Install
npm install @paypal/agent-toolkitTry itExperimental
See what an agent can do with PayPal Agentic Commerce before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server PayPal documents for agentsrecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agent checkout — stories about agent checkout in this arenaAgent checkoutevidence →
Stories about agent checkout in this arena
Agent discovery — stories about agent discovery in this arenaAgent discoveryevidence →
Stories about agent discovery in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Fees economics — stories about fees economics in this arenaFees economicsevidence →
Stories about fees economics in this arena
Merchant enablement — stories about merchant enablement in this arenaMerchant enablementevidence →
Stories about merchant enablement in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Order lifecycle — stories about order lifecycle in this arenaOrder lifecycleevidence →
Stories about order lifecycle in this arena
Payment credentials — stories about payment credentials in this arenaPayment credentialsevidence →
Stories about payment credentials in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Protocol openness — stories about protocol openness in this arenaProtocol opennessevidence →
Stories about protocol openness in this arena
Refunds disputes — stories about refunds disputes in this arenaRefunds disputesevidence →
Stories about refunds disputes in this arena
Trust safety — stories about trust safety in this arenaTrust safetyevidence →
Stories about trust safety in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 0 free · 1 paid · 0 enterprise · 26 not stated in evidence
Follow the green: where the map greys out is where PayPal Agentic Commerce stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent checkout — stories about agent checkout in this arenaAgent checkout
Stories about agent checkout in this arena
My agent can create and update a cart or order draft through a documented protocol call
✓8/10
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
~6/10
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
~6/10
Build against a versioned commerce protocol with a published schema and conformance or validation tooling
~4/10
Agent discovery — stories about agent discovery in this arenaAgent discovery
Stories about agent discovery in this arena
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
!3/10
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
~5/10
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell
~6/10
My agent can discover payable services and APIs through a published directory or discovery index
~5/10
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓9/10
unlocks → Machine-readable spec · Versioning policy · Official CLI · My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
Subscribe to events via webhooks
✓7/10
Build against official SDKs
✓8/10
Issue scoped/least-privilege API credentials for an agent
~4/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
✓8/10
Explore an interactive API reference with runnable examples
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—–
Operate the product with natural-language commands
~6/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
~6/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Fees economics — stories about fees economics in this arenaFees economics
Stories about fees economics in this arena
Merchant enablement — stories about merchant enablement in this arenaMerchant enablement
Stories about merchant enablement in this arena
Orders are attributed to the originating agent and I can report on or filter transactions by agent
—0/10
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
~5/10
Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout
—0/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle
Stories about order lifecycle in this arena
Payment credentials — stories about payment credentials in this arenaPayment credentials
Stories about payment credentials in this arena
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
~6/10
Monetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI
—–
Settle agent-initiated payments in stablecoins over documented rails
—0/10
Provision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility
—–
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Protocol openness — stories about protocol openness in this arenaProtocol openness
Stories about protocol openness in this arena
Refunds disputes — stories about refunds disputes in this arenaRefunds disputes
Stories about refunds disputes in this arena
Trust safety — stories about trust safety in this arenaTrust safety
Stories about trust safety in this arena
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots
—0/10
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
~5/10
The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk
—0/10
Set per-agent spend caps and usage limits and revoke an agent's payment authority instantly
—0/10
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed⚿ | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed⚿ | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed⚿ | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed⚿ | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed⚿ | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed⚿ | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed⚿ | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed⚿ | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | full | 8/10 | Cclaimed | |
My agent can create and update a cart or order draft through a documented protocol call C Cart | ai-native user | Agent checkout — stories about agent checkout in this arenaAgent checkout | 3 | full | 8/10 | Cclaimed | |
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number C Delegated credentials | ai-native user | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | partial | 6/10 | Cclaimed | |
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order C Checkout | ai-native user | Agent checkout — stories about agent checkout in this arenaAgent checkout | 3 | partial | 6/10 | Tprobed⚿ | |
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell C Merchant feeds | merchant | Agent discovery — stories about agent discovery in this arenaAgent discovery | 3 | partial | 6/10 | Cclaimed | |
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint C Onboarding to agents | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 3 | partial | 5/10 | Cclaimed | |
My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmatically C Order events | developer | Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle | 3 | partial | 5/10 | Cclaimed | |
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves C Human oversight | ai-native user | Trust safety — stories about trust safety in this arenaTrust safety | 3 | partial | 5/10 | Cclaimed | |
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required C Agent search | ai-native user | Agent discovery — stories about agent discovery in this arenaAgent discovery | 3 | disputed | 3/10 | Dcontradicted⚿ | |
Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots C Agent identity | merchant | Trust safety — stories about trust safety in this arenaTrust safety | 3 | none | 0/10 | ⚿ | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | 0/10 | ||
The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything C Spec publication | developer | Protocol openness — stories about protocol openness in this arenaProtocol openness | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Monetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI C Machine payments | developer | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Provision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility C Wallets | ai-native user | Payment credentials — stories about payment credentials in this arenaPayment credentials | 3 | none | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers) C Embedded surfaces | merchant | Agent checkout — stories about agent checkout in this arenaAgent checkout | 2 | partial | 6/10 | Tprobed⚿ | |
Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes C Disputes | developer | Refunds disputes — stories about refunds disputes in this arenaRefunds disputes | 2 | partial | 6/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Cclaimed | |
My agent can query the status and tracking of an order it placed, after the purchase C Post purchase status | ai-native user | Order lifecycle — stories about order lifecycle in this arenaOrder lifecycle | 2 | partial | 6/10 | Tprobed | |
Refunds on agent-placed orders can be initiated and tracked programmatically C Refunds | developer | Refunds disputes — stories about refunds disputes in this arenaRefunds disputes | 2 | partial | 6/10 | Tprobed | |
My agent can discover payable services and APIs through a published directory or discovery index C Service discovery | ai-native user | Agent discovery — stories about agent discovery in this arenaAgent discovery | 2 | partial | 5/10 | Tprobed⚿ | |
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service C Machine readable offers | developer | Agent discovery — stories about agent discovery in this arenaAgent discovery | 2 | partial | 5/10 | Cclaimed | |
The fees for agent-originated transactions are published — I can price agentic channels without asking sales C Fees transparency | merchant | Fees economics — stories about fees economics in this arenaFees economics | 2 | partialpaid | 5/10 | Cclaimed | |
Build against a versioned commerce protocol with a published schema and conformance or validation tooling C Protocol conformance | developer | Agent checkout — stories about agent checkout in this arenaAgent checkout | 2 | partial | 4/10 | Cclaimed | |
At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration C Ecosystem adoption | developer | Protocol openness — stories about protocol openness in this arenaProtocol openness | 2 | none | 0/10 | ||
Orders are attributed to the originating agent and I can report on or filter transactions by agent C Attribution analytics | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout C Traffic controls | merchant | Merchant enablement — stories about merchant enablement in this arenaMerchant enablement | 2 | none | 0/10 | ||
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Set per-agent spend caps and usage limits and revoke an agent's payment authority instantly G Spend controls | ai-native user | Trust safety — stories about trust safety in this arenaTrust safety | 2 | none | 0/10 | ||
Settle agent-initiated payments in stablecoins over documented rails C Settlement rails | developer | Payment credentials — stories about payment credentials in this arenaPayment credentials | 2 | none | 0/10 | ||
The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk C Liability | merchant | Trust safety — stories about trust safety in this arenaTrust safety | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel C Payouts | merchant | Fees economics — stories about fees economics in this arenaFees economics | 1 | partial | 6/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 42 stories with headroom
What would move PayPal Agentic Commerce’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
The evidence pack is entirely about PayPal enabling external AI agents (ChatGPT, Gemini, third-party MCP clients, or developer-built agents via the Agent Toolkit) to transact through PayPal/Braintree — it is infrastructure for other assistants to use PayPal, not a built-in AI assistant inside PayPal's own product that an end user delegates tasks to.
Trust safety — stories about trust safety in this arenaAgents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots
nonemoves PA Scoreimpact 30
PayPal's docs describe payment-token authentication (Braintree single-use tokens bound to merchant ID), PayPal-issued JWTs for verifying that requests come from PayPal's own Shopping Cart service, and webhook signature verification — but none of this constitutes a verifiable agent identity system (no registered agent profiles, agent-level signatures, or trust tiers that would let a merchant distinguish which specific AI agent or bot is originating traffic).
Payment credentials — stories about payment credentials in this arenaProvision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility
nonemoves PA Scoreimpact 30
All evidence describes merchant-side infrastructure (Agent Ready, Store Sync, agent toolkit, cart APIs) that lets AI agents check out with merchants or lets merchants build agents for order/refund/dispute management — none of it describes a consumer-provisioned wallet that a user funds, an agent holds/spends from, with balance visibility.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
Missing: any rule-builder/automation-trigger UI or API, conditional logic definition, and evidence of automatic action execution tied to rules rather than manual webhook handling.
Payment credentials — stories about payment credentials in this arenaMonetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI
nonemoves PA Scoreimpact 30
All evidence describes PayPal's agentic commerce as checkout-flow based (carts, ACP/UCP delegated tokens, Store Sync, agent toolkit for orders/refunds/disputes) — none of it describes HTTP 402 status-code machine payments or per-call API monetization without a checkout UI, which is a distinct technical pattern.
Protocol openness — stories about protocol openness in this arenaThe commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything
nonemoves PA Scoreimpact 30
The evidence pack shows PayPal implements OpenAI's ACP and Google's UCP protocols and tells developers to 'follow the ACP agentic checkout specification,' but never provides or links a version number, license, or spec document for ACP/UCP that a developer could read independently of PayPal.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Evidence documents PayPal's agentic commerce stack (Agent Ready, Store Sync, cart APIs, agent toolkit, MCP server) purely as infrastructure enabling AI agents to browse catalogs, create carts, and complete transactions on a merchant's behalf — none of it shows PayPal analyzing a user's/merchant's own data to surface AI-generated insights or suggestions inside the product (e.g., analytics dashboards, business recommendations).
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
The evidence pack documents PayPal's Agent Toolkit, MCP server, REST APIs, and SDKs, but nowhere mentions an official command-line interface (CLI) tool for developers or AI-native users to interact with PayPal's agentic commerce services.
Showing the top 8 of 42 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map9 surfaces · 28 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
AI tools docs21 stories
- My agent can create and update a cart or order draft through a documented protocol call
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
- Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
- My agent can discover payable services and APIs through a published directory or discovery index
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel
- Do everything through the API that I can do in the UI
- My agent can query the status and tracking of an order it placed, after the purchase
- Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes
- Refunds on agent-placed orders can be initiated and tracked programmatically
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
API reference19 stories
- My agent can create and update a cart or order draft through a documented protocol call
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Build against a versioned commerce protocol with a published schema and conformance or validation tooling
- Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Test against a sandbox environment without touching production data
- Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel
- Do everything through the API that I can do in the UI
- My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmatically
- My agent can query the status and tracking of an order it placed, after the purchase
- Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
- Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes
- Refunds on agent-placed orders can be initiated and tracked programmatically
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
Agentic commerce services docs11 stories
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
- Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
- Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell
- My agent can discover payable services and APIs through a published directory or discovery index
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- The fees for agent-originated transactions are published — I can price agentic channels without asking sales
- I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
- Do everything through the API that I can do in the UI
Store sync docs11 stories
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- Build against a versioned commerce protocol with a published schema and conformance or validation tooling
- My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
- Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service
- Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell
- My agent can discover payable services and APIs through a published directory or discovery index
- The fees for agent-originated transactions are published — I can price agentic channels without asking sales
- Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel
- I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
- Do everything through the API that I can do in the UI
Agent ready docs10 stories
- My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order
- Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)
- My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required
- Point an agent at llms.txt or agent-oriented docs
- Issue scoped/least-privilege API credentials for an agent
- Operate the product with natural-language commands
- I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint
- Do everything through the API that I can do in the UI
- Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number
- Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves
Tools docs5 stories
Us docs2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server PayPal documents for agentsreproduced$ curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server PayPal documents for agents HTTP/2 401 www-authenticate: Bearer realm="OAuth", resource_metadata="https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp", error="invalid_[redacted]", error_description="Missing or invalid access [redacted]"
$curl -s https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp # public OAuth resource metadatareproduced$ curl -s https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp # public OAuth resource metadata
{"resource":"https://mcp.paypal.com/mcp","authorization_servers":["https://mcp.paypal.com"],"scopes_supported":["openid","email","profile"],"bearer_methods_supported":["header"]}
$npm view @paypal/agent-toolkit versionreproduced$ npm view @paypal/agent-toolkit version agent-toolkit version: 1.11.0
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
8 of 22 testable claims verified · 2 contradicted → integrity 18/100
33 distinct capability claims found in PayPal Agentic Commerce’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
8
Verified
12
Unverified
2
Contradicted
7
Undersold
Verified (15)
“Accept payments from AI shopping assistants (ChatGPT, Google AI Mode, Gemini) via Braintree without building separate integrations for each platform”
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)partialproof ↗
“Build a custom ChatGPT app that accepts payments using the Agentic Commerce Protocol (ACP) and ChatGPT Apps SDK”
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)partialproof ↗
“Integrate the Google Pay handler for Google's Universal Commerce Protocol (UCP) with Braintree to enable checkout via Google AI Mode/Gemini”
Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers)partialproof ↗
“Store Sync connects a product catalog and commerce API so AI agents can discover products, manage carts, and complete purchases conversationally”
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed orderpartialproof ↗
“Build custom AI agents to handle payment workflows and customer interactions via the agent toolkit quickstart”
“Agent toolkit integrates PayPal APIs into agent frameworks: Bedrock, CrewAI, LangChain, MCP, OpenAI Agents SDK, Vercel AI SDK”
“Official MCP server lets merchants operate PayPal via natural language in MCP clients”
“Official MCP server lets merchants operate PayPal via natural language in MCP clients”
Operate the product with natural-language commandspartialproof ↗
“Pre-built functions give agents access to orders, invoices, subscriptions, shipment tracking, transaction details, and dispute management”
Drive the product through a documented public APIfullproof ↗
“Pre-built functions give agents access to orders, invoices, subscriptions, shipment tracking, transaction details, and dispute management”
My agent can query the status and tracking of an order it placed, after the purchasepartialproof ↗
“ChatGPT checkout uses a delegated one-time-use Braintree payment token, bound to merchant ID with amount and time restrictions”
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed orderpartialproof ↗
“UCP checkout returns a Google Pay tokenized credential server-side, processed by Braintree via the checkout-complete payload's credential.token field”
My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed orderpartialproof ↗
“Agent toolkit is available as SDKs in TypeScript and Python”
“Agent toolkit includes refund tools (create_refund/get_refund) for full or partial refunds on captured payments”
Refunds on agent-placed orders can be initiated and tracked programmaticallypartialproof ↗
“Agent toolkit includes order tools (create_order, pay_order, create_shipment) for programmatic order management”
Drive the product through a documented public APIfullproof ↗
Unverified (25)
“Accept payments from AI shopping assistants (ChatGPT, Google AI Mode, Gemini) via Braintree without building separate integrations for each platform”
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpointpartialproof ↗
“Build a custom ChatGPT app that accepts payments using the Agentic Commerce Protocol (ACP) and ChatGPT Apps SDK”
Build against a versioned commerce protocol with a published schema and conformance or validation toolingpartialproof ↗
“Connect product listings to partner platforms (Wix, Cymbio, BigCommerce/Feedonomics, Shopware) for easy catalog setup”
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sellpartialproof ↗
“Store Sync connects a product catalog and commerce API so AI agents can discover products, manage carts, and complete purchases conversationally”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Validate a product catalog file before connecting it to Store Sync”
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sellpartialproof ↗
“Pre-built functions give agents access to orders, invoices, subscriptions, shipment tracking, transaction details, and dispute management”
Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomespartialproof ↗
“Reverse API endpoint lets an AI agent or customer create a cart to initiate checkout”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Cart-status endpoint lets agents check current cart state, validation issues, and totals”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Both ACP and UCP acceptance paths require an existing Braintree merchant account — gated on Braintree, not a plain PayPal account”
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpointpartialproof ↗
“Access to agentic commerce services requires submitting a form and manual onboarding by PayPal's AI team, not self-serve enablement”
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpointpartialproof ↗
“ChatGPT checkout uses a delegated one-time-use Braintree payment token, bound to merchant ID with amount and time restrictions”
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card numberpartialproof ↗
“ACP checkout flow follows the published agentic checkout specification to manage checkout sessions”
Build against a versioned commerce protocol with a published schema and conformance or validation toolingpartialproof ↗
“UCP checkout returns a Google Pay tokenized credential server-side, processed by Braintree via the checkout-complete payload's credential.token field”
Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card numberpartialproof ↗
“UCP enablement requires separate merchant registration with Google, gated by Google rather than self-serve”
I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpointpartialproof ↗
“Orders placed via AI agents flow into the merchant's existing order management system like any other sales channel”
Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channelpartialproof ↗
“Catalog feeds support Google Product Feed and OpenAI ACP Product Feed specs (CSV/TSV/PSV, up to 4GB) reusable for both traditional and AI-driven discovery”
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sellpartialproof ↗
“Catalog feeds support Google Product Feed and OpenAI ACP Product Feed specs (CSV/TSV/PSV, up to 4GB) reusable for both traditional and AI-driven discovery”
Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or servicepartialproof ↗
“Merchant-hosted cart-creation endpoint authenticates via JWT tokens issued and managed by PayPal, verified with PayPal's public keys”
My agent can create and update a cart or order draft through a documented protocol callfullproof ↗
“Docs recommend keeping human oversight for judgment calls while letting AI handle repetitive tasks”
Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money movespartialproof ↗
“Agent toolkit includes dispute-management tools (list_disputes, get_dispute, accept_dispute_claim) to resolve disputes programmatically”
Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomespartialproof ↗
“Agent toolkit includes catalog-management tools (create_product, list_product, show_product_details) letting agents write to PayPal's product catalog”
Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sellpartialproof ↗
“Webhooks push HTTPS event notifications to merchant endpoints, up to 10 URLs per app, scoped by event type”
“Webhooks push HTTPS event notifications to merchant endpoints, up to 10 URLs per app, scoped by event type”
My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmaticallypartialproof ↗
“Webhook delivery retries up to 25 times over 3 days until a 2xx response is received”
“Standard PayPal commercial fee schedule applies to agent-originated orders; no separate agentic-channel fee schedule is published”
The fees for agent-originated transactions are published — I can price agentic channels without asking salespartialproof ↗
Contradicted (2)
“Store Sync connects a product catalog and commerce API so AI agents can discover products, manage carts, and complete purchases conversationally”
My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership requireddisputedproof ↗
“Agent toolkit integrates PayPal APIs into agent frameworks: Bedrock, CrewAI, LangChain, MCP, OpenAI Agents SDK, Vercel AI SDK”
Plug MCP servers into this product so it can use their toolsn/a
Undersold (7)
My agent can discover payable services and APIs through a published directory or discovery indexpartialproof ↗
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Test against a sandbox environment without touching production datafullproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Claims outside our story set (3)
Real capability claims found in PayPal Agentic Commerce’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Store Sync preserves merchant control over brand appearance and customer communications for AI-powered transactions”
source ↗“Store Sync currently only supports physical goods sold to US-based customers in USD — no digital goods, subscriptions, or international sales”
source ↗“Webhook authenticity can be verified via PayPal's verify-signature endpoint”
source ↗
Business model
Agent flows ride standard PayPal/Braintree processing (PayPal Checkout 3.49% + fixed fee, cards 2.99% + fixed fee in the US); no separate published price for agent-originated traffic.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
