{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "agentzon",
    "name": "Agentzon",
    "vendor": "Merit Systems, Inc.",
    "vendorUrl": "https://agentzon.co",
    "kind": "http-api",
    "category": "commerce",
    "summary": "Online store for household essentials that agents can search and buy from through a JSON API. Sells 466 purchasable items shipped within the U.S. by Merit Systems Inc, with payment on a private checkout page.",
    "url": "https://www.anchorterminal.com/tools/agentzon",
    "markdownUrl": "https://www.anchorterminal.com/tools/agentzon.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentzon.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentzon.json",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://agentzon.co/api",
    "packages": [],
    "auth": "none",
    "authNotes": "No accounts, registration or API keys for search, product lookup or checkout creation. Order status takes a per-order bearer token (orderToken) issued by checkout. It is read-only, never expires and has no revocation endpoint. The UCP endpoint takes no credential and asks for a UCP-Agent header naming the platform profile (https://agentzon.co/auth.md).",
    "pricing": "usage",
    "pricingNotes": "The API has no fee and no plan. The buyer pays the item price per order, with sales tax added at checkout and free shipping to U.S. addresses. No free tier, trial or test mode was found. Every product reports checkoutMode live (checked 10 October 2026).",
    "priceSummary": "Pay per use",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in llms.txt, agents.md, openapi.json, auth.md or the storefront script (checked 10 October 2026).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-10"
    },
    "docsUrl": "https://agentzon.co/agents.md",
    "llmsTxt": "https://agentzon.co/llms.txt",
    "openapi": "https://agentzon.co/openapi.json",
    "capabilities": [
      "commerce.products",
      "commerce.checkout",
      "commerce.orders",
      "commerce.headless"
    ],
    "tags": [
      "hosted",
      "openapi",
      "llms-txt",
      "no-key",
      "no-signup",
      "webmcp",
      "ucp",
      "stripe",
      "us-only",
      "closed-source",
      "no-status-page",
      "sales-tax"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 51.4,
      "grade": "D",
      "agentReady": false,
      "rank": 753,
      "ranked": true,
      "rankOf": 955,
      "categoryRank": 16,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 5,
        "payments": 40,
        "reliability": 40,
        "schema": 83,
        "security": 45,
        "transparency": 45
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 40,
          "points": 8,
          "reason": "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status, each 404 on 10 October 2026, so the status page line scores 0 (0 of 20). No readable incident history exists, which takes the 5-point default (5 of 30). Catalogue reads have published figures, 120 a minute per process and client IP, with Retry-After on 429 (10 of 15). The checkout and order limits have no figure, so the line is not full. 429 handling is documented with Retry-After, and Idempotency-Key covers checkout retries, with retry guidance in agents.md (15 of 15). No SLA and no paid tier (0 of 10). The API is live and takes real payments, with checkoutMode live on all 500 products (10 of 10). Total 40."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "OpenAPI 3.1.0 at /openapi.json, valid JSON, with request and response schemas for every route (25 of 25). llms.txt at /llms.txt and agents.md in Markdown, both linked from the home page (10 of 10). The descriptions say when not to act. Creating a session is not payment, a paid status confirms payment and not shipment, a null price is unavailable and never free, and purchase needs the buyer's authorisation (18 of 20). No MCP tool definitions exist to read. Inputs are typed, with enums for category and sort, length limits, a pattern on Idempotency-Key and required items at checkout (15 of 15). Examples are given in curl and JSON. Responses are listed for 400, 404, 409 and 429, but the error body is one text field with no machine-readable code (10 of 15). The info block has version 1.0.0 and UCP is dated, but there is no public changelog and the URLs carry no version (5 of 15). Total 83."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Responses can be limited (limit 1 to 100, offset) but not reduced field by field. The first 20 items of the unfiltered catalogue came to 15.5 KB, because each item carries its details (15 of 25). Pagination with offset and nextOffset, filters for category and brand, and four sort orders (20 of 20). Errors carry HTTP codes and a short message, and agents.md gives a recovery step for 400, 415, 409, 429 and network failure, but there are no error codes in the body (15 of 20). Idempotency-Key is required on checkout and catalogue suggestions, with safe-retry guidance (20 of 20). Sensible defaults (limit 20, sort featured) and one required field at checkout. No official SDKs, so the SDK half of the line is unmet (8 of 15). Total 78."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 45,
          "points": 7.88,
          "reason": "Read endpoints and checkout creation take no credential (no points for a key model). The order token is a bearer secret that reads one order, never expires and cannot be revoked (15 of 30, between the 10 for one all-powerful key and the 20 for a revocable key). The checkout URL is a payment credential passed in the URL fragment, not the query string, so the 10-point deduction does not apply. Read-only and least-privilege. Catalogue reads and checkout creation cannot take money. The privacy policy says Stripe handles card details and the checkout application never receives them, and the API says never to send them to Agentzon, so an agent cannot pay alone (20 of 20). Prompt injection. The catalogue returns product names and descriptions written by the seller, and no guidance on treating them as data was found (5 of 15). Operator visibility. The buyer has no call log. Agentzon keeps checkout diagnostics for 90 days and aggregate request counters, which the buyer cannot see (5 of 15). Programme. security.txt returns 404, and no bug bounty, certification or advisory page was found (0 of 20). Total 45."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No machine payment protocol (x402, MPP or L402) on any endpoint. UCP is a commerce protocol, and its checkout ends at the same payment page, so it earns nothing here (0 of 40). Item prices are published without a login through GET /api/products. 466 priced items from USD 0.99 to 149.99 on 10 October 2026. Prices exclude sales tax, which is added at checkout (20 of 20). No free tier, trial or test mode was found. Every product reports checkoutMode live (0 of 20). No account, registration or key is needed to search or to create a checkout, so an agent gets access without a signup flow (20 of 20). Total 40. The buyer still enters card details by hand, which the security note covers."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 5,
          "points": 0.44,
          "reason": "No dated API release, changelog or version history was found. The policy pages carry an effective date of 8 October 2026, but those are changes to terms, not to the API, so the time-since-change line scores 0 (0 of 30). No dated changelog entries in the last 90 days (0 of 20). Responsiveness. A support address is published, agentzon-support@merit.systems, but replies were not tested because the brief allows only product listing reads. No changelog (5 of 15 for a closed service). No MCP registry entry under this operator. The official registry lists an unrelated server, xyz.agentzon/agentzon, from agentzon.xyz (0 of 15). No public repository, CI or SDK package was found (0 of 10). Total 5."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 45,
          "points": 3.94,
          "note": "editorial 35, provenance 55",
          "reason": "Closed service with published, dated terms that are clear on the merchant of record, the refund window and the exclusions (15 of 30). The privacy policy names the seller and Stripe, and says retention is as reasonably needed, with a 90-day period only for checkout diagnostics. Retailers and fulfilment providers are named by type, and the seller has no registered address on agentzon.co (12 of 30). No deprecation policy or dated notices were found (0 of 20). Telemetry is disclosed, including Vercel Web Analytics and checkout diagnostics such as IP address, screen size and automation signals, but no opt-out is stated. Stripe and Vercel are named, with no subprocessor list and no data locations (8 of 20). Total 35."
        }
      ],
      "assessment": {
        "date": "2026-10-10",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses can be limited (limit 1 to 100, offset) but not reduced field by field. The first 20 items of the unfiltered catalogue came to 15.5 KB, because each item carries its details (15 of 25). Pagination with offset and nextOffset, filters for category and brand, and four sort orders (20 of 20). Errors carry HTTP codes and a short message, and agents.md gives a recovery step for 400, 415, 409, 429 and network failure, but there are no error codes in the body (15 of 20). Idempotency-Key is required on checkout and catalogue suggestions, with safe-retry guidance (20 of 20). Sensible defaults (limit 20, sort featured) and one required field at checkout. No official SDKs, so the SDK half of the line is unmet (8 of 15). Total 78.",
          "maintenance": "No dated API release, changelog or version history was found. The policy pages carry an effective date of 8 October 2026, but those are changes to terms, not to the API, so the time-since-change line scores 0 (0 of 30). No dated changelog entries in the last 90 days (0 of 20). Responsiveness. A support address is published, agentzon-support@merit.systems, but replies were not tested because the brief allows only product listing reads. No changelog (5 of 15 for a closed service). No MCP registry entry under this operator. The official registry lists an unrelated server, xyz.agentzon/agentzon, from agentzon.xyz (0 of 15). No public repository, CI or SDK package was found (0 of 10). Total 5.",
          "payments": "No machine payment protocol (x402, MPP or L402) on any endpoint. UCP is a commerce protocol, and its checkout ends at the same payment page, so it earns nothing here (0 of 40). Item prices are published without a login through GET /api/products. 466 priced items from USD 0.99 to 149.99 on 10 October 2026. Prices exclude sales tax, which is added at checkout (20 of 20). No free tier, trial or test mode was found. Every product reports checkoutMode live (0 of 20). No account, registration or key is needed to search or to create a checkout, so an agent gets access without a signup flow (20 of 20). Total 40. The buyer still enters card details by hand, which the security note covers.",
          "reliability": "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status, each 404 on 10 October 2026, so the status page line scores 0 (0 of 20). No readable incident history exists, which takes the 5-point default (5 of 30). Catalogue reads have published figures, 120 a minute per process and client IP, with Retry-After on 429 (10 of 15). The checkout and order limits have no figure, so the line is not full. 429 handling is documented with Retry-After, and Idempotency-Key covers checkout retries, with retry guidance in agents.md (15 of 15). No SLA and no paid tier (0 of 10). The API is live and takes real payments, with checkoutMode live on all 500 products (10 of 10). Total 40.",
          "schema": "OpenAPI 3.1.0 at /openapi.json, valid JSON, with request and response schemas for every route (25 of 25). llms.txt at /llms.txt and agents.md in Markdown, both linked from the home page (10 of 10). The descriptions say when not to act. Creating a session is not payment, a paid status confirms payment and not shipment, a null price is unavailable and never free, and purchase needs the buyer's authorisation (18 of 20). No MCP tool definitions exist to read. Inputs are typed, with enums for category and sort, length limits, a pattern on Idempotency-Key and required items at checkout (15 of 15). Examples are given in curl and JSON. Responses are listed for 400, 404, 409 and 429, but the error body is one text field with no machine-readable code (10 of 15). The info block has version 1.0.0 and UCP is dated, but there is no public changelog and the URLs carry no version (5 of 15). Total 83.",
          "security": "Read endpoints and checkout creation take no credential (no points for a key model). The order token is a bearer secret that reads one order, never expires and cannot be revoked (15 of 30, between the 10 for one all-powerful key and the 20 for a revocable key). The checkout URL is a payment credential passed in the URL fragment, not the query string, so the 10-point deduction does not apply. Read-only and least-privilege. Catalogue reads and checkout creation cannot take money. The privacy policy says Stripe handles card details and the checkout application never receives them, and the API says never to send them to Agentzon, so an agent cannot pay alone (20 of 20). Prompt injection. The catalogue returns product names and descriptions written by the seller, and no guidance on treating them as data was found (5 of 15). Operator visibility. The buyer has no call log. Agentzon keeps checkout diagnostics for 90 days and aggregate request counters, which the buyer cannot see (5 of 15). Programme. security.txt returns 404, and no bug bounty, certification or advisory page was found (0 of 20). Total 45.",
          "transparency": "Closed service with published, dated terms that are clear on the merchant of record, the refund window and the exclusions (15 of 30). The privacy policy names the seller and Stripe, and says retention is as reasonably needed, with a 90-day period only for checkout diagnostics. Retailers and fulfilment providers are named by type, and the seller has no registered address on agentzon.co (12 of 30). No deprecation policy or dated notices were found (0 of 20). Telemetry is disclosed, including Vercel Web Analytics and checkout diagnostics such as IP address, screen size and automation signals, but no opt-out is stated. Stripe and Vercel are named, with no subprocessor list and no data locations (8 of 20). Total 35."
        },
        "sources": [
          {
            "what": "llms.txt, the agent reference",
            "url": "https://agentzon.co/llms.txt",
            "seen": "2026-10-10"
          },
          {
            "what": "agents.md, the agent quick start",
            "url": "https://agentzon.co/agents.md",
            "seen": "2026-10-10"
          },
          {
            "what": "OpenAPI 3.1 description",
            "url": "https://agentzon.co/openapi.json",
            "seen": "2026-10-10"
          },
          {
            "what": "auth.md",
            "url": "https://agentzon.co/auth.md",
            "seen": "2026-10-10"
          },
          {
            "what": "catalogue API, all 500 items in five pages of 100",
            "url": "https://agentzon.co/api/products?limit=100\u0026offset=0",
            "seen": "2026-10-10"
          },
          {
            "what": "home page, Markdown form",
            "url": "https://agentzon.co/",
            "seen": "2026-10-10"
          },
          {
            "what": "product page, Markdown form",
            "url": "https://agentzon.co/product/HH-0057",
            "seen": "2026-10-10"
          },
          {
            "what": "UCP business profile",
            "url": "https://agentzon.co/.well-known/ucp",
            "seen": "2026-10-10"
          },
          {
            "what": "API catalogue (RFC 9727)",
            "url": "https://agentzon.co/.well-known/api-catalog",
            "seen": "2026-10-10"
          },
          {
            "what": "robots.txt",
            "url": "https://agentzon.co/robots.txt",
            "seen": "2026-10-10"
          },
          {
            "what": "terms of sale",
            "url": "https://agentzon.co/terms",
            "seen": "2026-10-10"
          },
          {
            "what": "shipping and returns",
            "url": "https://agentzon.co/returns",
            "seen": "2026-10-10"
          },
          {
            "what": "privacy policy",
            "url": "https://agentzon.co/privacy",
            "seen": "2026-10-10"
          },
          {
            "what": "storefront script with the WebMCP tool registrations",
            "url": "https://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js",
            "seen": "2026-10-10"
          },
          {
            "what": "Merit Systems terms, legal entity and address",
            "url": "https://merit.systems/terms",
            "seen": "2026-10-10"
          },
          {
            "what": "Merit Systems home page",
            "url": "https://merit.systems",
            "seen": "2026-10-10"
          },
          {
            "what": "UCP announcements, governance and licence",
            "url": "https://ucp.dev/documentation/announcements/",
            "seen": "2026-10-10"
          },
          {
            "what": "UCP specification overview, version 2026-08-25",
            "url": "https://ucp.dev/2026-08-25/specification/overview/",
            "seen": "2026-10-10"
          },
          {
            "what": "official MCP registry search for agentzon, a different product",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=agentzon",
            "seen": "2026-10-10"
          },
          {
            "what": "security.txt probe, 404",
            "url": "https://agentzon.co/.well-known/security.txt",
            "seen": "2026-10-10"
          },
          {
            "what": "status page probe, 404",
            "url": "https://status.agentzon.co",
            "seen": "2026-10-10"
          }
        ],
        "openQuestions": [
          "unchecked: the checkout page at the returned URL, including its order summary, tax calculation and whether Stripe Link is offered. The brief allows only product listing reads, so no checkout was created.",
          "unchecked: Stripe Link. The founder's lead says checkout supports it. No mention appears in the pages or the storefront script read on 10 October 2026.",
          "unchecked: the UCP REST endpoint at https://agentzon.co/api/ucp. A GET returned 404 and no POST was sent, so catalogue search and checkout over UCP are untested.",
          "unchecked: the three WebMCP tools in a browser. They are registered in the storefront script when document.modelContext exists, but the script was read, not run.",
          "unchecked: a registered address, state of incorporation or company number for Merit Systems Inc or Merit Systems, Inc. Search returned no matching registry record.",
          "unchecked: the source retailers for the 500 items and whether any of them is Amazon. The footer says the site is not affiliated with Amazon.",
          "unchecked: support response times, refund timings in practice and delivery times. The support address was not emailed.",
          "unchecked: the domain registration date. RDAP for .co was unreachable.",
          "The sale label is applied to all 466 priced items, with no list or comparison price in the API. Whether a discount is shown on the product page was not checked.",
          "The catalogue count differs by source. llms.txt, openapi.json and the home page say 500 essentials, the API total is 500 and 466 are purchasable, and the rendered home page showed 466. The listing uses 466 for purchasable items.",
          "There is a name collision. A different product named agentzon (agentzon.xyz, a Solana skill marketplace) is in the official MCP registry as xyz.agentzon/agentzon. The slug agentzon may need a qualifier before this listing is merged."
        ]
      },
      "negative": 0,
      "verdict": "Public OpenAPI 3.1 description and llms.txt, with a whole-basket checkout that needs no account or key. The buyer pays on a private page, so a person completes each purchase. No status page, security.txt or registered seller address was found on agentzon.co, and 34 of 500 listed items cannot be bought.",
      "bestFor": "A shopping destination for an agent buying everyday household goods for a U.S. address.",
      "strengths": [
        "OpenAPI 3.1 description at /openapi.json, with enums, length limits, and documented 400, 404, 409 and 429 responses",
        "Whole basket in one checkout call, with an Idempotency-Key on checkout and on catalogue suggestions",
        "No account, registration or API key for search or checkout, and a read-only order token for payment status",
        "The buyer reviews the total and pays on a private checkout page, so an agent cannot charge the card itself",
        "Terms, returns and privacy pages name the seller, the refund window and a support address"
      ],
      "weaknesses": [
        "No status page, security.txt or disclosure contact was found. Each probe returned 404",
        "The terms name Merit Systems Inc as seller, but agentzon.co gives no registered address, state or company number",
        "Change-of-mind returns exclude food, medicines and personal hygiene items. Personal care is the largest department, with 107 of 500 items",
        "Source retailers are not named. The policies say only that third parties source and deliver orders",
        "The UCP endpoint advertised in the profile answered 404 to a GET, and the POST route was not tested"
      ],
      "agentNotes": [
        "Search with GET /api/products. Use only items with checkoutAvailable true and a non-null unitAmount, because a null price means unavailable, never free",
        "Send every item and quantity in one POST /api/checkout, with a new Idempotency-Key for each purchase attempt and the same key only to retry that basket",
        "Show the buyer the product image from /api/products/{id}/image and get their approval before opening the checkout URL",
        "Tell the buyer that catalogue prices exclude sales tax, that shipping is U.S. only and that change-of-mind returns exclude hygiene and food items",
        "Keep the checkout URL and the orderToken private. A paid status confirms payment, not shipment"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 51.4
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 5,
        "payments": 40,
        "reliability": 40,
        "schema": 83,
        "security": 45,
        "transparency": 35
      },
      "provenanceScore": 55
    },
    "connect": {
      "http": "curl \"https://agentzon.co/api/products?q=Colgate%20toothpaste\u0026limit=5\""
    },
    "letme": {
      "capability": "https://letme.dev/commerce.products",
      "tool": "https://letme.dev/agentzon"
    },
    "notable": [
      "The catalogue API reports 500 items, and 466 have a price and checkoutAvailable true. The other 34 have no price, are unavailable and cannot be bought (https://agentzon.co/api/products, read 10 October 2026)",
      "Seller and merchant of record is Merit Systems Inc, which also fulfils orders (https://agentzon.co/terms and https://agentzon.co/returns). merit.systems/terms names Merit Systems, Inc. and a New York address for legal notices, with no state of incorporation or company number (https://merit.systems/terms)",
      "Checkout returns a private URL and an orderId with an orderToken. The buyer reviews the order and pays there through a Stripe-embedded form, and the API says card numbers must never be sent to Agentzon (https://agentzon.co/agents.md and https://agentzon.co/auth.md). The checkout page itself was not opened, because the brief allows only product listing reads",
      "UCP 2026-08-25 is advertised at https://agentzon.co/.well-known/ucp with the REST endpoint https://agentzon.co/api/ucp, which answered 404 to a GET. The UCP protocol is Apache 2.0 licensed and governed by a Governing Council (https://ucp.dev/documentation/announcements/)",
      "WebMCP tools search_catalog, stage_cart_items and request_catalog_items are registered by the storefront script when document.modelContext exists. The script was read, not run in a browser (https://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js)",
      "The founder's lead says checkout supports Stripe Link. No Link mention was found in the pages or storefront script read on 10 October 2026",
      "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status (each 404 on 10 October 2026). No security.txt at /.well-known/security.txt (404)",
      "A different product named agentzon, at agentzon.xyz, is in the official MCP registry as xyz.agentzon/agentzon (https://registry.modelcontextprotocol.io/v0/servers?search=agentzon). It is not this listing"
    ],
    "area": "business",
    "details": [
      {
        "label": "Catalogue",
        "value": "500 items in the API on 10 October 2026, 13 categories, 204 brands. 466 items have a price and can be checked out. 34 have no price and are unavailable"
      },
      {
        "label": "Prices",
        "value": "USD 0.99 to 149.99 for the 466 priced items, median 7.49. Each item is marked priceStatus sale, and the API gives no list or comparison price. Catalogue prices exclude sales tax"
      },
      {
        "label": "Search",
        "value": "GET /api/products with q (up to 200 characters, all words must match), category, brand, sort (featured, low, high, az), limit (1 to 100) and offset. The response includes nextOffset and checkoutAvailable"
      },
      {
        "label": "Checkout",
        "value": "POST /api/checkout with items (maximum 50 distinct products, quantity 1 to 99), an Idempotency-Key of 16 to 100 characters, and optional email, phone, shipping and billing. Creating a session is not payment"
      },
      {
        "label": "Order status",
        "value": "GET /api/orders/{orderId} with the orderToken as a bearer token. Integer USD cents. Statuses pending, paid and expired. A paid status confirms payment, not shipment"
      },
      {
        "label": "Shipping",
        "value": "Free to U.S. addresses only, with a shipment timeframe of 3 to 5 days that is not a delivery guarantee. Merit Systems fulfils orders and gives tracking by email"
      },
      {
        "label": "Returns",
        "value": "Change-of-mind requests within 14 days of delivery for unopened items. Food, perishables, medicines and personal hygiene or intimate-use products are excluded. The buyer pays return postage. Refunds within 10 business days of inspection"
      },
      {
        "label": "Rate limits",
        "value": "Catalogue reads 120 a minute per process and client IP. Catalogue suggestions 10 a minute per client IP. Checkout and order limits in shared storage with no figure stated. HTTP 429 carries Retry-After"
      },
      {
        "label": "Discovery",
        "value": "llms.txt, agents.md, openapi.json, auth.md, /.well-known/api-catalog (RFC 9727), /.well-known/ucp, and Markdown for any page when the request asks for text/markdown"
      },
      {
        "label": "Images",
        "value": "GET /api/products/{id}/image returns image/webp. Checked on HH-0057 (19,974 bytes on 10 October 2026)"
      },
      {
        "label": "Data handling",
        "value": "Stripe takes card details on the checkout page. Vercel Web Analytics is used. Checkout diagnostics (IP address, headers, screen size, automation signals) are kept for 90 days. The cart is kept in the browser"
      },
      {
        "label": "Hosting and security headers",
        "value": "Served by Vercel with Strict-Transport-Security max-age 63072000. robots.txt sets Content-Signal ai-train=no. No security.txt"
      }
    ],
    "provenance": {
      "legalEntity": "Merit Systems Inc (agentzon.co terms); Merit Systems, Inc. (merit.systems terms)",
      "domain": "agentzon.co",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://agentzon.co/terms",
      "privacy": "https://agentzon.co/privacy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-10",
      "notes": [
        "agentzon.co/terms, returns and privacy are each dated 8 October 2026. They name Merit Systems Inc as operator, seller and merchant of record, with support at agentzon-support@merit.systems. None of the three gives a postal address.",
        "merit.systems/terms names Merit Systems, Inc. with a New York address for legal notices (224 West 35th Street, Ste 500 #2218, New York, NY 10001), New York governing law, and no state of incorporation or company number.",
        "/.well-known/security.txt and /security return 404 on agentzon.co. No changelog page was found at /changelog.",
        "The domain registration date could not be read. RDAP for .co was unreachable from the research environment."
      ],
      "score": 55,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Merit Systems Inc (agentzon.co terms); Merit Systems, Inc. (merit.systems terms)",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "agentzon.co, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "agentzon.co",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/agentzon.json",
    "live": {
      "slug": "agentzon",
      "probe": {
        "target": "https://agentzon.co/api",
        "method": "get",
        "lastAt": "2026-10-10T21:43:11.517465164Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 48,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 50,
        "p95ms24h": 128,
        "samples24h": 30,
        "samples30d": 30,
        "days": [
          {
            "date": "2026-10-10",
            "probes": 30,
            "ok": 30
          }
        ]
      },
      "pages": [
        {
          "url": "https://agentzon.co/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-10T18:56:43.075875783Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "de0595c6491b"
        },
        {
          "url": "https://agentzon.co/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-10T18:56:45.218708349Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "83db3205ec95"
        }
      ],
      "updatedAt": "2026-10-10T21:43:11.517465164Z"
    }
  }
}
