generated: '2026-08-11' method: probed source: >- https://davidprotein.com/agents.md plus live probes of the three MCP endpoints note: >- David has no REST API and no OpenAPI, so these conventions describe the JSON-RPC 2.0 / MCP surface the store actually serves. Everything below was observed on a live request or read from a tool inputSchema, not inferred from platform documentation. transport: protocol: JSON-RPC 2.0 over HTTP POST content_type: application/json accept: 'application/json, text/event-stream' methods_observed: [initialize, tools/list, tools/call] authentication: style: mixed detail: >- Anonymous on the storefront MCP server and the read-only JSON paths; a signed JWT on the UCP commerce server's tools/call; OAuth 2.0 authorization-code with PKCE on the customer-account server. See authentication/david-protein-authentication.yml. idempotency: supported: true mechanism: request field field: meta.idempotency-key scope: complete_checkout source: >- inputSchema of the complete_checkout tool in mcp/david-protein-ucp-mcp-tools.json, described as "An idempotency key for completing the checkout." retention: not published note: >- Idempotency is offered on exactly one operation - the one that takes money. No idempotency key is accepted on cart or checkout mutation tools, so a retried update_cart or update_checkout has no replay protection. pagination: style: cursor request: object: catalog.pagination params: - {name: cursor, type: string, description: Pagination cursor} - {name: limit, type: integer, default: 10, minimum: 1} response_field: pagination.cursor applies_to: [search_catalog] source: mcp/david-protein-ucp-mcp-tools.json buyer_context: object: catalog.context fields: [address_country, address_region, postal_code, language, currency, intent] note: >- agents.md instructs agents to pass context.address_country and context.currency for accurate pricing and availability. platform_signals: object: catalog.signals fields: ['dev.ucp.buyer_ip', 'dev.ucp.user_agent'] agent_identity: object: meta.ucp-agent field: profile type: uri required: true note: >- Every UCP commerce tool requires meta.ucp-agent.profile, a URI the store fetches to resolve the calling agent. Omitting it returns JSON-RPC -32001 "UCP discovery failed" with data.code invalid_profile_url. This is a real agent-identity requirement, not a formality. money: representation: integer minor units plus ISO 4217 currency code example: '{"amount": 600, "currency": "USD"} is $6.00' source: tool descriptions across the UCP commerce server identifiers: style: Shopify global ID (GID) example: 'gid://shopify/Product/8653621264551' error_envelope: style: JSON-RPC 2.0 error object fields: [code, message, data] see: errors/david-protein-problem-types.yml rate_limit_signaling: see: rate-limits/david-protein-rate-limits.yml versioning: see: lifecycle/david-protein-lifecycle.yml human_in_the_loop: required_for: [complete_checkout, payment] policy: >- Both robots.txt and agents.md state that checkout, payment and order placement must not be completed automatically - no scripted form fills, browser automation or end-to-end agent flows that finalize payment without an explicit, contemporaneous human approval step. source: https://davidprotein.com/agents.md