AGENT PROTOCOL MAPFacts checked against their sources on October 8, 2026

The agent protocol map: UCP, ACP, AP2, MCP, WebMCP, A2A, Web Bot Auth and llms.txt

Eight names come up whenever agentic commerce is discussed. Here is what each one is for, who runs it, where it stands, what is known about it in Türkiye, and exactly what Specoria’s free test checks for it. Only sourced facts, each with a date.

At a glance

ProtocolWhat it is forIn TürkiyeOur free test
UCPAn open standard for agentic commerce covering catalog, cart, checkout, identity linking and orders; it is designed to work with AP2, A2A and MCP.Google’s Merchant Center help says UCP-based checkout applies only to products eligible in the United States, Canada and Australia, for select merchants.Checked
ACPAn open standard (Apache 2.0) for agents and businesses to complete purchases: checkout and delegated payment, and since 2026 product feeds too.OpenAI’s product feed specification says the shared format currently covers the US, Canada and Mexico.Partly checked
AP2Agent-initiated payments built on signed mandates: cryptographic records of what the user authorised the agent to buy.The protocol site names no Türkiye-specific programme or partner.Not checked
MCPAn open protocol that connects AI applications to external tools and data; a store can offer an MCP server so agents can search products or check stock.An open specification with no country restrictions.Partly checked
WebMCPLets a website expose actions, such as “add to cart” or “check stock”, as tools an agent in the browser can call directly instead of guessing which button to press.No country restrictions are stated.Partly checked
A2ALets agents from different vendors discover each other and hand off tasks; an agent publishes a card describing what it can do.An open specification with no country restrictions.Checked
Web Bot AuthBots and agents sign their HTTP requests (HTTP Message Signatures, RFC 9421) so a site or CDN can verify who they are against published keys.Works at web level, with no country restrictions.Checked
llms.txtA Markdown file at /llms.txt that summarises a site for language models and links to its key pages.A site-level file with no country restrictions.Checked

UCP Universal Commerce Protocol

What it is for
An open standard for agentic commerce covering catalog, cart, checkout, identity linking and orders; it is designed to work with AP2, A2A and MCP. A store publishes a profile at /.well-known/ucp.
Who runs it
An open-source project (Apache 2.0) co-developed by Google with Shopify, Etsy, Wayfair, Target and Walmart.
Where it stands
Launched in January 2026; the latest specification release is dated 25 August 2026.

Source: UCP releases (GitHub) ↗ ·

In Türkiye
Google’s Merchant Center help says UCP-based checkout applies only to products eligible in the United States, Canada and Australia, for select merchants. Türkiye is not listed.

Source: Google Merchant Center Help ↗ ·

What our free test checks Checked
Reads /.well-known/ucp and checks it softly: a valid JSON object with a dated version, and common setup mistakes (no signing key; placeholder signing key; signing key isn’t a valid JWK; non-standard capability name; extends a capability missing from the profile; non-https schema URL).
Requests (GET only): /.well-known/ucp
Shown in the result as: UCP (/.well-known/ucp)

ACP Agentic Commerce Protocol

What it is for
An open standard (Apache 2.0) for agents and businesses to complete purchases: checkout and delegated payment, and since 2026 product feeds too.
Who runs it
OpenAI and Stripe, as founding maintainers.
Where it stands
The specification describes itself as beta. ChatGPT’s Instant Checkout launched in the US in September 2025; in March 2026 OpenAI said it would let merchants use their own checkout and focus on product discovery.

Source: Agentic Commerce Protocol (GitHub) ↗ ·

Source: CNBC ↗ ·

In Türkiye
OpenAI’s product feed specification says the shared format currently covers the US, Canada and Mexico. Türkiye is not listed.

Source: OpenAI Commerce · product feed spec ↗ ·

What our free test checks Partly checked
Sends a GET to /checkout_sessions: a 405 or an ACP-style JSON error is shown as a possible ACP checkout endpoint, not verified. Also looks for the OpenAI domain verification tag, and a separate line checks the eight policy and contact link types ACP asks merchants for.
Requests (GET only): /checkout_sessions
Shown in the result as: possible ACP checkout endpoint (/checkout_sessions, not verified) · OpenAI domain verification tag · Policy and contact links

AP2 Agent Payments Protocol

What it is for
Agent-initiated payments built on signed mandates: cryptographic records of what the user authorised the agent to buy.
Who runs it
Announced by Google in September 2025; donated to the FIDO Alliance on 28 April 2026, together with version 0.2.
Where it stands
Version 0.2, under the FIDO Alliance.

Source: Google ↗ ·

In Türkiye
The protocol site names no Türkiye-specific programme or partner.

Source: AP2 ↗ ·

What our free test checks Not checked
Not checked. There is no file a store publishes for us to read; AP2 travels inside payment flows, which we never start.

MCP Model Context Protocol

What it is for
An open protocol that connects AI applications to external tools and data; a store can offer an MCP server so agents can search products or check stock.
Who runs it
Created by Anthropic; donated on 9 December 2025 to the Agentic AI Foundation, a fund under the Linux Foundation.
Where it stands
Donated to the Agentic AI Foundation in December 2025; the current specification is version 2026-07-28.

Source: Anthropic ↗ ·

Source: Model Context Protocol blog ↗ ·

In Türkiye
An open specification with no country restrictions.

Source: MCP specification ↗ ·

What our free test checks Partly checked
Reads /.well-known/mcp.json and /.well-known/mcp. A valid JSON object is shown as an MCP discovery file. We don’t connect to the server or run a handshake.
Requests (GET only): /.well-known/mcp.json, /.well-known/mcp
Shown in the result as: MCP discovery file

WebMCP Web Model Context Protocol

What it is for
Lets a website expose actions, such as “add to cart” or “check stock”, as tools an agent in the browser can call directly instead of guessing which button to press.
Who runs it
The W3C Web Machine Learning Community Group. It is a draft community group report, not a W3C standard.
Where it stands
A draft community group report. In origin trial from Chrome 149 (announced June 2026). Shopify added WebMCP tools to checkout on 28 September 2026.

Source: W3C Web Machine Learning CG · WebMCP draft ↗ ·

Source: Chrome for Developers ↗ ·

Source: Shopify changelog ↗ ·

In Türkiye
No country restrictions are stated. Shopify’s checkout tools hand control back to the buyer for steps such as 3D Secure.

Source: Shopify changelog ↗ ·

What our free test checks Partly checked
Looks in the initial HTML for a form with a toolname attribute or a modelContext.registerTool call. The agent simulator, which runs a real browser, also lists the tools a page offers.
Shown in the result as: WebMCP tool markers (in the page source)

A2A Agent2Agent

What it is for
Lets agents from different vendors discover each other and hand off tasks; an agent publishes a card describing what it can do.
Who runs it
Launched by Google in April 2025, a Linux Foundation project since June 2025 and an Agentic AI Foundation hosted project since 17 August 2026.
Where it stands
Version 1.0, its first stable specification, came out in early 2026; the Linux Foundation reported more than 150 supporting organisations in April 2026.

Source: Linux Foundation ↗ ·

Source: Agentic AI Foundation ↗ ·

In Türkiye
An open specification with no country restrictions.

Source: A2A specification ↗ ·

What our free test checks Checked
Reads /.well-known/agent-card.json. It counts if the JSON has a name and skills, a URL or capabilities.
Requests (GET only): /.well-known/agent-card.json
Shown in the result as: A2A agent card

Web Bot Auth Web Bot Auth

What it is for
Bots and agents sign their HTTP requests (HTTP Message Signatures, RFC 9421) so a site or CDN can verify who they are against published keys.
Who runs it
The IETF webbotauth working group; Cloudflare treats signed agents as verified bots, and Google is testing it for part of its Google-Agent traffic.
Where it stands
An Internet-Draft (working-group draft of 1 September 2026), not yet an RFC. Cloudflare added a “signed agents” category in August 2025.

Source: IETF webbotauth working group ↗ ·

Source: Cloudflare ↗ ·

In Türkiye
Works at web level, with no country restrictions. Google describes its own use as experimental.

Source: Google Search Central ↗ ·

What our free test checks Checked
Reads /.well-known/http-message-signatures-directory and shows it if it lists keys. Most stores don’t need one: it matters for sites that run their own agents. Separately, the agent simulator’s browser runs on Cloudflare and identifies itself as Cloudflare’s signed bot.
Requests (GET only): /.well-known/http-message-signatures-directory
Shown in the result as: Web Bot Auth key directory

llms.txt llms.txt

What it is for
A Markdown file at /llms.txt that summarises a site for language models and links to its key pages.
Who runs it
A proposal by Jeremy Howard (Answer.AI), first published in September 2024. Not a formal standard.
Where it stands
Version 2 of the proposal (last updated August 2026). Google says its Search ignores llms.txt files: creating one will neither help nor harm.

Source: llmstxt.org ↗ ·

Source: Google Search Central ↗ ·

In Türkiye
A site-level file with no country restrictions.

Source: llmstxt.org ↗ ·

What our free test checks Checked
Checks whether /llms.txt exists and how it is built: one H1 title, a “>” summary, “##” sections and annotated links; up to three of its links are tried. Neither line affects the score.
Requests (GET only): /llms.txt
Shown in the result as: llms.txt · llms.txt structure

Other discovery files the test reads

Two catalog files are not protocols in themselves but help agents find a site’s resources. The test reads them too, with the same rules:

  • AI Catalog: /.well-known/ai-catalog.json
  • API Catalog (RFC 9727): /.well-known/api-catalog

How the test treats protocols

  • None of these affects the score. Adoption is still very low, so a missing file is information, not a fault.
  • Only GET requests to the store’s own domain, small and short. We never call an endpoint, open a session, send a POST or place an order.
  • A file counts only if it is a valid JSON object of the expected shape; a soft 404 page doesn’t count.
  • Every request is listed on our crawler page, and you can ask to have your site excluded.

Every request our crawler makes →

Run the free test on your store → How the free test works →

Questions

Does my store need all of these?

No. For most stores in Türkiye today, what matters more is that agents can reach and read your pages: robots.txt, bot protection, product data, prices, policies. Protocols are worth watching; the free test tells you which signals you already publish.

Why do you check ACP only partly?

An ACP checkout endpoint expects signed POST requests. We only send a GET to /checkout_sessions and treat a 405 or an ACP-style error as a possible sign; we don’t verify it, because doing so would mean starting a checkout.

Why isn’t AP2 checked?

AP2 has no file a store publishes on its own site for us to read; it travels inside payment flows. We don’t start payment flows.