07/schema#",
      +  "additionalProperties": false,
      +  "properties": {
      +    "checkout_session_id": {
      +      "type": "string"
      +    },
      +    "currency": {
      +      "type": "string"
      +    },
      +    "external_order_id": {
      +      "type": "string"
      +    },
      +    "idempotent": {
      +      "type": "boolean"
      +    },
      +    "order_id": {
      +      "type": "string"
      +    },
      +    "status": {
      +      "enum": [
      +        "COMPLETED",
      +        "ALREADY_PLACED",
      +        "PENDING_EXTERNAL_CONFIRMATION"
      +      ],
      +      "type": "string"
      +    },
      +    "store_name": {
      +      "type": "string"
      +    },
      +    "total_cents": {
      +      "type": "number"
      +    }
      +  },
      +  "required": [
      +    "order_id",
      +    "checkout_session_id",
      +    "store_name",
      +    "total_cents",
      +    "currency",
      +    "status",
      +    "idempotent"
      +  ],
      +  "type": "object"
      +}
  17. Changed1 schema field changed
    • addedInput schema / properties / reconfirmed_state_hash
      Added value: +{
      +  "description": "SHA-256 of the authoritative merchant state, as returned in details.reconfirm_state_hash by a previous STATE_RECONFIRMATION_REQUIRED error. Required to proceed when the merchant state moved after the approved preview. Passing a stale hash is refused: it means the state moved again and must be reconfirmed anew.",
      +  "pattern": "^[0-9a-f]{64}$",
      +  "type": "string"
      +}
  18. Changed4 schema fields changed
    • addedInput schema / $schema
      Added value: +"http://json-schema.org/draft-07/schema#"
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties
      Added value: +{
      +  "buyer": {
      +    "additionalProperties": false,
      +    "description": "Optional buyer contact information",
      +    "properties": {
      +      "email": {
      +        "description": "Buyer email address",
      +        "format": "email",
      +        "type": "string"
      +      },
      +      "name": {
      +        "description": "Buyer full name",
      +        "type": "string"
      +      },
      +      "phone": {
      +        "description": "Buyer phone number",
      +        "type": "string"
      +      }
      +    },
      +    "type": "object"
      +  },
      +  "cel_context": {
      +    "additionalProperties": false,
      +    "description": "Optional enforcement context for Trusteed native MCP flows (no Shopify/WooCommerce/PrestaShop/Magento plugin). Providing these fields enables full evaluation of rules R004, R006, R008, R012-R013, R015-R017, R022, R026-R029. Fields are validated and signed — do not include values you cannot substantiate.",
      +    "properties": {
      +      "agent_provider_id": {
      +        "maxLength": 64,
      +        "minLength": 1,
      +        "pattern": "^[a-z0-9_\\-]+$",
      +        "type": "string"
      +      },
      +      "autorenew_consent": {
      +        "type": "boolean"
      +      },
      +      "cart_total_cents": {
      +        "maximum": 100000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "completed_orders": {
      +        "maximum": 1000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "completed_orders_24h": {
      +        "maximum": 1000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "cross_merchant_abuse": {
      +        "type": "boolean"
      +      },
      +      "digital_good_types": {
      +        "items": {
      +          "enum": [
      +            "gift_card",
      +            "license_key",
      +            "downloadable",
      +            "stored_value"
      +          ],
      +          "type": "string"
      +        },
      +        "maxItems": 10,
      +        "type": "array"
      +      },
      +      "discount_bps": {
      +        "maximum": 10000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "discount_codes_tried": {
      +        "maximum": 100,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "dispute_count": {
      +        "maximum": 1000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "is_b2b": {
      +        "type": "boolean"
      +      },
      +      "is_subscription": {
      +        "type": "boolean"
      +      },
      +      "item_count": {
      +        "maximum": 10000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "key_age_hours": {
      +        "maximum": 720,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "lowest_stock": {
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "merchant_avg_order_cents": {
      +        "maximum": 100000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "merchant_orders_1h": {
      +        "maximum": 1000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "payment_method": {
      +        "maxLength": 64,
      +        "minLength": 1,
      +        "type": "string"
      +      },
      +      "price_delta_bps": {
      +        "maximum": 10000,
      +        "minimum": -10000,
      +        "type": "integer"
      +      },
      +      "product_categories": {
      +        "items": {
      +          "maxLength": 64,
      +          "type": "string"
      +        },
      +        "maxItems": 50,
      +        "type": "array"
      +      },
      +      "provider_confidence": {
      +        "maximum": 1,
      +        "minimum": 0,
      +        "type": "number"
      +      },
      +      "purchase_order_hash": {
      +        "maxLength": 128,
      +        "type": "string"
      +      },
      +      "qty_per_sku_max": {
      +        "maximum": 10000,
      +        "minimum": 0,
      +        "type": "integer"
      +      },
      +      "refund_ratio": {
      +        "maximum": 1,
      +        "minimum": 0,
      +        "type": "number"
      +      },
      +      "regulated_evidence_present": {
      +        "type": "boolean"
      +      },
      +      "requested_scopes": {
      +        "items": {
      +          "maxLength": 64,
      +          "type": "string"
      +        },
      +        "maxItems": 20,
      +        "type": "array"
      +      },
      +      "return_policy_mismatch": {
      +        "type": "boolean"
      +      },
      +      "shipping_freight_forwarder": {
      +        "type": "boolean"
      +      },
      +      "shipping_po_box": {
      +        "type": "boolean"
      +      },
      +      "stored_value_cents": {
      +        "maximum": 100000000,
      +        "minimum": 0,
      +        "type": "integer"
      +      }
      +    },
      +    "type": "object"
      +  },
      +  "checkout_session_id": {
      +    "description": "Checkout session ID from preview_checkout (must be a valid UUID)",
      +    "type": "string"
      +  },
      +  "idempotency_key": {
      +    "description": "Unique key to prevent duplicate charges on retry. Generate once per purchase attempt. Replay is enforced primarily on checkout_session_id (the existing order is returned). The first key seen for a session is recorded; reusing the same key short-circuits to the existing order.",
      +    "type": "string"
      +  },
      +  "kyapay_token": {
      +    "description": "Skyfire pay or kya-pay JWT for autonomous payment via Skyfire (payment_method=KYAPAY). Alternative to passing the token in the skyfire-pay-id request header — the header takes precedence if both are provided. Claims required: sub, jti, amount (USD), cur=USD, sps.",
      +    "type": "string"
      +  },
      +  "payment_method": {
      +    "description": "Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. ACP (Agentic Commerce Protocol / Stripe-native settlement) is NOT enabled by default: unless MCP_ACP_NATIVE_SETTLEMENT_ENABLED=true, a non-zero non-Shopify ACP cart returns an explicit 'not enabled' response instead of a mock completion. Defaults to MOCK if not specified.",
      +    "enum": [
      +      "ACP",
      +      "KYAPAY",
      +      "PAYPAL",
      +      "MOCK"
      +    ],
      +    "type": "string"
      +  }
      +}
    • addedInput schema / required
      Added value: +[
      +  "checkout_session_id",
      +  "idempotency_key"
      +]
  19. Changed5 schema fields changed
    • removedInput schema / $schema
      Removed value: -"http://json-schema.org/draft-07/schema#"
    • removedInput schema / additionalProperties
      Removed value: -false
    • removedInput schema / properties
      Removed value: -{
      -  "buyer": {
      -    "additionalProperties": false,
      -    "description": "Optional buyer contact information",
      -    "properties": {
      -      "email": {
      -        "description": "Buyer email address",
      -        "format": "email",
      -        "type": "string"
      -      },
      -      "name": {
      -        "description": "Buyer full name",
      -        "type": "string"
      -      },
      -      "phone": {
      -        "description": "Buyer phone number",
      -        "type": "string"
      -      }
      -    },
      -    "type": "object"
      -  },
      -  "checkout_session_id": {
      -    "description": "Checkout session ID from preview_checkout (must be a valid UUID)",
      -    "type": "string"
      -  },
      -  "idempotency_key": {
      -    "description": "Unique key to prevent duplicate charges on retry. Generate once per purchase attempt.",
      -    "type": "string"
      -  },
      -  "kyapay_token": {
      -    "description": "Skyfire pay or kya-pay JWT for autonomous payment via Skyfire (payment_method=KYAPAY). Alternative to passing the token in the skyfire-pay-id request header — the header takes precedence if both are provided. Claims required: sub, jti, amount (USD), cur=USD, sps.",
      -    "type": "string"
      -  },
      -  "payment_method": {
      -    "description": "Payment method to use. PAYPAL creates a PayPal order and presents approval URL. KYAPAY requires kyapay_token. Defaults to MOCK if not specified.",
      -    "enum": [
      -      "ACP",
      -      "KYAPAY",
      -      "PAYPAL",
      -      "MOCK"
      -    ],
      -    "type": "string"
      -  }
      -}
    • removedInput schema / required
      Removed value: -[
      -  "checkout_session_id",
      -  "idempotency_key"
      -]
    • changedOutput schema / (root)
      Previous value: -{
      -  "$schema": "http://json-schema.org/draft-07/schema#",
      -  "additionalProperties": false,
      -  "properties": {
      -    "checkout_session_id": {
      -      "type": "string"
      -    },
      -    "currency": {
      -      "type": "string"
      -    },
      -    "external_order_id": {
      -      "type": "string"
      -    },
      -    "idempotent": {
      -      "type": "boolean"
      -    },
      -    "order_id": {
      -      "type": "string"
      -    },
      -    "status": {
      -      "enum": [
      -        "COMPLETED",
      -        "ALREADY_PLACED",
      -        "PENDING_EXTERNAL_CONFIRMATION"
      -      ],
      -      "type": "string"
      -    },
      -    "store_name": {
      -      "type": "string"
      -    },
      -    "total_cents": {
      -      "type": "number"
      -    }
      -  },
      -  "required": [
      -    "order_id",
      -    "checkout_session_id",
      -    "store_name",
      -    "total_cents",
      -    "currency",
      -    "status",
      -    "idempotent"
      -  ],
      -  "type": "object"
      -}New value: +null
  20. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: idempotency is explained as replay keyed on checkout_session_id returning the same order without re-charging, the PENDING_EXTERNAL_CONFIRMATION state is disambiguated ('no purchase has completed yet') along with how to read order_placed/next_action, and auth/token validation rules (Skyfire claims, mandate fields, header vs argument precedence) are disclosed. The readOnlyHint=false annotation is consistent with the described mutation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the action and the cart-card preference, and the all-caps section headers make the dense content scannable. It is long, though, and the PAYMENT MANDATE paragraph duplicates much of the payment_mandate schema description, so a few sentences do not fully earn their place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an 11-parameter, nested-schema, high-stakes mutation with an output schema, the description covers everything an agent needs: credentials, mandate, token, idempotency, and the multi-step approval outcome. Return-value structure is left to the output schema, so nothing critical is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3; the description adds real value on top by explaining payment_method semantics (which methods need a Skyfire token, that MOCK moves no money), mandate argument rules ('exp' is Unix seconds not ISO 8601, 'aud' is the store slug), and header precedence. It does not add much about the buyer.* or cel_context fields, which the schema already carries.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening sentence states a specific verb and resource ('Complete the purchase') and the description grounds it in the flow by identifying checkout_session_id as coming from preview_checkout/cart_id. It does not, however, distinguish this tool from the sibling ucp_complete_checkout, leaving the agent to infer which completion path applies in a UCP context.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit when-to-use and when-not-to-use rules: prefer the interactive cart card for confirmation and payment-method choice, only call this tool directly when no card exists or the buyer asks to finish in chat. Prerequisites are spelled out too — buyer.name/email must be collected first, a sandbox key is needed via create_sandbox_key, and a payment mandate is required.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources