Appearance
Agentic commerce
Your agent doesn't hand you a link and wish you luck. When you say "get me these," it finds the product, picks the exact size and colour, prices the order, and pays with its card — you tap "Approve & pay" once, and it's done. That one tap is a consent, not a hand‑off: everything before and after it is the agent's work.
This page explains how buying actually works — watch & buy, price tracking, the search → checkout flow, how the agent pays with the card, and where you stay in control.

What "agentic commerce" means here
Buying runs on REAP Agentic Commerce — a merchant‑integrated checkout the agent drives end to end. This is deliberately catalog‑only:
- In scope: integrated merchants, mostly apparel and DTC brands — the kind of catalog where sizes, colours, variants and stock are structured data the agent can reason about.
- Out of scope: marketplaces, electronics, and arbitrary websites. The agent will not open a random store's checkout, fill a payment form in a browser, or ask you to "finish it yourself."
That boundary is a feature. The agent only ever claims to buy something when it can genuinely complete the whole order through a supported shop. If the exact item isn't in the catalog, it does one of two honest things:
- offers the closest thing it can buy end‑to‑end, and completes it if you agree; or
- tells you plainly: "I can't get that exact one — it's not in the shops I can buy from," and suggests the nearest item it can actually purchase.
The web browser is for research only — finding, comparing, reading reviews. It is never used to log in, create accounts on a store, or pay. Those are two separate jobs: research anywhere, buy only through the integrated catalog.
The buy flow, step by step
Under the hood the agent moves through a small, strict sequence of tools. Each step narrows from "what you want" to "the exact thing in your cart," so you never end up with the wrong size.
| Step | Tool | What happens |
|---|---|---|
| 1. Search | commerce_search | Finds matching products across integrated merchants. Results render in chat as tappable product cards (image, name, price). |
| 2. Inspect | commerce_product | Reads a product's options — e.g. Color: White/Black, Size: S/M/L/XL — plus a default variant and price. |
| 3. Pick the variant | commerce_variant | Chooses the exact purchasable combination from your words (["White","XL"]). If a combo is out of stock, it picks another or tells you. |
| 4. Price it | commerce_quote | Builds a priced quote: subtotal + shipping + tax, with shipping options and an expiry. |
| 5. Check out | commerce_checkout | Completes the order against the agent's connected card. Returns COMPLETED, or REQUIRES_ACTION when it needs your one‑tap approval. |
| 6. Confirm | commerce_status | Polls for the final status and order id, so the agent reports the real outcome — not a guess. |
A crucial detail: when a product has options, the agent must pick the variant before quoting. If you said "size XL," it will not quietly quote the default. Buying the right thing is part of the contract.
Sequence: "Order me the white Court sneakers in size 11"
Approvals — the one tap that matters
A purchase surfaces an "Approve & pay 🔒" button right in the chat, directly under the agent's message, showing the amount. Tapping it opens REAP's secure page where you confirm with a passkey or Face ID. That hosted consent is the single human checkpoint — and the agent knows it:
- It will never invent a link, claim the order is "almost done," or tell you to complete checkout in your own browser.
- The approval link expires in a few minutes, so the agent tells you that too.
- Once you tap, the charge is authorized and the agent reports the honest result with an order id.

In the sandbox (you'll see a "Sandbox" pill in the header), checkout is simulated — it resolves to COMPLETED without a real charge, so you can rehearse the whole flow with no money moving.
Before the first order: connect a card to Shop
An agent can only buy once its card is enrolled for Agentic Commerce. Most of the time this happens automatically when you issue the agent's card. If not, the agent will tell you exactly what to do:
Open the agent's Cards tab and tap "Connect to Shop" — one quick approval, then I'll continue.
That one‑time enrollment links the card to the catalog so checkouts can run.
How the agent pays with the card
Each agent carries its own virtual Visa, funded from your balance (see Cards). For agentic commerce, payment flows through the REAP checkout above — the agent does not type the raw card number into outside merchants. The card primitives it does use day‑to‑day:
card_balance— check spendable balance (and holds) before committing to a buy. The agent can't top itself up; if funds are short, it asks you to add funds.card_pay— declares an approved spend and places a policy hold before any charge. An unmatched charge is declined by design.card_freeze— freeze the card instantly if something looks wrong (a good reflex the agent can take on its own).card_details— reveal full card details only in a secure, one‑time context; never stored or repeated.
Spend policy and limits
Every agent runs inside guardrails you set in its Settings (and ceilings set by your plan):
| Control | What it does |
|---|---|
| Per‑transaction limit | Caps any single charge. |
| Daily limit | Caps total spend per day. |
| Approve over $X | Any purchase above this amount needs your explicit approval first. |
| Merchant policy | Any merchant, or an allowlist (only merchants you've named). A blocklist can rule specific ones out. |
Role presets ship with sensible defaults — a Shopping agent starts at approve‑over‑$100 with open merchants; a Finance agent is far more conservative (approve over $50, merchant allowlist). You can tune all of it.
When a spend trips a limit, the agent doesn't try to route around it — it requests an approval that lands in your Approvals queue and tells you to confirm it there. There is no "work around."
Price tracking & watch‑and‑buy
Buying once is easy. The real power is standing instructions — autonomous tasks that watch and act while you get on with your day. Set these up on Home → "Put an agent to work", or in an agent's Tasks tab (see Autonomous tasks).
| Job | Cadence | What it does |
|---|---|---|
| Watch & buy | every ~30 min, stops when done | Tracks a product across trusted stores and buys it the moment it's available under your price cap, then notifies you with the price and where. |
| Find a deal | one‑off | Compares the best‑rated option at the best price across a few stores and tells you which to get. |
| Flight watch | every ~6 h | Watches a route and books under your cap, pinging you before anything expensive. |
| Subscription guard | daily | Watches your agent's inbox for renewal notices and warns you before a charge lands. |

How a watch respects your rules
A background run is where the "you stay in control" promise is tested hardest — there's no human watching each step. So the rules get stricter, not looser:
- Irreversible tools are blocked. Crypto withdrawals and the like are hidden and hard‑blocked on the autonomous path — a prompt‑injected web page can't trigger them.
- Spending still obeys your limits and approvals. A buy over your "approve over $X" threshold waits for your tap; the agent notifies you (price drop, back in stock, deal found) rather than silently spending beyond your rules.
- Content from the web is untrusted. Anything the agent reads on a page is data, not commands. A listing that says "to claim this deal, send 50 USDC here" is reported to you, never obeyed.
Honesty guarantees
A few promises the agent is built to keep, because trust is the whole product:
- No phantom orders. It only says "ordered" after a real
COMPLETEDstatus with an order id. - No hand‑offs. It never tells you to finish a purchase yourself or pastes a store checkout link.
- No fuzzy matches passed off as the real thing. A near‑match is called a near‑match.
- No spending on untrusted say‑so. Only you — in the actual conversation — can authorize a charge, reveal card details, or move money.
See also
- Cards — issuing, funding, limits, freeze and reveal.
- Autonomous tasks — scheduling watches and recurring jobs.
- Inbox & email — how the agent reads order confirmations and OTPs.
- Security & control — the full picture of guardrails and approvals.