---
title: "Agent protocols: UCP, ACP, AP2, WebMCP, llms.txt · Specoria"
description: "What UCP, ACP, AP2, MCP, WebMCP, A2A, Web Bot Auth and llms.txt are for, who runs them, where they stand and what our free test checks. Sourced and dated."
source_url: "https://specoria.com/agent-protocols/"
lang: "en"
---

AGENT PROTOCOL MAP Facts checked against their sources on October 8, 2026

# The agent protocol map: UCP, ACP, AP2, MCP, WebMCP, A2A, Web Bot Auth and llms.txt

Eight names come up whenever agentic commerce is discussed. Here is what each one is for, who runs it, where it stands, what is known about it in Türkiye, and exactly what Specoria’s free test checks for it. Only sourced facts, each with a date.

## At a glance

| Protocol | What it is for | In Türkiye | Our free test |
| --- | --- | --- | --- |
| [UCP](https://specoria.com/agent-protocols/#ucp) | An open standard for agentic commerce covering catalog, cart, checkout, identity linking and orders; it is designed to work with AP2, A2A and MCP. | Google’s Merchant Center help says UCP-based checkout applies only to products eligible in the United States, Canada and Australia, for select merchants. | Checked |
| [ACP](https://specoria.com/agent-protocols/#acp) | An open standard (Apache 2.0) for agents and businesses to complete purchases: checkout and delegated payment, and since 2026 product feeds too. | OpenAI’s product feed specification says the shared format currently covers the US, Canada and Mexico. | Partly checked |
| [AP2](https://specoria.com/agent-protocols/#ap2) | Agent-initiated payments built on signed mandates: cryptographic records of what the user authorised the agent to buy. | The protocol site names no Türkiye-specific programme or partner. | Not checked |
| [MCP](https://specoria.com/agent-protocols/#mcp) | An open protocol that connects AI applications to external tools and data; a store can offer an MCP server so agents can search products or check stock. | An open specification with no country restrictions. | Partly checked |
| [WebMCP](https://specoria.com/agent-protocols/#webmcp) | Lets a website expose actions, such as “add to cart” or “check stock”, as tools an agent in the browser can call directly instead of guessing which button to press. | No country restrictions are stated. | Partly checked |
| [A2A](https://specoria.com/agent-protocols/#a2a) | Lets agents from different vendors discover each other and hand off tasks; an agent publishes a card describing what it can do. | An open specification with no country restrictions. | Checked |
| [Web Bot Auth](https://specoria.com/agent-protocols/#web-bot-auth) | Bots and agents sign their HTTP requests (HTTP Message Signatures, RFC 9421) so a site or CDN can verify who they are against published keys. | Works at web level, with no country restrictions. | Checked |
| [llms.txt](https://specoria.com/agent-protocols/#llms-txt) | A Markdown file at /llms.txt that summarises a site for language models and links to its key pages. | A site-level file with no country restrictions. | Checked |

## UCP Universal Commerce Protocol

**What it is for**
An open standard for agentic commerce covering catalog, cart, checkout, identity linking and orders; it is designed to work with AP2, A2A and MCP. A store publishes a profile at /.well-known/ucp.

**Who runs it**
An open-source project (Apache 2.0) co-developed by Google with Shopify, Etsy, Wayfair, Target and Walmart.

**Where it stands**
Launched in January 2026; the latest specification release is dated 25 August 2026. Source: [UCP releases (GitHub) ↗](https://github.com/Universal-Commerce-Protocol/ucp/releases) · August 25, 2026

**In Türkiye**
Google’s Merchant Center help says UCP-based checkout applies only to products eligible in the United States, Canada and Australia, for select merchants. Türkiye is not listed. Source: [Google Merchant Center Help ↗](https://support.google.com/merchants/answer/16837055) · October 8, 2026

**What our free test checks Checked**
Reads /.well-known/ucp and checks it softly: a valid JSON object with a dated version, and common setup mistakes (no signing key; placeholder signing key; signing key isn’t a valid JWK; non-standard capability name; extends a capability missing from the profile; non-https schema URL).
Requests (GET only): `/.well-known/ucp`
Shown in the result as: UCP (/.well-known/ucp)

## ACP Agentic Commerce Protocol

**What it is for**
An open standard (Apache 2.0) for agents and businesses to complete purchases: checkout and delegated payment, and since 2026 product feeds too.

**Who runs it**
OpenAI and Stripe, as founding maintainers.

**Where it stands**
The specification describes itself as beta. ChatGPT’s Instant Checkout launched in the US in September 2025; in March 2026 OpenAI said it would let merchants use their own checkout and focus on product discovery. Source: [Agentic Commerce Protocol (GitHub) ↗](https://github.com/agentic-commerce-protocol/agentic-commerce-protocol) · October 8, 2026

Source: [CNBC ↗](https://www.cnbc.com/2026/03/24/openai-revamps-shopping-experience-in-chatgpt-after-instant-checkout.html) · March 24, 2026

**In Türkiye**
OpenAI’s product feed specification says the shared format currently covers the US, Canada and Mexico. Türkiye is not listed. Source: [OpenAI Commerce · product feed spec ↗](https://developers.openai.com/commerce/specs/file-upload/products.md) · October 8, 2026

**What our free test checks Partly checked**
Sends a GET to /checkout_sessions: a 405 or an ACP-style JSON error is shown as a possible ACP checkout endpoint, not verified. Also looks for the OpenAI domain verification tag, and a separate line checks the eight policy and contact link types ACP asks merchants for.
Requests (GET only): `/checkout_sessions`
Shown in the result as: possible ACP checkout endpoint (/checkout_sessions, not verified) · OpenAI domain verification tag · Policy and contact links

## AP2 Agent Payments Protocol

**What it is for**
Agent-initiated payments built on signed mandates: cryptographic records of what the user authorised the agent to buy.

**Who runs it**
Announced by Google in September 2025; donated to the FIDO Alliance on 28 April 2026, together with version 0.2.

**Where it stands**
Version 0.2, under the FIDO Alliance. Source: [Google ↗](https://blog.google/products-and-platforms/platforms/google-pay/agent-payments-protocol-fido-alliance/) · April 28, 2026

**In Türkiye**
The protocol site names no Türkiye-specific programme or partner. Source: [AP2 ↗](https://ap2-protocol.org/) · October 8, 2026

**What our free test checks Not checked**
Not checked. There is no file a store publishes for us to read; AP2 travels inside payment flows, which we never start.

## MCP Model Context Protocol

**What it is for**
An open protocol that connects AI applications to external tools and data; a store can offer an MCP server so agents can search products or check stock.

**Who runs it**
Created by Anthropic; donated on 9 December 2025 to the Agentic AI Foundation, a fund under the Linux Foundation.

**Where it stands**
Donated to the Agentic AI Foundation in December 2025; the current specification is version 2026-07-28. Source: [Anthropic ↗](https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation) · December 9, 2025

Source: [Model Context Protocol blog ↗](https://blog.modelcontextprotocol.io/posts/2026-07-28/) · July 28, 2026

**In Türkiye**
An open specification with no country restrictions. Source: [MCP specification ↗](https://modelcontextprotocol.io/specification/) · October 8, 2026

**What our free test checks Partly checked**
Reads /.well-known/mcp.json and /.well-known/mcp. A valid JSON object is shown as an MCP discovery file. We don’t connect to the server or run a handshake.
Requests (GET only): `/.well-known/mcp.json`, `/.well-known/mcp`
Shown in the result as: MCP discovery file

## WebMCP Web Model Context Protocol

**What it is for**
Lets a website expose actions, such as “add to cart” or “check stock”, as tools an agent in the browser can call directly instead of guessing which button to press.

**Who runs it**
The W3C Web Machine Learning Community Group. It is a draft community group report, not a W3C standard.

**Where it stands**
A draft community group report. In origin trial from Chrome 149 (announced June 2026). Shopify added WebMCP tools to checkout on 28 September 2026. Source: [W3C Web Machine Learning CG · WebMCP draft ↗](https://webmachinelearning.github.io/webmcp/) · October 8, 2026

Source: [Chrome for Developers ↗](https://developer.chrome.com/blog/ai-webmcp-origin-trial) · June 9, 2026

Source: [Shopify changelog ↗](https://shopify.dev/changelog/webmcp-support-for-checkout) · September 28, 2026

**In Türkiye**
No country restrictions are stated. Shopify’s checkout tools hand control back to the buyer for steps such as 3D Secure. Source: [Shopify changelog ↗](https://shopify.dev/changelog/webmcp-support-for-checkout) · September 28, 2026

**What our free test checks Partly checked**
Looks in the initial HTML for a form with a toolname attribute or a modelContext.registerTool call. The agent simulator, which runs a real browser, also lists the tools a page offers.
Shown in the result as: WebMCP tool markers (in the page source)

## A2A Agent2Agent

**What it is for**
Lets agents from different vendors discover each other and hand off tasks; an agent publishes a card describing what it can do.

**Who runs it**
Launched by Google in April 2025, a Linux Foundation project since June 2025 and an Agentic AI Foundation hosted project since 17 August 2026.

**Where it stands**
Version 1.0, its first stable specification, came out in early 2026; the Linux Foundation reported more than 150 supporting organisations in April 2026. Source: [Linux Foundation ↗](https://www.linuxfoundation.org/press/a2a-protocol-surpasses-150-organizations-lands-in-major-cloud-platforms-and-sees-enterprise-production-use-in-first-year) · April 9, 2026

Source: [Agentic AI Foundation ↗](https://aaif.io/blog/a2a-joins-aaif) · August 17, 2026

**In Türkiye**
An open specification with no country restrictions. Source: [A2A specification ↗](https://a2a-protocol.org/latest/specification/) · October 8, 2026

**What our free test checks Checked**
Reads /.well-known/agent-card.json. It counts if the JSON has a name and skills, a URL or capabilities.
Requests (GET only): `/.well-known/agent-card.json`
Shown in the result as: A2A agent card

## Web Bot Auth Web Bot Auth

**What it is for**
Bots and agents sign their HTTP requests (HTTP Message Signatures, RFC 9421) so a site or CDN can verify who they are against published keys.

**Who runs it**
The IETF webbotauth working group; Cloudflare treats signed agents as verified bots, and Google is testing it for part of its Google-Agent traffic.

**Where it stands**
An Internet-Draft (working-group draft of 1 September 2026), not yet an RFC. Cloudflare added a “signed agents” category in August 2025. Source: [IETF webbotauth working group ↗](https://datatracker.ietf.org/group/webbotauth/documents/) · September 1, 2026

Source: [Cloudflare ↗](https://blog.cloudflare.com/signed-agents/) · August 28, 2025

**In Türkiye**
Works at web level, with no country restrictions. Google describes its own use as experimental. Source: [Google Search Central ↗](https://developers.google.com/crawling/docs/crawlers-fetchers/web-bot-auth) · May 4, 2026

**What our free test checks Checked**
Reads /.well-known/http-message-signatures-directory and shows it if it lists keys. Most stores don’t need one: it matters for sites that run their own agents. Separately, the agent simulator’s browser runs on Cloudflare and identifies itself as Cloudflare’s signed bot.
Requests (GET only): `/.well-known/http-message-signatures-directory`
Shown in the result as: Web Bot Auth key directory

## llms.txt llms.txt

**What it is for**
A Markdown file at /llms.txt that summarises a site for language models and links to its key pages.

**Who runs it**
A proposal by Jeremy Howard (Answer.AI), first published in September 2024. Not a formal standard.

**Where it stands**
Version 2 of the proposal (last updated August 2026). Google says its Search ignores llms.txt files: creating one will neither help nor harm. Source: [llmstxt.org ↗](https://llmstxt.org/) · August 10, 2026

Source: [Google Search Central ↗](https://developers.google.com/search/docs/fundamentals/ai-optimization-guide) · July 10, 2026

**In Türkiye**
A site-level file with no country restrictions. Source: [llmstxt.org ↗](https://llmstxt.org/) · August 10, 2026

**What our free test checks Checked**
Checks whether /llms.txt exists and how it is built: one H1 title, a “>” summary, “##” sections and annotated links; up to three of its links are tried. Neither line affects the score.
Requests (GET only): `/llms.txt`
Shown in the result as: llms.txt · llms.txt structure

## Other discovery files the test reads

Two catalog files are not protocols in themselves but help agents find a site’s resources. The test reads them too, with the same rules:

- **AI Catalog**: `/.well-known/ai-catalog.json`
- **API Catalog (RFC 9727)**: `/.well-known/api-catalog`

## How the test treats protocols

- None of these affects the score. Adoption is still very low, so a missing file is information, not a fault.
- Only GET requests to the store’s own domain, small and short. We never call an endpoint, open a session, send a POST or place an order.
- A file counts only if it is a valid JSON object of the expected shape; a soft 404 page doesn’t count.
- Every request is listed on our crawler page, and you can ask to have your site excluded.

[Every request our crawler makes →](https://specoria.com/bot/)

[Run the free test on your store →](https://specoria.com/#contact) [How the free test works →](https://specoria.com/method/)

## Questions

Does my store need all of these? No. For most stores in Türkiye today, what matters more is that agents can reach and read your pages: robots.txt, bot protection, product data, prices, policies. Protocols are worth watching; the free test tells you which signals you already publish.

Why do you check ACP only partly? An ACP checkout endpoint expects signed POST requests. We only send a GET to /checkout_sessions and treat a 405 or an ACP-style error as a possible sign; we don’t verify it, because doing so would mean starting a checkout.

Why isn’t AP2 checked? AP2 has no file a store publishes on its own site for us to read; it travels inside payment flows. We don’t start payment flows.
