Challenger
Generated from this merchant’s live profile. Every identifier and example below is real for this deployment.
Identity
Integration status
Commercial policy (server-side only)
These values are never returned by a public endpoint and are never sent to a browser. They are applied inside the offer validator before an offer can be sealed.
Endpoints
/api/storefront/chatMerchant-scoped storefront conversation. Tools are bound to this merchantId; there is no cross-merchant search.
/api/shopify/syncPull catalogue, variants and inventory into the normalized mirror.
/api/shopify/orderCreate an order for a SKU. Returns shopifyOrderStatus: created | not_configured | failed | demo.
/api/public/merchant/challengerPublic browser-safe config for the storefront widget. Agent id only, no secrets.
/api/exchange/requestCustomer-agent entry point. Signed RFO fans out to every network-enabled merchant agent.
/api/exchange/counterOne counteroffer round against a sealed offer, evaluated against this merchant's policy floor.
/api/offers/:offerId/lockRe-check inventory, re-canonicalize, compare SHA-256, freeze the offer.
/api/payments/instructionCreate a Payment Instruction bound to this merchant, an amount ceiling and an expiry.
/api/payments/authorizeEnforce the instruction controls, then authorize through the Visa Acceptance adapter.
/api/events/:sessionIdSSE stream of agent events for a session.
Examples
curl -X POST http://localhost:3000/api/storefront/chat \
-H 'content-type: application/json' \
-d '{
"merchantId": "challenger",
"message": "I need something light for coding under SGD 1500",
"history": []
}'curl -X POST http://localhost:3000/api/shopify/order \
-H 'content-type: application/json' \
-d '{
"merchantId": "challenger",
"sku": "CHA-NITRO-V16",
"quantity": 1,
"amount": 1599,
"currency": "SGD",
"reference": "PI-EXAMPLE"
}'{
"offerId": "ofbiz_a1b2c3d4",
"requestId": "req_xxxx",
"merchantId": "challenger",
"sku": "CHA-NITRO-V16",
"price": 1551,
"currency": "SGD",
"bundle": {
"type": "mouse",
"description": "Wireless mouse",
"value": 35
},
"warrantyYears": 2,
"deliveryDays": 1,
"availability": "in_stock",
"merchantPolicyVerified": true,
"state": "sealed",
"hash": "sha-256 hex of the canonical offer",
"expiresAt": "2026-08-29T13:45:00.000Z"
}Storefront widget
<script src="http://localhost:3000/widget.js" data-merchant-id="challenger" data-agent-id="merchant_challenger_5MW9D" async></script>
Auth and security
- Public identifiers. The agent id and merchant id are browser-safe and are the only values the widget receives.
- Server-side secrets. Commercial rules, cost prices, margins, Shopify tokens, Visa credentials and the agent signing key never leave the server and never enter a model prompt.
- Agent request signing. Customer-agent requests carry an Ed25519 signature over an RFC 9421-style signature base with a nonce and timestamp; the merchant agent verifies before constructing an offer. This is a TAP-style implementation against Visa’s public protocol model — the demo key is locally generated and is not registered with Visa.
- Merchant isolation. Storefront sessions are constructed with one merchant id and the tools close over it. No cross-merchant read path exists.
- Offer integrity. A sealed offer is canonicalized and hashed with SHA-256. Authorization is refused if the hash changes.
- This prototype has no merchant authentication. A production deployment would issue per-merchant API keys with HMAC request signing and scope every endpoint to the authenticated merchant.