Sherpa Computers
Generated from this merchant’s live profile. Every identifier and example below is real for this deployment.
This merchant runs on Shopify, so catalogue sync, inventory and order creation flow through the installed app — nothing on this page is required. These endpoints are the advanced path for custom integrations, headless storefronts, or connecting a second commerce system.
Identity
Integration status
Commercial policy (server-side only)
These values are never returned by a public endpoint and are never sent to a browser. They are applied inside the offer validator before an offer can be sealed.
Endpoints
/api/storefront/chatMerchant-scoped storefront conversation. Tools are bound to this merchantId; there is no cross-merchant search.
/api/shopify/syncPull catalogue, variants and inventory into the normalized mirror.
/api/shopify/orderCreate an order for a SKU. Returns shopifyOrderStatus: created | not_configured | failed | demo.
/api/public/merchant/sherpa-computersPublic browser-safe config for the storefront widget. Agent id only, no secrets.
/api/exchange/requestCustomer-agent entry point. Signed RFO fans out to every network-enabled merchant agent.
/api/exchange/counterOne counteroffer round against a sealed offer, evaluated against this merchant's policy floor.
/api/offers/:offerId/lockRe-check inventory, re-canonicalize, compare SHA-256, freeze the offer.
/api/payments/instructionCreate a Payment Instruction bound to this merchant, an amount ceiling and an expiry.
/api/payments/authorizeEnforce the instruction controls, then authorize through the Visa Acceptance adapter.
/api/events/:sessionIdSSE stream of agent events for a session.
Examples
curl -X POST http://localhost:3000/api/storefront/chat \
-H 'content-type: application/json' \
-d '{
"merchantId": "sherpa-computers",
"message": "I need something light for coding under SGD 1500",
"history": []
}'curl -X POST http://localhost:3000/api/shopify/order \
-H 'content-type: application/json' \
-d '{
"merchantId": "sherpa-computers",
"sku": "SHP-TUF-A15",
"quantity": 1,
"amount": 1529,
"currency": "SGD",
"reference": "PI-EXAMPLE"
}'{
"offerId": "ofbiz_a1b2c3d4",
"requestId": "req_xxxx",
"merchantId": "sherpa-computers",
"sku": "SHP-TUF-A15",
"price": 1483,
"currency": "SGD",
"bundle": {
"type": "mouse",
"description": "Wireless mouse",
"value": 35
},
"warrantyYears": 1,
"deliveryDays": 2,
"availability": "in_stock",
"merchantPolicyVerified": true,
"state": "sealed",
"hash": "sha-256 hex of the canonical offer",
"expiresAt": "2026-08-29T13:45:00.000Z"
}Storefront widget
On Shopify the storefront agent ships as a Theme App Extension app embed block (extensions/storefront-chat). Activate it in the theme editor under App embeds — no theme code changes and no ScriptTag injection.
<script src="http://localhost:3000/widget.js" data-merchant-id="sherpa-computers" data-agent-id="merchant_sherpa_computers_8H3K2" async></script>
Auth and security
- Public identifiers. The agent id and merchant id are browser-safe and are the only values the widget receives.
- Server-side secrets. Commercial rules, cost prices, margins, Shopify tokens, Visa credentials and the agent signing key never leave the server and never enter a model prompt.
- Agent request signing. Customer-agent requests carry an Ed25519 signature over an RFC 9421-style signature base with a nonce and timestamp; the merchant agent verifies before constructing an offer. This is a TAP-style implementation against Visa’s public protocol model — the demo key is locally generated and is not registered with Visa.
- Merchant isolation. Storefront sessions are constructed with one merchant id and the tools close over it. No cross-merchant read path exists.
- Offer integrity. A sealed offer is canonicalized and hashed with SHA-256. Authorization is refused if the hash changes.
- This prototype has no merchant authentication. A production deployment would issue per-merchant API keys with HMAC request signing and scope every endpoint to the authenticated merchant.