{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopify.json",
        "name": "Shopify API + MCP",
        "score": 75,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopify"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/woocommerce.json",
        "name": "WooCommerce API + MCP",
        "score": 72.9,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "woocommerce"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopware.json",
        "name": "Shopware",
        "score": 71.4,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopware"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/commercetools.json",
        "name": "commercetools",
        "score": 71.3,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "commercetools"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/vendure.json",
        "name": "Vendure",
        "score": 70.9,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "vendure"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/spree-commerce.json",
        "name": "Spree Commerce",
        "score": 70.4,
        "shared": [
          "commerce.products",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "spree-commerce"
      }
    ],
    "tool": {
      "slug": "agentzon",
      "name": "Agentzon",
      "vendor": "Merit Systems, Inc.",
      "vendorUrl": "https://agentzon.co",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Online store for household essentials that agents can search and buy from through a JSON API. Sells 466 purchasable items shipped within the U.S. by Merit Systems Inc, with payment on a private checkout page.",
      "url": "https://www.anchorterminal.com/tools/agentzon",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentzon.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentzon.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentzon.json",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://agentzon.co/api",
      "packages": [],
      "auth": "none",
      "authNotes": "No accounts, registration or API keys for search, product lookup or checkout creation. Order status takes a per-order bearer token (orderToken) issued by checkout. It is read-only, never expires and has no revocation endpoint. The UCP endpoint takes no credential and asks for a UCP-Agent header naming the platform profile (https://agentzon.co/auth.md).",
      "pricing": "usage",
      "pricingNotes": "The API has no fee and no plan. The buyer pays the item price per order, with sales tax added at checkout and free shipping to U.S. addresses. No free tier, trial or test mode was found. Every product reports checkoutMode live (checked 10 October 2026).",
      "priceSummary": "Pay per use",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in llms.txt, agents.md, openapi.json, auth.md or the storefront script (checked 10 October 2026).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-10"
      },
      "docsUrl": "https://agentzon.co/agents.md",
      "llmsTxt": "https://agentzon.co/llms.txt",
      "openapi": "https://agentzon.co/openapi.json",
      "capabilities": [
        "commerce.products",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "openapi",
        "llms-txt",
        "no-key",
        "no-signup",
        "webmcp",
        "ucp",
        "stripe",
        "us-only",
        "closed-source",
        "no-status-page",
        "sales-tax"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 51.4,
        "grade": "D",
        "agentReady": false,
        "rank": 753,
        "ranked": true,
        "rankOf": 955,
        "categoryRank": 16,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 5,
          "payments": 40,
          "reliability": 40,
          "schema": 83,
          "security": 45,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 40,
            "points": 8,
            "reason": "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status, each 404 on 10 October 2026, so the status page line scores 0 (0 of 20). No readable incident history exists, which takes the 5-point default (5 of 30). Catalogue reads have published figures, 120 a minute per process and client IP, with Retry-After on 429 (10 of 15). The checkout and order limits have no figure, so the line is not full. 429 handling is documented with Retry-After, and Idempotency-Key covers checkout retries, with retry guidance in agents.md (15 of 15). No SLA and no paid tier (0 of 10). The API is live and takes real payments, with checkoutMode live on all 500 products (10 of 10). Total 40."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 83,
            "points": 13.49,
            "reason": "OpenAPI 3.1.0 at /openapi.json, valid JSON, with request and response schemas for every route (25 of 25). llms.txt at /llms.txt and agents.md in Markdown, both linked from the home page (10 of 10). The descriptions say when not to act. Creating a session is not payment, a paid status confirms payment and not shipment, a null price is unavailable and never free, and purchase needs the buyer's authorisation (18 of 20). No MCP tool definitions exist to read. Inputs are typed, with enums for category and sort, length limits, a pattern on Idempotency-Key and required items at checkout (15 of 15). Examples are given in curl and JSON. Responses are listed for 400, 404, 409 and 429, but the error body is one text field with no machine-readable code (10 of 15). The info block has version 1.0.0 and UCP is dated, but there is no public changelog and the URLs carry no version (5 of 15). Total 83."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "Responses can be limited (limit 1 to 100, offset) but not reduced field by field. The first 20 items of the unfiltered catalogue came to 15.5 KB, because each item carries its details (15 of 25). Pagination with offset and nextOffset, filters for category and brand, and four sort orders (20 of 20). Errors carry HTTP codes and a short message, and agents.md gives a recovery step for 400, 415, 409, 429 and network failure, but there are no error codes in the body (15 of 20). Idempotency-Key is required on checkout and catalogue suggestions, with safe-retry guidance (20 of 20). Sensible defaults (limit 20, sort featured) and one required field at checkout. No official SDKs, so the SDK half of the line is unmet (8 of 15). Total 78."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 45,
            "points": 7.88,
            "reason": "Read endpoints and checkout creation take no credential (no points for a key model). The order token is a bearer secret that reads one order, never expires and cannot be revoked (15 of 30, between the 10 for one all-powerful key and the 20 for a revocable key). The checkout URL is a payment credential passed in the URL fragment, not the query string, so the 10-point deduction does not apply. Read-only and least-privilege. Catalogue reads and checkout creation cannot take money. The privacy policy says Stripe handles card details and the checkout application never receives them, and the API says never to send them to Agentzon, so an agent cannot pay alone (20 of 20). Prompt injection. The catalogue returns product names and descriptions written by the seller, and no guidance on treating them as data was found (5 of 15). Operator visibility. The buyer has no call log. Agentzon keeps checkout diagnostics for 90 days and aggregate request counters, which the buyer cannot see (5 of 15). Programme. security.txt returns 404, and no bug bounty, certification or advisory page was found (0 of 20). Total 45."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No machine payment protocol (x402, MPP or L402) on any endpoint. UCP is a commerce protocol, and its checkout ends at the same payment page, so it earns nothing here (0 of 40). Item prices are published without a login through GET /api/products. 466 priced items from USD 0.99 to 149.99 on 10 October 2026. Prices exclude sales tax, which is added at checkout (20 of 20). No free tier, trial or test mode was found. Every product reports checkoutMode live (0 of 20). No account, registration or key is needed to search or to create a checkout, so an agent gets access without a signup flow (20 of 20). Total 40. The buyer still enters card details by hand, which the security note covers."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 5,
            "points": 0.44,
            "reason": "No dated API release, changelog or version history was found. The policy pages carry an effective date of 8 October 2026, but those are changes to terms, not to the API, so the time-since-change line scores 0 (0 of 30). No dated changelog entries in the last 90 days (0 of 20). Responsiveness. A support address is published, agentzon-support@merit.systems, but replies were not tested because the brief allows only product listing reads. No changelog (5 of 15 for a closed service). No MCP registry entry under this operator. The official registry lists an unrelated server, xyz.agentzon/agentzon, from agentzon.xyz (0 of 15). No public repository, CI or SDK package was found (0 of 10). Total 5."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 45,
            "points": 3.94,
            "note": "editorial 35, provenance 55",
            "reason": "Closed service with published, dated terms that are clear on the merchant of record, the refund window and the exclusions (15 of 30). The privacy policy names the seller and Stripe, and says retention is as reasonably needed, with a 90-day period only for checkout diagnostics. Retailers and fulfilment providers are named by type, and the seller has no registered address on agentzon.co (12 of 30). No deprecation policy or dated notices were found (0 of 20). Telemetry is disclosed, including Vercel Web Analytics and checkout diagnostics such as IP address, screen size and automation signals, but no opt-out is stated. Stripe and Vercel are named, with no subprocessor list and no data locations (8 of 20). Total 35."
          }
        ],
        "assessment": {
          "date": "2026-10-10",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Responses can be limited (limit 1 to 100, offset) but not reduced field by field. The first 20 items of the unfiltered catalogue came to 15.5 KB, because each item carries its details (15 of 25). Pagination with offset and nextOffset, filters for category and brand, and four sort orders (20 of 20). Errors carry HTTP codes and a short message, and agents.md gives a recovery step for 400, 415, 409, 429 and network failure, but there are no error codes in the body (15 of 20). Idempotency-Key is required on checkout and catalogue suggestions, with safe-retry guidance (20 of 20). Sensible defaults (limit 20, sort featured) and one required field at checkout. No official SDKs, so the SDK half of the line is unmet (8 of 15). Total 78.",
            "maintenance": "No dated API release, changelog or version history was found. The policy pages carry an effective date of 8 October 2026, but those are changes to terms, not to the API, so the time-since-change line scores 0 (0 of 30). No dated changelog entries in the last 90 days (0 of 20). Responsiveness. A support address is published, agentzon-support@merit.systems, but replies were not tested because the brief allows only product listing reads. No changelog (5 of 15 for a closed service). No MCP registry entry under this operator. The official registry lists an unrelated server, xyz.agentzon/agentzon, from agentzon.xyz (0 of 15). No public repository, CI or SDK package was found (0 of 10). Total 5.",
            "payments": "No machine payment protocol (x402, MPP or L402) on any endpoint. UCP is a commerce protocol, and its checkout ends at the same payment page, so it earns nothing here (0 of 40). Item prices are published without a login through GET /api/products. 466 priced items from USD 0.99 to 149.99 on 10 October 2026. Prices exclude sales tax, which is added at checkout (20 of 20). No free tier, trial or test mode was found. Every product reports checkoutMode live (0 of 20). No account, registration or key is needed to search or to create a checkout, so an agent gets access without a signup flow (20 of 20). Total 40. The buyer still enters card details by hand, which the security note covers.",
            "reliability": "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status, each 404 on 10 October 2026, so the status page line scores 0 (0 of 20). No readable incident history exists, which takes the 5-point default (5 of 30). Catalogue reads have published figures, 120 a minute per process and client IP, with Retry-After on 429 (10 of 15). The checkout and order limits have no figure, so the line is not full. 429 handling is documented with Retry-After, and Idempotency-Key covers checkout retries, with retry guidance in agents.md (15 of 15). No SLA and no paid tier (0 of 10). The API is live and takes real payments, with checkoutMode live on all 500 products (10 of 10). Total 40.",
            "schema": "OpenAPI 3.1.0 at /openapi.json, valid JSON, with request and response schemas for every route (25 of 25). llms.txt at /llms.txt and agents.md in Markdown, both linked from the home page (10 of 10). The descriptions say when not to act. Creating a session is not payment, a paid status confirms payment and not shipment, a null price is unavailable and never free, and purchase needs the buyer's authorisation (18 of 20). No MCP tool definitions exist to read. Inputs are typed, with enums for category and sort, length limits, a pattern on Idempotency-Key and required items at checkout (15 of 15). Examples are given in curl and JSON. Responses are listed for 400, 404, 409 and 429, but the error body is one text field with no machine-readable code (10 of 15). The info block has version 1.0.0 and UCP is dated, but there is no public changelog and the URLs carry no version (5 of 15). Total 83.",
            "security": "Read endpoints and checkout creation take no credential (no points for a key model). The order token is a bearer secret that reads one order, never expires and cannot be revoked (15 of 30, between the 10 for one all-powerful key and the 20 for a revocable key). The checkout URL is a payment credential passed in the URL fragment, not the query string, so the 10-point deduction does not apply. Read-only and least-privilege. Catalogue reads and checkout creation cannot take money. The privacy policy says Stripe handles card details and the checkout application never receives them, and the API says never to send them to Agentzon, so an agent cannot pay alone (20 of 20). Prompt injection. The catalogue returns product names and descriptions written by the seller, and no guidance on treating them as data was found (5 of 15). Operator visibility. The buyer has no call log. Agentzon keeps checkout diagnostics for 90 days and aggregate request counters, which the buyer cannot see (5 of 15). Programme. security.txt returns 404, and no bug bounty, certification or advisory page was found (0 of 20). Total 45.",
            "transparency": "Closed service with published, dated terms that are clear on the merchant of record, the refund window and the exclusions (15 of 30). The privacy policy names the seller and Stripe, and says retention is as reasonably needed, with a 90-day period only for checkout diagnostics. Retailers and fulfilment providers are named by type, and the seller has no registered address on agentzon.co (12 of 30). No deprecation policy or dated notices were found (0 of 20). Telemetry is disclosed, including Vercel Web Analytics and checkout diagnostics such as IP address, screen size and automation signals, but no opt-out is stated. Stripe and Vercel are named, with no subprocessor list and no data locations (8 of 20). Total 35."
          },
          "sources": [
            {
              "what": "llms.txt, the agent reference",
              "url": "https://agentzon.co/llms.txt",
              "seen": "2026-10-10"
            },
            {
              "what": "agents.md, the agent quick start",
              "url": "https://agentzon.co/agents.md",
              "seen": "2026-10-10"
            },
            {
              "what": "OpenAPI 3.1 description",
              "url": "https://agentzon.co/openapi.json",
              "seen": "2026-10-10"
            },
            {
              "what": "auth.md",
              "url": "https://agentzon.co/auth.md",
              "seen": "2026-10-10"
            },
            {
              "what": "catalogue API, all 500 items in five pages of 100",
              "url": "https://agentzon.co/api/products?limit=100\u0026offset=0",
              "seen": "2026-10-10"
            },
            {
              "what": "home page, Markdown form",
              "url": "https://agentzon.co/",
              "seen": "2026-10-10"
            },
            {
              "what": "product page, Markdown form",
              "url": "https://agentzon.co/product/HH-0057",
              "seen": "2026-10-10"
            },
            {
              "what": "UCP business profile",
              "url": "https://agentzon.co/.well-known/ucp",
              "seen": "2026-10-10"
            },
            {
              "what": "API catalogue (RFC 9727)",
              "url": "https://agentzon.co/.well-known/api-catalog",
              "seen": "2026-10-10"
            },
            {
              "what": "robots.txt",
              "url": "https://agentzon.co/robots.txt",
              "seen": "2026-10-10"
            },
            {
              "what": "terms of sale",
              "url": "https://agentzon.co/terms",
              "seen": "2026-10-10"
            },
            {
              "what": "shipping and returns",
              "url": "https://agentzon.co/returns",
              "seen": "2026-10-10"
            },
            {
              "what": "privacy policy",
              "url": "https://agentzon.co/privacy",
              "seen": "2026-10-10"
            },
            {
              "what": "storefront script with the WebMCP tool registrations",
              "url": "https://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js",
              "seen": "2026-10-10"
            },
            {
              "what": "Merit Systems terms, legal entity and address",
              "url": "https://merit.systems/terms",
              "seen": "2026-10-10"
            },
            {
              "what": "Merit Systems home page",
              "url": "https://merit.systems",
              "seen": "2026-10-10"
            },
            {
              "what": "UCP announcements, governance and licence",
              "url": "https://ucp.dev/documentation/announcements/",
              "seen": "2026-10-10"
            },
            {
              "what": "UCP specification overview, version 2026-08-25",
              "url": "https://ucp.dev/2026-08-25/specification/overview/",
              "seen": "2026-10-10"
            },
            {
              "what": "official MCP registry search for agentzon, a different product",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=agentzon",
              "seen": "2026-10-10"
            },
            {
              "what": "security.txt probe, 404",
              "url": "https://agentzon.co/.well-known/security.txt",
              "seen": "2026-10-10"
            },
            {
              "what": "status page probe, 404",
              "url": "https://status.agentzon.co",
              "seen": "2026-10-10"
            }
          ],
          "openQuestions": [
            "unchecked: the checkout page at the returned URL, including its order summary, tax calculation and whether Stripe Link is offered. The brief allows only product listing reads, so no checkout was created.",
            "unchecked: Stripe Link. The founder's lead says checkout supports it. No mention appears in the pages or the storefront script read on 10 October 2026.",
            "unchecked: the UCP REST endpoint at https://agentzon.co/api/ucp. A GET returned 404 and no POST was sent, so catalogue search and checkout over UCP are untested.",
            "unchecked: the three WebMCP tools in a browser. They are registered in the storefront script when document.modelContext exists, but the script was read, not run.",
            "unchecked: a registered address, state of incorporation or company number for Merit Systems Inc or Merit Systems, Inc. Search returned no matching registry record.",
            "unchecked: the source retailers for the 500 items and whether any of them is Amazon. The footer says the site is not affiliated with Amazon.",
            "unchecked: support response times, refund timings in practice and delivery times. The support address was not emailed.",
            "unchecked: the domain registration date. RDAP for .co was unreachable.",
            "The sale label is applied to all 466 priced items, with no list or comparison price in the API. Whether a discount is shown on the product page was not checked.",
            "The catalogue count differs by source. llms.txt, openapi.json and the home page say 500 essentials, the API total is 500 and 466 are purchasable, and the rendered home page showed 466. The listing uses 466 for purchasable items.",
            "There is a name collision. A different product named agentzon (agentzon.xyz, a Solana skill marketplace) is in the official MCP registry as xyz.agentzon/agentzon. The slug agentzon may need a qualifier before this listing is merged."
          ]
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.1 description and llms.txt, with a whole-basket checkout that needs no account or key. The buyer pays on a private page, so a person completes each purchase. No status page, security.txt or registered seller address was found on agentzon.co, and 34 of 500 listed items cannot be bought.",
        "bestFor": "A shopping destination for an agent buying everyday household goods for a U.S. address.",
        "strengths": [
          "OpenAPI 3.1 description at /openapi.json, with enums, length limits, and documented 400, 404, 409 and 429 responses",
          "Whole basket in one checkout call, with an Idempotency-Key on checkout and on catalogue suggestions",
          "No account, registration or API key for search or checkout, and a read-only order token for payment status",
          "The buyer reviews the total and pays on a private checkout page, so an agent cannot charge the card itself",
          "Terms, returns and privacy pages name the seller, the refund window and a support address"
        ],
        "weaknesses": [
          "No status page, security.txt or disclosure contact was found. Each probe returned 404",
          "The terms name Merit Systems Inc as seller, but agentzon.co gives no registered address, state or company number",
          "Change-of-mind returns exclude food, medicines and personal hygiene items. Personal care is the largest department, with 107 of 500 items",
          "Source retailers are not named. The policies say only that third parties source and deliver orders",
          "The UCP endpoint advertised in the profile answered 404 to a GET, and the POST route was not tested"
        ],
        "agentNotes": [
          "Search with GET /api/products. Use only items with checkoutAvailable true and a non-null unitAmount, because a null price means unavailable, never free",
          "Send every item and quantity in one POST /api/checkout, with a new Idempotency-Key for each purchase attempt and the same key only to retry that basket",
          "Show the buyer the product image from /api/products/{id}/image and get their approval before opening the checkout URL",
          "Tell the buyer that catalogue prices exclude sales tax, that shipping is U.S. only and that change-of-mind returns exclude hygiene and food items",
          "Keep the checkout URL and the orderToken private. A paid status confirms payment, not shipment"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 51.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 5,
          "payments": 40,
          "reliability": 40,
          "schema": 83,
          "security": 45,
          "transparency": 35
        },
        "provenanceScore": 55
      },
      "connect": {
        "http": "curl \"https://agentzon.co/api/products?q=Colgate%20toothpaste\u0026limit=5\""
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/agentzon"
      },
      "notable": [
        "The catalogue API reports 500 items, and 466 have a price and checkoutAvailable true. The other 34 have no price, are unavailable and cannot be bought (https://agentzon.co/api/products, read 10 October 2026)",
        "Seller and merchant of record is Merit Systems Inc, which also fulfils orders (https://agentzon.co/terms and https://agentzon.co/returns). merit.systems/terms names Merit Systems, Inc. and a New York address for legal notices, with no state of incorporation or company number (https://merit.systems/terms)",
        "Checkout returns a private URL and an orderId with an orderToken. The buyer reviews the order and pays there through a Stripe-embedded form, and the API says card numbers must never be sent to Agentzon (https://agentzon.co/agents.md and https://agentzon.co/auth.md). The checkout page itself was not opened, because the brief allows only product listing reads",
        "UCP 2026-08-25 is advertised at https://agentzon.co/.well-known/ucp with the REST endpoint https://agentzon.co/api/ucp, which answered 404 to a GET. The UCP protocol is Apache 2.0 licensed and governed by a Governing Council (https://ucp.dev/documentation/announcements/)",
        "WebMCP tools search_catalog, stage_cart_items and request_catalog_items are registered by the storefront script when document.modelContext exists. The script was read, not run in a browser (https://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js)",
        "The founder's lead says checkout supports Stripe Link. No Link mention was found in the pages or storefront script read on 10 October 2026",
        "No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status (each 404 on 10 October 2026). No security.txt at /.well-known/security.txt (404)",
        "A different product named agentzon, at agentzon.xyz, is in the official MCP registry as xyz.agentzon/agentzon (https://registry.modelcontextprotocol.io/v0/servers?search=agentzon). It is not this listing"
      ],
      "area": "business",
      "details": [
        {
          "label": "Catalogue",
          "value": "500 items in the API on 10 October 2026, 13 categories, 204 brands. 466 items have a price and can be checked out. 34 have no price and are unavailable"
        },
        {
          "label": "Prices",
          "value": "USD 0.99 to 149.99 for the 466 priced items, median 7.49. Each item is marked priceStatus sale, and the API gives no list or comparison price. Catalogue prices exclude sales tax"
        },
        {
          "label": "Search",
          "value": "GET /api/products with q (up to 200 characters, all words must match), category, brand, sort (featured, low, high, az), limit (1 to 100) and offset. The response includes nextOffset and checkoutAvailable"
        },
        {
          "label": "Checkout",
          "value": "POST /api/checkout with items (maximum 50 distinct products, quantity 1 to 99), an Idempotency-Key of 16 to 100 characters, and optional email, phone, shipping and billing. Creating a session is not payment"
        },
        {
          "label": "Order status",
          "value": "GET /api/orders/{orderId} with the orderToken as a bearer token. Integer USD cents. Statuses pending, paid and expired. A paid status confirms payment, not shipment"
        },
        {
          "label": "Shipping",
          "value": "Free to U.S. addresses only, with a shipment timeframe of 3 to 5 days that is not a delivery guarantee. Merit Systems fulfils orders and gives tracking by email"
        },
        {
          "label": "Returns",
          "value": "Change-of-mind requests within 14 days of delivery for unopened items. Food, perishables, medicines and personal hygiene or intimate-use products are excluded. The buyer pays return postage. Refunds within 10 business days of inspection"
        },
        {
          "label": "Rate limits",
          "value": "Catalogue reads 120 a minute per process and client IP. Catalogue suggestions 10 a minute per client IP. Checkout and order limits in shared storage with no figure stated. HTTP 429 carries Retry-After"
        },
        {
          "label": "Discovery",
          "value": "llms.txt, agents.md, openapi.json, auth.md, /.well-known/api-catalog (RFC 9727), /.well-known/ucp, and Markdown for any page when the request asks for text/markdown"
        },
        {
          "label": "Images",
          "value": "GET /api/products/{id}/image returns image/webp. Checked on HH-0057 (19,974 bytes on 10 October 2026)"
        },
        {
          "label": "Data handling",
          "value": "Stripe takes card details on the checkout page. Vercel Web Analytics is used. Checkout diagnostics (IP address, headers, screen size, automation signals) are kept for 90 days. The cart is kept in the browser"
        },
        {
          "label": "Hosting and security headers",
          "value": "Served by Vercel with Strict-Transport-Security max-age 63072000. robots.txt sets Content-Signal ai-train=no. No security.txt"
        }
      ],
      "provenance": {
        "legalEntity": "Merit Systems Inc (agentzon.co terms); Merit Systems, Inc. (merit.systems terms)",
        "domain": "agentzon.co",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://agentzon.co/terms",
        "privacy": "https://agentzon.co/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-10",
        "notes": [
          "agentzon.co/terms, returns and privacy are each dated 8 October 2026. They name Merit Systems Inc as operator, seller and merchant of record, with support at agentzon-support@merit.systems. None of the three gives a postal address.",
          "merit.systems/terms names Merit Systems, Inc. with a New York address for legal notices (224 West 35th Street, Ste 500 #2218, New York, NY 10001), New York governing law, and no state of incorporation or company number.",
          "/.well-known/security.txt and /security return 404 on agentzon.co. No changelog page was found at /changelog.",
          "The domain registration date could not be read. RDAP for .co was unreachable from the research environment."
        ],
        "score": 55,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Merit Systems Inc (agentzon.co terms); Merit Systems, Inc. (merit.systems terms)",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "agentzon.co, no registry record we could read",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "agentzon.co",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentzon.json",
      "live": {
        "slug": "agentzon",
        "probe": {
          "target": "https://agentzon.co/api",
          "method": "get",
          "lastAt": "2026-10-10T21:43:11.517465164Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 48,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 50,
          "p95ms24h": 128,
          "samples24h": 30,
          "samples30d": 30,
          "days": [
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "pages": [
          {
            "url": "https://agentzon.co/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-10T18:56:43.075875783Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de0595c6491b"
          },
          {
            "url": "https://agentzon.co/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-10T18:56:45.218708349Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "83db3205ec95"
          }
        ],
        "updatedAt": "2026-10-10T21:43:11.517465164Z"
      }
    },
    "verify": {
      "accepts": "a page on agentzon.co or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/agentzon.svg",
      "body": {
        "slug": "agentzon",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/agentzon",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/agentzon\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agentzon.svg\" alt=\"Agentzon on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Agentzon on Anchor Terminal](https://www.anchorterminal.com/badges/agentzon.svg)](https://www.anchorterminal.com/tools/agentzon)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/agentzon\"\u003eAgentzon on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/agentzon",
    "json": "https://www.anchorterminal.com/tools/agentzon.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/agentzon.md",
    "slim": "https://www.anchorterminal.com/tools/agentzon.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 51.4/100 · rank #753 of 955 · #16 in Commerce \u0026 checkout · not agent-ready · confidence medium**\n\n\n## Assessment\n\nPublic OpenAPI 3.1 description and llms.txt, with a whole-basket checkout that needs no account or key. The buyer pays on a private page, so a person completes each purchase. No status page, security.txt or registered seller address was found on agentzon.co, and 34 of 500 listed items cannot be bought.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Merit Systems, Inc. (https://agentzon.co) |\n| Kind | HTTP API |\n| Category | Commerce \u0026 checkout (https://www.anchorterminal.com/categories/commerce) |\n| Transport | HTTP |\n| Endpoint | `https://agentzon.co/api` |\n| Auth | None · No accounts, registration or API keys for search, product lookup or checkout creation. Order status takes a per-order bearer token (orderToken) issued by checkout. It is read-only, never expires and has no revocation endpoint. The UCP endpoint takes no credential and asks for a UCP-Agent header naming the platform profile (https://agentzon.co/auth.md). |\n| Pricing | Pay per use (Pay per use) · The API has no fee and no plan. The buyer pays the item price per order, with sales tax added at checkout and free shipping to U.S. addresses. No free tier, trial or test mode was found. Every product reports checkoutMode live (checked 10 October 2026). |\n| x402 | No · No x402, MPP or L402 in llms.txt, agents.md, openapi.json, auth.md or the storefront script (checked 10 October 2026). |\n| Licence | unknown |\n| Docs | https://agentzon.co/agents.md |\n| llms.txt | https://agentzon.co/llms.txt |\n| Catalogue | 500 items in the API on 10 October 2026, 13 categories, 204 brands. 466 items have a price and can be checked out. 34 have no price and are unavailable |\n| Prices | USD 0.99 to 149.99 for the 466 priced items, median 7.49. Each item is marked priceStatus sale, and the API gives no list or comparison price. Catalogue prices exclude sales tax |\n| Search | GET /api/products with q (up to 200 characters, all words must match), category, brand, sort (featured, low, high, az), limit (1 to 100) and offset. The response includes nextOffset and checkoutAvailable |\n| Checkout | POST /api/checkout with items (maximum 50 distinct products, quantity 1 to 99), an Idempotency-Key of 16 to 100 characters, and optional email, phone, shipping and billing. Creating a session is not payment |\n| Order status | GET /api/orders/{orderId} with the orderToken as a bearer token. Integer USD cents. Statuses pending, paid and expired. A paid status confirms payment, not shipment |\n| Shipping | Free to U.S. addresses only, with a shipment timeframe of 3 to 5 days that is not a delivery guarantee. Merit Systems fulfils orders and gives tracking by email |\n| Returns | Change-of-mind requests within 14 days of delivery for unopened items. Food, perishables, medicines and personal hygiene or intimate-use products are excluded. The buyer pays return postage. Refunds within 10 business days of inspection |\n| Rate limits | Catalogue reads 120 a minute per process and client IP. Catalogue suggestions 10 a minute per client IP. Checkout and order limits in shared storage with no figure stated. HTTP 429 carries Retry-After |\n| Discovery | llms.txt, agents.md, openapi.json, auth.md, /.well-known/api-catalog (RFC 9727), /.well-known/ucp, and Markdown for any page when the request asks for text/markdown |\n| Images | GET /api/products/{id}/image returns image/webp. Checked on HH-0057 (19,974 bytes on 10 October 2026) |\n| Data handling | Stripe takes card details on the checkout page. Vercel Web Analytics is used. Checkout diagnostics (IP address, headers, screen size, automation signals) are kept for 90 days. The cart is kept in the browser |\n| Hosting and security headers | Served by Vercel with Strict-Transport-Security max-age 63072000. robots.txt sets Content-Signal ai-train=no. No security.txt |\n| Capabilities | commerce.products, commerce.checkout, commerce.orders, commerce.headless |\n| Tags | hosted, openapi, llms-txt, no-key, no-signup, webmcp, ucp, stripe, us-only, closed-source, no-status-page, sales-tax |\n| JSON | https://www.anchorterminal.com/api/v1/tools/agentzon.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-10 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 40 | 8.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 83 | 13.5 |\n| Agent ergonomics | 13% | 16.2 | 78 | 12.7 |\n| Security \u0026 auth | 14% | 17.5 | 45 | 7.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 5 | 0.4 |\n| Transparency \u0026 trust (editorial 35, provenance 55) | 7% | 8.8 | 45 | 3.9 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **51.4 → D** |\n\n### Why each score\n\n- Reliability 40: No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status, each 404 on 10 October 2026, so the status page line scores 0 (0 of 20). No readable incident history exists, which takes the 5-point default (5 of 30). Catalogue reads have published figures, 120 a minute per process and client IP, with Retry-After on 429 (10 of 15). The checkout and order limits have no figure, so the line is not full. 429 handling is documented with Retry-After, and Idempotency-Key covers checkout retries, with retry guidance in agents.md (15 of 15). No SLA and no paid tier (0 of 10). The API is live and takes real payments, with checkoutMode live on all 500 products (10 of 10). Total 40.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 83: OpenAPI 3.1.0 at /openapi.json, valid JSON, with request and response schemas for every route (25 of 25). llms.txt at /llms.txt and agents.md in Markdown, both linked from the home page (10 of 10). The descriptions say when not to act. Creating a session is not payment, a paid status confirms payment and not shipment, a null price is unavailable and never free, and purchase needs the buyer's authorisation (18 of 20). No MCP tool definitions exist to read. Inputs are typed, with enums for category and sort, length limits, a pattern on Idempotency-Key and required items at checkout (15 of 15). Examples are given in curl and JSON. Responses are listed for 400, 404, 409 and 429, but the error body is one text field with no machine-readable code (10 of 15). The info block has version 1.0.0 and UCP is dated, but there is no public changelog and the URLs carry no version (5 of 15). Total 83.\n- Agent ergonomics 78: Responses can be limited (limit 1 to 100, offset) but not reduced field by field. The first 20 items of the unfiltered catalogue came to 15.5 KB, because each item carries its details (15 of 25). Pagination with offset and nextOffset, filters for category and brand, and four sort orders (20 of 20). Errors carry HTTP codes and a short message, and agents.md gives a recovery step for 400, 415, 409, 429 and network failure, but there are no error codes in the body (15 of 20). Idempotency-Key is required on checkout and catalogue suggestions, with safe-retry guidance (20 of 20). Sensible defaults (limit 20, sort featured) and one required field at checkout. No official SDKs, so the SDK half of the line is unmet (8 of 15). Total 78.\n- Security \u0026 auth 45: Read endpoints and checkout creation take no credential (no points for a key model). The order token is a bearer secret that reads one order, never expires and cannot be revoked (15 of 30, between the 10 for one all-powerful key and the 20 for a revocable key). The checkout URL is a payment credential passed in the URL fragment, not the query string, so the 10-point deduction does not apply. Read-only and least-privilege. Catalogue reads and checkout creation cannot take money. The privacy policy says Stripe handles card details and the checkout application never receives them, and the API says never to send them to Agentzon, so an agent cannot pay alone (20 of 20). Prompt injection. The catalogue returns product names and descriptions written by the seller, and no guidance on treating them as data was found (5 of 15). Operator visibility. The buyer has no call log. Agentzon keeps checkout diagnostics for 90 days and aggregate request counters, which the buyer cannot see (5 of 15). Programme. security.txt returns 404, and no bug bounty, certification or advisory page was found (0 of 20). Total 45.\n- Payments \u0026 pricing 40: No machine payment protocol (x402, MPP or L402) on any endpoint. UCP is a commerce protocol, and its checkout ends at the same payment page, so it earns nothing here (0 of 40). Item prices are published without a login through GET /api/products. 466 priced items from USD 0.99 to 149.99 on 10 October 2026. Prices exclude sales tax, which is added at checkout (20 of 20). No free tier, trial or test mode was found. Every product reports checkoutMode live (0 of 20). No account, registration or key is needed to search or to create a checkout, so an agent gets access without a signup flow (20 of 20). Total 40. The buyer still enters card details by hand, which the security note covers.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 5: No dated API release, changelog or version history was found. The policy pages carry an effective date of 8 October 2026, but those are changes to terms, not to the API, so the time-since-change line scores 0 (0 of 30). No dated changelog entries in the last 90 days (0 of 20). Responsiveness. A support address is published, agentzon-support@merit.systems, but replies were not tested because the brief allows only product listing reads. No changelog (5 of 15 for a closed service). No MCP registry entry under this operator. The official registry lists an unrelated server, xyz.agentzon/agentzon, from agentzon.xyz (0 of 15). No public repository, CI or SDK package was found (0 of 10). Total 5.\n- Transparency \u0026 trust 45: Closed service with published, dated terms that are clear on the merchant of record, the refund window and the exclusions (15 of 30). The privacy policy names the seller and Stripe, and says retention is as reasonably needed, with a 90-day period only for checkout diagnostics. Retailers and fulfilment providers are named by type, and the seller has no registered address on agentzon.co (12 of 30). No deprecation policy or dated notices were found (0 of 20). Telemetry is disclosed, including Vercel Web Analytics and checkout diagnostics such as IP address, screen size and automation signals, but no opt-out is stated. Stripe and Vercel are named, with no subprocessor list and no data locations (8 of 20). Total 35.\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/agentzon.md (JSON https://www.anchorterminal.com/fixes/agentzon.json)\n\n### What we couldn't check\n\n- unchecked: the checkout page at the returned URL, including its order summary, tax calculation and whether Stripe Link is offered. The brief allows only product listing reads, so no checkout was created.\n- unchecked: Stripe Link. The founder's lead says checkout supports it. No mention appears in the pages or the storefront script read on 10 October 2026.\n- unchecked: the UCP REST endpoint at https://agentzon.co/api/ucp. A GET returned 404 and no POST was sent, so catalogue search and checkout over UCP are untested.\n- unchecked: the three WebMCP tools in a browser. They are registered in the storefront script when document.modelContext exists, but the script was read, not run.\n- unchecked: a registered address, state of incorporation or company number for Merit Systems Inc or Merit Systems, Inc. Search returned no matching registry record.\n- unchecked: the source retailers for the 500 items and whether any of them is Amazon. The footer says the site is not affiliated with Amazon.\n- unchecked: support response times, refund timings in practice and delivery times. The support address was not emailed.\n- unchecked: the domain registration date. RDAP for .co was unreachable.\n- The sale label is applied to all 466 priced items, with no list or comparison price in the API. Whether a discount is shown on the product page was not checked.\n- The catalogue count differs by source. llms.txt, openapi.json and the home page say 500 essentials, the API total is 500 and 466 are purchasable, and the rendered home page showed 466. The listing uses 466 for purchasable items.\n- There is a name collision. A different product named agentzon (agentzon.xyz, a Solana skill marketplace) is in the official MCP registry as xyz.agentzon/agentzon. The slug agentzon may need a qualifier before this listing is merged.\n\n### Sources\n\n- llms.txt, the agent reference: \u003chttps://agentzon.co/llms.txt\u003e (seen 2026-10-10)\n- agents.md, the agent quick start: \u003chttps://agentzon.co/agents.md\u003e (seen 2026-10-10)\n- OpenAPI 3.1 description: \u003chttps://agentzon.co/openapi.json\u003e (seen 2026-10-10)\n- auth.md: \u003chttps://agentzon.co/auth.md\u003e (seen 2026-10-10)\n- catalogue API, all 500 items in five pages of 100: \u003chttps://agentzon.co/api/products?limit=100\u0026offset=0\u003e (seen 2026-10-10)\n- home page, Markdown form: \u003chttps://agentzon.co/\u003e (seen 2026-10-10)\n- product page, Markdown form: \u003chttps://agentzon.co/product/HH-0057\u003e (seen 2026-10-10)\n- UCP business profile: \u003chttps://agentzon.co/.well-known/ucp\u003e (seen 2026-10-10)\n- API catalogue (RFC 9727): \u003chttps://agentzon.co/.well-known/api-catalog\u003e (seen 2026-10-10)\n- robots.txt: \u003chttps://agentzon.co/robots.txt\u003e (seen 2026-10-10)\n- terms of sale: \u003chttps://agentzon.co/terms\u003e (seen 2026-10-10)\n- shipping and returns: \u003chttps://agentzon.co/returns\u003e (seen 2026-10-10)\n- privacy policy: \u003chttps://agentzon.co/privacy\u003e (seen 2026-10-10)\n- storefront script with the WebMCP tool registrations: \u003chttps://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js\u003e (seen 2026-10-10)\n- Merit Systems terms, legal entity and address: \u003chttps://merit.systems/terms\u003e (seen 2026-10-10)\n- Merit Systems home page: \u003chttps://merit.systems\u003e (seen 2026-10-10)\n- UCP announcements, governance and licence: \u003chttps://ucp.dev/documentation/announcements/\u003e (seen 2026-10-10)\n- UCP specification overview, version 2026-08-25: \u003chttps://ucp.dev/2026-08-25/specification/overview/\u003e (seen 2026-10-10)\n- official MCP registry search for agentzon, a different product: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=agentzon\u003e (seen 2026-10-10)\n- security.txt probe, 404: \u003chttps://agentzon.co/.well-known/security.txt\u003e (seen 2026-10-10)\n- status page probe, 404: \u003chttps://status.agentzon.co\u003e (seen 2026-10-10)\n\n## Who's behind it (provenance 55/100, checked 2026-10-10)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Merit Systems Inc (agentzon.co terms); Merit Systems, Inc. (merit.systems terms) | 20/20 |\n| Domain age | agentzon.co, no registry record we could read | 0/15 |\n| Endpoint on the vendor's domain | agentzon.co | 15/15 |\n| Terms of service | published | 10/10 |\n| Privacy policy | published | 10/10 |\n| Status page | not found | 0/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nagentzon.co/terms, returns and privacy are each dated 8 October 2026. They name Merit Systems Inc as operator, seller and merchant of record, with support at agentzon-support@merit.systems. None of the three gives a postal address.\n\nmerit.systems/terms names Merit Systems, Inc. with a New York address for legal notices (224 West 35th Street, Ste 500 #2218, New York, NY 10001), New York governing law, and no state of incorporation or company number.\n\n/.well-known/security.txt and /security return 404 on agentzon.co. No changelog page was found at /changelog.\n\nThe domain registration date could not be read. RDAP for .co was unreachable from the research environment.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://agentzon.co/terms), not read yet.\n\n\n**Privacy policy** (https://agentzon.co/privacy), not read yet.\n\n\n## Live (updated 2026-10-10 21:43 UTC)\n\n- Right now: up, HTTP 404, 48 ms, checked 2026-10-10 21:43 UTC (get on `https://agentzon.co/api`)\n- Uptime 24h 100.0% (30 probes) · 30 days 100.0% (30 probes) · p50 50 ms · p95 128 ms\n- Watching privacy \u003chttps://agentzon.co/privacy\u003e\n- Watching terms \u003chttps://agentzon.co/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/agentzon.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- OpenAPI 3.1 description at /openapi.json, with enums, length limits, and documented 400, 404, 409 and 429 responses\n- Whole basket in one checkout call, with an Idempotency-Key on checkout and on catalogue suggestions\n- No account, registration or API key for search or checkout, and a read-only order token for payment status\n- The buyer reviews the total and pays on a private checkout page, so an agent cannot charge the card itself\n- Terms, returns and privacy pages name the seller, the refund window and a support address\n\n## Weaknesses\n\n- No status page, security.txt or disclosure contact was found. Each probe returned 404\n- The terms name Merit Systems Inc as seller, but agentzon.co gives no registered address, state or company number\n- Change-of-mind returns exclude food, medicines and personal hygiene items. Personal care is the largest department, with 107 of 500 items\n- Source retailers are not named. The policies say only that third parties source and deliver orders\n- The UCP endpoint advertised in the profile answered 404 to a GET, and the POST route was not tested\n\n## Before you call it (notes for agents)\n\n1. Search with GET /api/products. Use only items with checkoutAvailable true and a non-null unitAmount, because a null price means unavailable, never free\n2. Send every item and quantity in one POST /api/checkout, with a new Idempotency-Key for each purchase attempt and the same key only to retry that basket\n3. Show the buyer the product image from /api/products/{id}/image and get their approval before opening the checkout URL\n4. Tell the buyer that catalogue prices exclude sales tax, that shipping is U.S. only and that change-of-mind returns exclude hygiene and food items\n5. Keep the checkout URL and the orderToken private. A paid status confirms payment, not shipment\n\n## Connect\n\nFirst request:\n\n```bash\ncurl \"https://agentzon.co/api/products?q=Colgate%20toothpaste\u0026limit=5\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/agentzon. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Shopify API + MCP | BB | 75 | 58 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopify.md |\n| WooCommerce API + MCP | BB | 72.9 | 97 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/woocommerce.md |\n| Shopware | BB | 71.4 | 128 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopware.md |\n| commercetools | BB | 71.3 | 132 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/commercetools.md |\n| Vendure | BB | 70.9 | 139 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/vendure.md |\n| Spree Commerce | BB | 70.4 | 154 | commerce.products, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/spree-commerce.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The catalogue API reports 500 items, and 466 have a price and checkoutAvailable true. The other 34 have no price, are unavailable and cannot be bought (source: \u003chttps://agentzon.co/api/products, read 10 October 2026\u003e)\n- Seller and merchant of record is Merit Systems Inc, which also fulfils orders (https://agentzon.co/terms and https://agentzon.co/returns). merit.systems/terms names Merit Systems, Inc. and a New York address for legal notices, with no state of incorporation or company number (source: \u003chttps://merit.systems/terms\u003e)\n- Checkout returns a private URL and an orderId with an orderToken. The buyer reviews the order and pays there through a Stripe-embedded form, and the API says card numbers must never be sent to Agentzon (https://agentzon.co/agents.md and https://agentzon.co/auth.md). The checkout page itself was not opened, because the brief allows only product listing reads\n- UCP 2026-08-25 is advertised at https://agentzon.co/.well-known/ucp with the REST endpoint https://agentzon.co/api/ucp, which answered 404 to a GET. The UCP protocol is Apache 2.0 licensed and governed by a Governing Council (source: \u003chttps://ucp.dev/documentation/announcements/\u003e)\n- WebMCP tools search_catalog, stage_cart_items and request_catalog_items are registered by the storefront script when document.modelContext exists. The script was read, not run in a browser (source: \u003chttps://agentzon.co/_next/static/immutable/chunks/26v1sia-uilve.js\u003e)\n- The founder's lead says checkout supports Stripe Link. No Link mention was found in the pages or storefront script read on 10 October 2026\n- No status page at status.agentzon.co, agentzon.co/status or agentzon.co/api/status (each 404 on 10 October 2026). No security.txt at /.well-known/security.txt (404)\n- A different product named agentzon, at agentzon.xyz, is in the official MCP registry as xyz.agentzon/agentzon (https://registry.modelcontextprotocol.io/v0/servers?search=agentzon). It is not this listing\n\n- #16 of 18 in Best commerce platforms and checkout APIs for AI agents: https://www.anchorterminal.com/best/commerce/index.md\n- All 153 commerce comparisons: https://www.anchorterminal.com/compare/commerce/index.md\n\n## Compare\n\n- [Adobe Commerce (Magento) vs Agentzon](https://www.anchorterminal.com/compare/adobe-commerce-vs-agentzon.md): B 63.9 vs D 51.4\n- [Agentzon vs BigCommerce API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-bigcommerce.md): D 51.4 vs B 64.3\n- [Agentzon vs Commerce Layer API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-commerce-layer.md): D 51.4 vs B 63.7\n- [Agentzon vs commercetools](https://www.anchorterminal.com/compare/agentzon-vs-commercetools.md): D 51.4 vs BB 71.3\n- [Agentzon vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/agentzon-vs-ecwid.md): D 51.4 vs B 63.2\n- [Agentzon vs Elastic Path API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-elastic-path.md): D 51.4 vs D 50.1\n- [Agentzon vs Medusa API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-medusa.md): D 51.4 vs B 63.5\n- [Agentzon vs Saleor API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-saleor.md): D 51.4 vs B 68.6\n- [Agentzon vs Shopify API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-shopify.md): D 51.4 vs BB 75\n- [Agentzon vs Shopware](https://www.anchorterminal.com/compare/agentzon-vs-shopware.md): D 51.4 vs BB 71.4\n- [Agentzon vs Snipcart API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-snipcart.md): D 51.4 vs E 40.8\n- [Agentzon vs Spree Commerce](https://www.anchorterminal.com/compare/agentzon-vs-spree-commerce.md): D 51.4 vs BB 70.4\n- [Agentzon vs Square](https://www.anchorterminal.com/compare/agentzon-vs-square.md): D 51.4 vs B 69.2\n- [Agentzon vs Swell](https://www.anchorterminal.com/compare/agentzon-vs-swell.md): D 51.4 vs C 55\n- [Agentzon vs Vendure](https://www.anchorterminal.com/compare/agentzon-vs-vendure.md): D 51.4 vs BB 70.9\n- [Agentzon vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/agentzon-vs-wix.md): D 51.4 vs C 61.4\n- [Agentzon vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/agentzon-vs-woocommerce.md): D 51.4 vs BB 72.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on agentzon.co or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"agentzon\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agentzon\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agentzon.svg\" alt=\"Agentzon on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Agentzon on Anchor Terminal](https://www.anchorterminal.com/badges/agentzon.svg)](https://www.anchorterminal.com/tools/agentzon)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agentzon\"\u003eAgentzon on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Agentzon is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/agentzon-dark.png\n- Light: https://www.anchorterminal.com/assets/share/agentzon-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Commerce \u0026 checkout",
        "url": "https://www.anchorterminal.com/categories/commerce"
      },
      {
        "name": "Agentzon",
        "url": ""
      }
    ],
    "description": "Online store for household essentials that agents can search and buy from through a JSON API. Sells 466 purchasable items shipped within the U.S. by Merit Systems Inc, with payment on a private checkout page.",
    "facts": [
      "rank #753 of 955",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "Agentzon",
    "image": "https://www.anchorterminal.com/assets/og/tools-agentzon.png",
    "path": "/tools/agentzon",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Agentzon review (2026): pricing, alternatives and grade D",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/agentzon"
  },
  "tokens": {
    "markdown": 7000,
    "slim": 1780
  },
  "version": 1
}
