Install
$ agentstack add skill-orcaqubits-agentic-commerce-skills-plugins-acp-checkout-mcp ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ACP Checkout — MCP Binding
Before writing code
Fetch live docs:
- Web-search
acp agentic commerce protocol MCP server implementationfor MCP binding guidance - Fetch
https://developers.openai.com/commerce/specs/checkout/for checkout operation semantics - Web-search
site:github.com agentic-commerce-protocol MCPfor any official MCP examples - Fetch MCP SDK docs: web-search
site:github.com modelcontextprotocol python-sdkortypescript-sdkfor current SDK
Conceptual Architecture
What MCP Binding Means
ACP's REST checkout operations can be exposed as MCP tools via an MCP server. This allows AI agents that use tool-calling (Claude, ChatGPT, Gemini) to invoke checkout operations directly as tools rather than making raw HTTP calls.
Mapping REST to MCP Tools
Each REST checkout operation becomes an MCP tool:
| REST Operation | MCP Tool Name | Description | |---------------|---------------|-------------| | POST /checkoutsessions | create_checkout_session | Create a new checkout session with items | | POST /checkoutsessions/{id} | update_checkout_session | Update session (items, address, fulfillment) | | GET /checkoutsessions/{id} | get_checkout_session | Retrieve current session state | | POST /checkoutsessions/{id}/complete | complete_checkout_session | Submit payment to finalize | | POST /checkout_sessions/{id}/cancel | cancel_checkout_session | Cancel the session |
Tool Input Schemas
Each MCP tool accepts JSON input matching the corresponding REST request body. The tool's inputSchema should be derived from the ACP OpenAPI spec's request schemas.
Tool Output
Each tool returns the CheckoutSession object (or error) as JSON, matching the REST response body.
MCP Server Architecture
AI Agent (Claude/ChatGPT)
↓ tool call (JSON-RPC)
MCP Server (your code)
↓ business logic
Checkout Service (same logic as REST)
↓ payment
PSP (Stripe)
The MCP server wraps the same business logic that the REST endpoints use. The checkout service layer should be shared between REST and MCP bindings.
Key Considerations
- Idempotency — MCP doesn't have HTTP headers, so pass
idempotency_keyas a tool parameter - API versioning — Include
api_versionas a tool parameter or server configuration - Authentication — MCP transport handles auth (stdio for local, SSE/streamable-HTTP for remote)
- Error handling — Return ACP error objects as tool errors with the same
type/code/messagestructure - Statelessness — Each tool call should be stateless; session state lives in the CheckoutSession object
Use Cases
- AI agents that prefer tool-calling over raw HTTP
- Claude Desktop / Claude Code integrations
- Multi-agent architectures where commerce is one capability
- Rapid prototyping without building a full REST server
Best Practices
- Share the checkout business logic layer between REST and MCP bindings
- Derive tool input schemas from the ACP OpenAPI spec (don't hand-write them)
- Include descriptive tool descriptions so the agent understands when to use each tool
- Test with the MCP Inspector before connecting to an agent
Fetch the latest ACP OpenAPI spec and MCP SDK documentation for exact schemas and server setup before implementing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: OrcaQubits
- Source: OrcaQubits/agentic-commerce-skills-plugins
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.