generated: '2026-08-05' method: searched source: - https://100thieves.com/agents.md - https://100thieves.com/llms.txt - https://100thieves.com/robots.txt - mcp/100-thieves-tools-list.json - graphql/100-thieves-storefront.graphql authentication: style: anonymous for the agent commerce and catalog surfaces; OpenID Connect for customer accounts detail: authentication/100-thieves-authentication.yml agent_identity: mechanism: UCP agent profile location: every MCP tool call, required object meta.ucp-agent.profile type: URI identifying the calling agent's published profile note: This is the only mandatory field on all thirteen tools — the store requires an agent to identify itself before any catalog, cart or checkout call. idempotency: supported: false detail: >- No idempotency key appears anywhere in the thirteen tool input schemas, and neither /agents.md nor /llms.txt documents one. Cart and checkout mutations are made safe by returning a server-assigned id on create and requiring that id on every later call, not by a client-supplied idempotency token. No Idempotency pointer is emitted. pagination: style: cursor request_params: - name: pagination.limit surface: mcp - name: pagination.cursor surface: mcp response_fields: - pagination.cursor graphql_equivalent: style: Relay connections — first/last/after/before with pageInfo detail: >- Documented on search_catalog: "Results are paginated, with initial results limited to improve experience. Use the pagination.cursor from the response to fetch additional pages when users request more results." buyer_context: documented: true fields: - context.address_country - context.currency purpose: Accurate pricing and availability. The store instructs agents to pass these. versioning: ucp: scheme: dated release train current: '2026-04-08' supported: ['2026-04-08', '2026-01-23'] discovery: https://100thieves.com/.well-known/ucp graphql: scheme: dated API version in the URL path current: '2024-04' example: https://100thieves.com/api/2024-04/graphql.json introspectable_versions_field: publicApiVersions detail: lifecycle/100-thieves-lifecycle.yml error_envelope: format: JSON-RPC 2.0 error object fields: [code, message, data] detail: errors/100-thieves-problem-types.yml note: The MCP endpoint speaks JSON-RPC 2.0, not RFC 9457 problem+json. GraphQL errors use the standard errors[] array with extensions. rate_limiting: documented: true quantified: false scope: per IP signal: HTTP 429 guidance: 'Published rule in /agents.md: "Respect rate limits. The MCP endpoint is rate-limited per IP. Back off on 429 responses." No numeric limit, window, or RateLimit-* header is published, so no rate-limits artifact is emitted.' graphql_signal: field: extensions.cost detail: Storefront GraphQL responses carry an extensions.cost object with requestedQueryCost — observed live on the introspection call. agent_policy: human_approval_required_for: [payment, checkout completion, order placement] statement: >- "Checkouts are for humans. Do NOT complete checkout, payment, or order placement automatically — no scripted form fills, browser automation, or end-to-end agent flows that finalize payment without an explicit, contemporaneous human approval step." (robots.txt and /agents.md) sanctioned_paths: - https://100thieves.com/api/ucp/mcp - https://shop.app/SKILL.md crawling: Public product, collection, page, blog, policy, cart, and localized HTML is explicitly crawlable per robots.txt. contact: bots@shopify.com discovery_convention: canonical_agent_doc: https://100thieves.com/agents.md mirrors: - https://100thieves.com/llms.txt advertised_in: robots.txt comment block cross_links: authentication: authentication/100-thieves-authentication.yml scopes: scopes/100-thieves-scopes.yml errors: errors/100-thieves-problem-types.yml lifecycle: lifecycle/100-thieves-lifecycle.yml mcp: mcp/100-thieves-mcp.yml well_known: well-known/100-thieves-well-known.yml