Agentic Shelf
Hosted MCP for e-commerce: live product catalog, stock, and pricing for AI agents.
Executive verdict
trustsnap_f10dc36c3f965145- Machine trust evaluator activity
- Possible agent/script activity
- profile / compare inspection
Current trust snapshot
trustsnap_f10dc36c3f965145Canonical machine links
Own this MCP?
Claim ownership, prove control with a GitHub, DNS, HTTP, MCP metadata, or email-domain challenge, revalidate now, publish a badge, configure monitoring, and unlock a verified server profile.
POST /v1/servers/ai.agenticshelf/mcp/revalidateBadge embed
[](https://verify.sentinelsignal.io/servers/ai.agenticshelf/mcp)
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Production readiness class
Evidence confidence
Recommended for
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Warningstep_up_auth_probe• Missingconnector_replay_probe• Missing — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Warning
Evidence provenance
action_safety_probe• Error
Evidence provenance
tool_snapshot_probe• Missingconnector_replay_probe• Missing
Why compatibility is limited by client
Remediation checklist
OpenAI connectors expect OAuth for remote server auth.Dynamic client registration materially improves connector setup.search fetch only is not yet satisfiedoauth configured is not yet satisfiedadmin refresh required is not yet satisfiedsafe for company knowledge is not yet satisfied
Remediation checklist
search fetch only is not yet satisfiedoauth configured is not yet satisfiedadmin refresh required is not yet satisfiedsafe for company knowledge is not yet satisfiedsafe for messages api remote mcp is not yet satisfiedTransport compliance issues should be resolved before wider client rollout.
Remediation checklist
Add a clearer auth boundary around risky write actions.Add confirmation or dry-run semantics for risky actions.Constrain or sandbox exec-capable tools before publishing broadly.
Verdict traces
- No active alert triggers.
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Partially client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Degraded
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewPublic server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Jul 31, 2026 05:31:35 AM UTC | Latest validation: healthy | Score 70.2 with status healthy. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://www.agenticshelf.ai
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://api.agenticshelf.ai/mcp
- Server card: none
Security posture
Agent Commerce & Payment Readiness - Beta
Beta assessment. Verify separates commerce-adjacent context from observed payment execution. Usage, billing, pricing, card, wallet, or meter terms alone do not make a server payment-capable. This is not a certification of safety, compliance, or fraud prevention.
Warnings
- This server appears to expose payment-execution tools without observed authentication. Treat as high risk.
Evidence
| Field | Value | Source | Matched terms | Confidence |
|---|---|---|---|---|
| commerce_signal | strong | tool_schema | charge, checkout, order, limit, currency, price, pricing, quote | high |
Recommended operator fixes
- Require OAuth or equivalent auth for protected tools.
- Separate quote/cart tools from charge/settlement tools.
- Require explicit user confirmation for payment execution.
- Return amount, currency, merchant, and receipt identifiers.
- Publish pricing and refund/cancellation policy.
- Add operator identity metadata.
- Add spending policy support or mandate constraints.
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes |
|---|---|---|---|---|
check_stock |
read write network admin | Medium | admin mutation | No explicit safeguard hints detected. |
get_product_details |
read network | Medium | none | No explicit safeguard hints detected. |
get_price |
read admin | Medium | none | No explicit safeguard hints detected. |
list_products |
read write network export | Medium | bulk data access | Safeguards hinted in metadata. |
search_products |
read write exec network export | High | command execution bulk data access freeform input surface | No explicit safeguard hints detected. |
add_to_cart |
read write network | Medium | none | No explicit safeguard hints detected. |
create_checkout |
read write network | Medium | none | No explicit safeguard hints detected. |
Write-action governance
Status detail: 1 high-risk tool(s), 1 exec-capable tool(s) are exposed without a clear auth boundary; 1 safeguard(s) and 0 confirmation signal(s) detected.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
search_products |
High | command execution bulk data access freeform input surface | no |
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
| No newly added actions. | ||
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Why this score?
Algorithmic score breakdown
Compatibility profiles
Connector URL: https://api.agenticshelf.ai/mcp # No OAuth metadata detected. # Server: ai.agenticshelf/mcp
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": ["mcp-remote", "https://api.agenticshelf.ai/mcp"]
}
}
}
smithery mcp add "https://api.agenticshelf.ai/mcp"
curl -sS https://api.agenticshelf.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| High | Add confirmation and dry-run semantics for risky actions | High-risk write, delete, exec, or egress tools should communicate safeguards clearly. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Associate roots, sampling, and elicitation with active client requests | Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Keep connector refreshes backward compatible | Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Reduce tool-surface churn | Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Support resumable HTTP sessions cleanly | Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Recovery Semantics | 0/4 | -4.0 |
| Error Contract | 0/4 | -4.0 |
| Trust Confidence | 1.8/4 | -2.2 |
| Utility Coverage | 2/4 | -2.0 |
| Transport Compliance | 2/4 | -2.0 |
| Spec Recency | 2/4 | -2.0 |
| Schema Completeness | 2/4 | -2.0 |
| Resource Contract | 2/4 | -2.0 |
| Registry Consistency | 2/4 | -2.0 |
| Rate Limit Semantics | 2/4 | -2.0 |
| Prompt Contract | 2/4 | -2.0 |
| Least Privilege Scope | 2/4 | -2.0 |
Validation diff
Need at least two validation runs before diffing changes.
Tool snapshot diff & changelog
Need at least two validation runs before building a tool changelog.
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Transport compliance drilldown
Issues: missing_session_id, missing_protocol_header
Request association
Utility coverage
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Likely to fail |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | Agentic Shelf — Live Inventory |
| Version | n/a | 0.1.0 |
| Homepage | n/a | n/a |
Active alerts
No active alerts for the current server state.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
ai.agenticshelf/mcp |
official_registry | yes | 70.2 |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Install snippets
Connector URL: https://api.agenticshelf.ai/mcp # No OAuth metadata detected. # Server: ai.agenticshelf/mcp
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": ["mcp-remote", "https://api.agenticshelf.ai/mcp"]
}
}
}
smithery mcp add "https://api.agenticshelf.ai/mcp"
curl -sS https://api.agenticshelf.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.ai.agenticshelf/mcp.Claims & monitoring
No verified maintainer claim recorded.
Alert routing
| Watch | Team | Channels | Minimum severity |
|---|---|---|---|
| No active watch destinations. | |||
Maintainer analytics
Maintainer response quality
Maintainer annotations
No maintainer annotations have been recorded yet.
Maintainer rebuttals & expected behavior
No maintainer rebuttals or expected-behavior overrides are recorded yet.
Latest validation evidence
Failures
oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://api.agenticshelf.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization server
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Error | n/a | 1 high-risk, 1 exec-capable tool(s); no clear auth boundary; safeguards=1; confirmation=none. |
advanced_capabilities_probe |
Warning | n/a | Only 3 capability signal(s): prompts, resources, structured outputs. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: action safety. |
connector_replay_probe |
Missing | n/a | No connector replay evidence recorded. |
determinism_probe |
OK | 54.0 ms | Check completed |
initialize |
OK | 93.3 ms | Protocol 2025-03-26 |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 42.8 ms | Client error '404 Not Found' for url 'https://api.agenticshelf.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
OK | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 52.8 ms | Fetched https://api.agenticshelf.ai/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
OK | 48.7 ms | 0 prompt(s) exposed |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
OK | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
OK | 60.6 ms | 0 resource item(s) exposed |
server_card |
OK | 86.5 ms | authentication, capabilities, schema_version, serverInfo |
session_resume_probe |
Warning | n/a | no session id |
step_up_auth_probe |
Missing | n/a | No OAuth or incremental-scope signals detected. |
tool_snapshot_probe |
Missing | n/a | no historical snapshot |
tools_list |
OK | 59.7 ms | 7 tool(s) exposed |
transport_compliance_probe |
Warning | 46.1 ms | Issues: missing session id, missing protocol header (bad protocol=400). |
utility_coverage_probe |
Missing | 49.6 ms | No completions evidence; no pagination evidence; tasks missing. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": false,
"confirmation_signals": [],
"safeguard_count": 1,
"summary": {
"bulk_access_tools": 2,
"capability_distribution": {
"admin": 2,
"exec": 1,
"export": 2,
"network": 6,
"read": 7,
"write": 5
},
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 1,
"high_risk_tools": 1,
"risk_distribution": {
"critical": 0,
"high": 1,
"low": 0,
"medium": 6
},
"secret_tools": 0,
"tool_count": 7
}
},
"latency_ms": null,
"status": "error"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": true,
"resource_links": false,
"resources": true,
"roots": false,
"sampling": false,
"structured_outputs": true
},
"enabled": [
"prompts",
"resources",
"structured_outputs"
],
"enabled_count": 3,
"initialize_capability_keys": [
"experimental",
"prompts",
"resources",
"tools"
]
},
"latency_ms": null,
"status": "warning"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"action_safety"
],
"criteria": {
"action_safety": false,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": true,
"remote_transport": true,
"request_association": true,
"server_card": true,
"session_resume": true,
"step_up_auth": true,
"tool_surface": true,
"tools_list": true,
"transport_compliance": true
},
"high_risk_tools": 1,
"tool_count": 7,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"connector_replay_probe": {
"details": {
"reason": "no_historical_snapshot"
},
"latency_ms": null,
"status": "missing"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "1930dc6dbdaba741ffb5d8471558f763c50f3773cfc33beb7088a84481882331",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 54.0,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"experimental": {},
"prompts": {
"listChanged": false
},
"resources": {
"listChanged": false,
"subscribe": false
},
"tools": {
"listChanged": false
}
},
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "AgenticShelf-Inventory",
"version": "1.28.1"
}
}
},
"url": "https://api.agenticshelf.ai/mcp"
},
"latency_ms": 93.34,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": [
"oauth",
"browser"
]
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://api.agenticshelf.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.agenticshelf.ai/.well-known/oauth-protected-resource"
},
"latency_ms": 42.76,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": true,
"official_peer_count": 1,
"registry_identifier": "ai.agenticshelf/mcp",
"registry_source": "official_registry"
},
"latency_ms": null,
"status": "ok"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 404,
"url": "https://api.agenticshelf.ai/robots.txt"
},
"latency_ms": 52.78,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 3,
"jsonrpc": "2.0",
"result": {
"prompts": []
}
},
"url": "https://api.agenticshelf.ai/mcp"
},
"latency_ms": 48.68,
"status": "ok"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"direct_official_match": true,
"drift_fields": [],
"metadata_document_count": 3,
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": "Agentic Shelf \u2014 Live Inventory",
"server_card_version": "0.1.0"
},
"latency_ms": null,
"status": "ok"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 5,
"jsonrpc": "2.0",
"result": {
"resources": []
}
},
"url": "https://api.agenticshelf.ai/mcp"
},
"latency_ms": 60.57,
"status": "ok"
},
"server_card": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"authentication": {
"description": "Anonymous tools/list works for discovery. Authenticated tool calls require an Authorization: Bearer <Firebase ID token> header \u2014 tokens are issued via the merchant console at agenticshelf.ai/console after a customer signs in with Google and OAuth-connects their Shopify store.",
"required": false,
"scheme": "firebase-id-token",
"tokenSource": "https://www.agenticshelf.ai/console",
"type": "bearer"
},
"capabilities": {
"tools": [
{
"description": "Real-time inventory, price, and shipping availability for a product SKU. Returns stock count, price in USD, can_ship_today flag.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "check_stock"
},
{
"description": "Full product metadata: title, description, image URL, tags, inventory quantity. Optimized for AI agents.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "get_product_details"
},
{
"description": "Current price in USD for a product SKU.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "get_price"
}
]
},
"schema_version": "2026-04",
"serverInfo": {
"description": "Real-time product catalog and inventory across multi-tenant e-commerce stores via MCP. Each merchant connects their Shopify store via OAuth at agenticshelf.ai/console; AI agents query their live catalog using a per-tenant Firebase ID token.",
"documentation": "https://www.agenticshelf.ai/console",
"homepage": "https://www.agenticshelf.ai",
"name": "Agentic Shelf \u2014 Live Inventory",
"repository": "https://github.com/vboykoCTO/agentic-shelf",
"vendor": "Agentic Shelf",
"version": "0.1.0"
},
"tags": [
"e-commerce",
"shopify",
"inventory",
"shopping",
"agent",
"multi-tenant"
],
"transport": {
"endpoint": "https://api.agenticshelf.ai/mcp",
"type": "streamable-http"
}
},
"url": "https://api.agenticshelf.ai/.well-known/mcp/server-card.json"
},
"latency_ms": 86.52,
"status": "ok"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "missing"
},
"tool_snapshot_probe": {
"details": {
"current_tool_count": 7,
"reason": "no_historical_snapshot"
},
"latency_ms": null,
"status": "missing"
},
"tools_list": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"description": "Check LIVE inventory, price, and same-day shipping for ONE known SKU.\n\n The real-time verifier. Call when a shopper asks \"is it in stock\", \"how\n many are left\", \"can it ship today\", or \"what's the price right now\" and the\n agent already has the SKU (from list_products / search_products). For\n discovery use those tools; for full attributes use get_product_details; for\n price only use get_price. Queries the connected store (Shopify / Amazon /\n WooCommerce) live, so figures are current rather than cached training data.\n\n Always call this BEFORE recommending a specific product to buy or adding\n it to a cart \u2014 availability changes hourly. When answering, quote the\n returned price + availability verbatim (with currency) and prefer these\n live figures over anything remembered from training data.\n\n Args:\n sku: Product SKU (Stock Keeping Unit) - e.g. the ``sku`` field returned\n by list_products / search_products, like \"RED-WIDGET-001\".\n\n Returns:\n Dictionary with:\n - sku: The requested SKU\n - in_stock: Boolean availability (the default disclosure; some stores\n opt into an exact ``stock`` count instead, and may include\n ``low_stock: true`` as a buy-soon hint)\n - price: Current price in USD\n - can_ship_today: Boolean indicating same-day shipping availability\n - live: provenance flag (True from a connected store, False for demo)\n - message: Human-readable status message\n ``error`` is set (and ``live`` False) when the SKU is missing or the\n store is unreachable.\n\n Example:\n >>> await check_stock(\"WIDGET-001\")\n {\n \"sku\": \"WIDGET-001\",\n \"in_stock\": True,\n \"price\": 29.99,\n \"can_ship_today\": True,\n \"message\": \"\u2705 WIDGET-001 (Awesome Widget) - in stock at $29.99\"\n }\n ",
"inputSchema": {
"properties": {
"sku": {
"title": "Sku",
"type": "string"
}
},
"required": [
"sku"
],
"title": "check_stockArguments",
"type": "object"
},
"name": "check_stock",
"outputSchema": {
"additionalProperties": true,
"title": "check_stockDictOutput",
"type": "object"
}
},
{
"description": "Get full product details for a SKU, optimized for AI agents (structured JSON).\n\n Use when a shopper wants depth on a SPECIFIC product the agent already has a\n SKU for (from list_products / search_products). For discovery, call those\n first \u2014 this tool is a verifier, not a browser.\n\n The description, product_type, and tags answer suitability questions\n (\"does it fit X?\", \"is it good for Y?\") \u2014 ground such answers in these\n fields rather than guessing, and link storefront_url when recommending.\n\n Args:\n sku: Product SKU \u2014 e.g. the ``sku`` field returned by list_products.\n\n Returns:\n Catalog dict (title, description, product_type, tags, price,\n in_stock, available, image_url); ``found`` is False when the\n SKU is missing. (Stores that opt into exact disclosure return an\n ``inventory_quantity`` count instead of ``in_stock``.)\n ",
"inputSchema": {
"properties": {
"sku": {
"title": "Sku",
"type": "string"
}
},
"required": [
"sku"
],
"title": "get_product_detailsArguments",
"type": "object"
},
"name": "get_product_details",
"outputSchema": {
"additionalProperties": true,
"title": "get_product_detailsDictOutput",
"type": "object"
}
},
{
"description": "Get the current price (and currency) for a product SKU.\n\n Returns price + currency ONLY \u2014 for stock/shipping use check_stock, for full\n details use get_product_details. Use when a shopper asks \"how much is X\" and\n the agent already has the SKU (from list_products / search_products).\n\n The figure is the store's CURRENT selling price (sales included) \u2014 always\n prefer it over prices remembered from training data or third-party sites,\n and quote it with its currency.\n\n Args:\n sku: Product SKU \u2014 e.g. the ``sku`` field returned by list_products.\n\n Returns:\n ``{\"sku\", \"price\", \"currency\", \"live\"}``; price 0.0 with an ``error``\n when the SKU isn't found.\n\n Example:\n >>> await get_price(\"WIDGET-001\")\n {\"sku\": \"WIDGET-001\", \"price\": 29.99, \"currency\": \"USD\"}\n ",
"inputSchema": {
"properties": {
"sku": {
"title": "Sku",
"type": "string"
}
},
"required": [
"sku"
],
"title": "get_priceArguments",
"type": "object"
},
"name": "get_price",
"outputSchema": {
"additionalProperties": true,
"title": "get_priceDictOutput",
"type": "object"
}
},
{
"description": "List products from the connected store, paginated.\n\n Use this tool when an agent needs to DISCOVER products by browsing the\n catalog rather than VERIFYING a known SKU. The response includes the SKU\n for every product, so a follow-up ``check_stock(sku)`` or\n ``get_product_details(sku)`` is a natural next step. When the shopper's\n request contains matchable terms (\"HEPA purifier\", \"dark roast\"), prefer\n search_products \u2014 it needs fewer pages to find the right item. Only\n sellable products are returned (drafts/archived are excluded).\n\n Recommended flow: search_products/list_products -> get_product_details\n -> check_stock -> add_to_cart/create_checkout.\n\n Args:\n limit: Number of products to return (1-50, default 10).\n cursor: Opaque cursor from a previous response's ``next_cursor``.\n Omit for the first page.\n\n Returns:\n Dictionary with:\n - products: list of {sku, title, description (\u2264400 chars),\n product_type, tags, price, currency, available, image_url,\n storefront_url}\n - next_cursor: str or null \u2014 pass to the next call to paginate\n - has_more: bool \u2014 whether more products exist\n - live / source: provenance flags\n ",
"inputSchema": {
"properties": {
"cursor": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"title": "Cursor"
},
"limit": {
"default": 10,
"title": "Limit",
"type": "integer"
}
},
"title": "list_productsArguments",
"type": "object"
},
"name": "list_products",
"outputSchema": {
"additionalProperties": true,
"title": "list_productsDictOutput",
"type": "object"
}
},
{
"description": "Search products in the connected store by keyword.\n\n Use this when a shopper's query suggests specific terms the agent can\n match against product titles or tags \u2014 e.g. \"HEPA air purifier\" or\n \"leather wristwatch\". Matches Shopify's native storefront search\n behavior, so results align with what customers would find on the site.\n\n Search with the fewest distinctive words (product nouns, not full\n sentences). If a search returns nothing, retry with a broader term or\n fall back to list_products and scan titles. Only sellable products are\n returned (drafts/archived are excluded).\n\n Recommended flow: search_products -> get_product_details -> check_stock\n -> add_to_cart/create_checkout.\n\n Args:\n query: Keyword or phrase to match.\n limit: Max products to return (1-50, default 10).\n\n Returns:\n Same shape as ``list_products``. Empty products list when no matches.\n ",
"inputSchema": {
"properties": {
"limit": {
"default": 10,
"title": "Limit",
"type": "integer"
},
"query": {
"title": "Query",
"type": "string"
}
},
"required": [
"query"
],
"title": "search_productsArguments",
"type": "object"
},
"name": "search_products",
"outputSchema": {
"additionalProperties": true,
"title": "search_productsDictOutput",
"type": "object"
}
},
{
"description": "Add a product to a cart and return its checkout URL.\n\n IMPORTANT: this does NOT charge or place an order. It returns a ``cart_url``\n /``checkout_url`` the shopper opens to review the pre-filled cart and pay\n themselves. Use for \"add X to my cart\" / \"I want to buy X\". For multiple\n items in one cart, use create_checkout. Verify availability with\n check_stock first \u2014 adding an out-of-stock item wastes the shopper's\n click-through.\n\n Args:\n sku: Product SKU (from list_products / search_products).\n quantity: How many (default 1).\n ",
"inputSchema": {
"properties": {
"quantity": {
"default": 1,
"title": "Quantity",
"type": "integer"
},
"sku": {
"title": "Sku",
"type": "string"
}
},
"required": [
"sku"
],
"title": "add_to_cartArguments",
"type": "object"
},
"name": "add_to_cart",
"outputSchema": {
"additionalProperties": true,
"title": "add_to_cartDictOutput",
"type": "object"
}
},
{
"description": "Build a multi-item cart and return its checkout URL.\n\n IMPORTANT: this does NOT charge or place an order \u2014 it returns a\n ``checkout_url`` the shopper opens to pay. Use to assemble a basket the\n shopper asked for.\n\n Args:\n items: list of ``{\"sku\": str, \"quantity\": int}`` (quantity defaults 1).\n ",
"inputSchema": {
"properties": {
"items": {
"items": {
"additionalProperties": true,
"type": "object"
},
"title": "Items",
"type": "array"
}
},
"required": [
"items"
],
"title": "create_checkoutArguments",
"type": "object"
},
"name": "create_checkout",
"outputSchema": {
"additionalProperties": true,
"title": "create_checkoutDictOutput",
"type": "object"
}
}
]
}
},
"url": "https://api.agenticshelf.ai/mcp"
},
"latency_ms": 59.69,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=63072000"
},
"bad_protocol_payload": {
"error": {
"code": -32600,
"message": "Bad Request: Unsupported protocol version: 1999-99-99. Supported versions: 2024-11-05, 2025-03-26, 2025-06-18, 2025-11-25"
},
"id": "server-error",
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 400,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 46.07,
"status": "warning"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"experimental",
"prompts",
"resources",
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 200,
"probe_status": "missing"
}
},
"latency_ms": 49.57,
"status": "missing"
}
},
"failures": {
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://api.agenticshelf.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://api.agenticshelf.ai/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
}
},
"remote_url": "https://api.agenticshelf.ai/mcp",
"server_card_payload": {
"authentication": {
"description": "Anonymous tools/list works for discovery. Authenticated tool calls require an Authorization: Bearer <Firebase ID token> header \u2014 tokens are issued via the merchant console at agenticshelf.ai/console after a customer signs in with Google and OAuth-connects their Shopify store.",
"required": false,
"scheme": "firebase-id-token",
"tokenSource": "https://www.agenticshelf.ai/console",
"type": "bearer"
},
"capabilities": {
"tools": [
{
"description": "Real-time inventory, price, and shipping availability for a product SKU. Returns stock count, price in USD, can_ship_today flag.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "check_stock"
},
{
"description": "Full product metadata: title, description, image URL, tags, inventory quantity. Optimized for AI agents.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "get_product_details"
},
{
"description": "Current price in USD for a product SKU.",
"inputSchema": {
"properties": {
"sku": {
"description": "Product SKU",
"type": "string"
}
},
"required": [
"sku"
],
"type": "object"
},
"name": "get_price"
}
]
},
"schema_version": "2026-04",
"serverInfo": {
"description": "Real-time product catalog and inventory across multi-tenant e-commerce stores via MCP. Each merchant connects their Shopify store via OAuth at agenticshelf.ai/console; AI agents query their live catalog using a per-tenant Firebase ID token.",
"documentation": "https://www.agenticshelf.ai/console",
"homepage": "https://www.agenticshelf.ai",
"name": "Agentic Shelf \u2014 Live Inventory",
"repository": "https://github.com/vboykoCTO/agentic-shelf",
"vendor": "Agentic Shelf",
"version": "0.1.0"
},
"tags": [
"e-commerce",
"shopify",
"inventory",
"shopping",
"agent",
"multi-tenant"
],
"transport": {
"endpoint": "https://api.agenticshelf.ai/mcp",
"type": "streamable-http"
}
},
"server_identifier": "ai.agenticshelf/mcp"
}
Known versions
1.0.0
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Jul 31, 2026 05:31:35 AM UTC | Healthy | 70.2 | 657.2 ms | 7 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Jul 31, 2026 05:31:35 AM UTC | Healthy | 70.2 | 2025-03-26 | public | 7 | 1 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Jul 31, 2026 05:31:35 AM UTC | Completed | Healthy | 657.2 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |