# Agent technologies for marketplaces

The answers about the site this list is for. Change any of them on the page: https://agentic-readiness.lumar.io/sectors/marketplaces

- You publish content you want AI assistants to read or quote: yes
- You sell online and take payment on the site: yes
- Visitors can do things an agent could do for them, like search, book or track an order: yes
- You offer an API other software can use: no
- You run bots or agents of your own that visit other sites: no

## Should have already

Standard equipment for a site like yours. If you have it, scan your site to check it is right.

- **AI-bot rules** (platform default, rising). Named rules for GPTBot, ClaudeBot and friends, rather than one blanket policy.
  Effort: low. Running cost: none. Needs: A decision on which AI crawlers may read the site; A rule for each of them in robots.txt. 60% of marketplaces have it 0.6% of all published ones are broken.
- **Canonical URL** (web baseline, flat). Tells an agent which address is the real one for this page.
  Effort: low. Running cost: none. Needs: A canonical link tag in each page template, pointing at the page's preferred address.
- **Content Signals** (platform default, rising). Cloudflare's robots.txt vocabulary for search, AI input and AI training.
  Effort: low. Running cost: none. Needs: One line in robots.txt saying how your content may be used; Or Cloudflare's managed robots.txt, which adds it. 3% of marketplaces have it 4.3% of all published ones are broken.
- **Editorial metadata** (web baseline, flat). Author, dates and provenance behind the content.
  Effort: low. Running cost: none. Needs: Author, publisher and dates in the structured data of each article.
- **HTTP Link header** (web baseline, flat). Relations declared in headers, readable without parsing the body.
  Effort: low. Running cost: none. Needs: A server or CDN rule that adds Link headers for the page's alternates.
- **JSON-LD** (web baseline, flat). Structured data describing what this page is about.
  Effort: low. Running cost: none. Needs: Structured data in each page template, describing what the page is about.
- **Language and encoding** (web baseline, flat). Declared language and charset, so text is interpreted correctly.
  Effort: low. Running cost: none. Needs: A lang attribute and a character set declared on every page.
- **Product / Offer schema** (web baseline, flat). Price, availability and identifiers an agent can quote.
  Effort: low. Running cost: none. Needs: Product and price markup in product page templates, which most shop platforms add for you.
- **robots.txt** (web baseline, flat). The crawl-policy file every agent reads first.
  Effort: low. Running cost: none. Needs: A robots.txt file at the root of the site. 98% of marketplaces have it 1.3% of all published ones are broken.
- **schema:Action** (web baseline, flat). Declares actions an agent could take from this page.
  Effort: low. Running cost: none. Needs: Markup describing the actions a page supports, such as search or booking.
- **XML sitemap** (web baseline, flat). The URL inventory agents and crawlers use for discovery.
  Effort: low. Running cost: none. Needs: A sitemap your CMS or a build step generates; A job that keeps it current as pages change. 68% of marketplaces have it 52% of theirs are broken.
- **Server-side rendering** (web baseline, flat). Whether the content exists before JavaScript runs. Most agents never run it.
  Effort: high. Running cost: low. Needs: Page content in the HTML the server sends, not only after scripts run; For a site that renders in the browser today, a framework change.

## Worth building

In production at other organisations and gaining ground. Weigh each one by what it takes.

- **TDMRep** (early production, rising). The W3C text and data mining reservation, used mainly by publishers.
  Effort: low. Running cost: none. Needs: A decision on whether you reserve text and data mining rights; A JSON file or header saying so, with a link to your licensing terms. 3 of 4,211 marketplaces have it 19% of all published ones are broken.
- **llms.txt** (early production, rising). A hand-written Markdown index of a site's most useful pages, written for language models.
  Effort: low. Running cost: low. Needs: A Markdown file listing your most useful pages; Someone to keep it current. 16% of marketplaces have it 9.4% of all published ones are broken.
- **Markdown negotiation** (early production, rising). Markdown served to agents that ask for it with Accept: text/markdown.
  Effort: medium. Running cost: low. Needs: A server or CDN that answers a request for Markdown with Markdown; A Vary: Accept header so caches keep the two versions apart.
- **Markdown twin** (early production, rising). A clean low-token markdown version of the page for agents.
  Effort: medium. Running cost: low. Needs: A build step that turns each page into Markdown; The Markdown served at the page's address with .md added.
- **UCP profile** (platform default, rising). Universal Commerce Protocol discovery for agentic shopping.
  Effort: medium. Running cost: low. Needs: On Shopify, nothing: it is on by default, so check it is correct; Elsewhere, checkout endpoints that follow the specification and a profile describing them. 13 of 4,211 marketplaces have it 5.3% of all published ones are broken.

## Keep an eye on

It fits your site, but it is early or still settling. Nothing to build yet; worth knowing about.

- **A2A agent card** (early pilots, rising). Declares an agent this site operates, for agent-to-agent work.
  Effort: low. Running cost: none. Needs: A JSON file at /.well-known/agent-card.json describing your agent's skills and address. It describes an A2A agent you already run. Building and hosting that agent is a separate project, and the bigger one. 5 of 4,211 marketplaces have it 79% of all published ones are broken.
- **ai.txt** (specification only, flat). Attribution preferences for AI systems that use the content.
  Effort: low. Running cost: none. Needs: A text file at the root of the site stating your AI usage terms. 6 of 4,211 marketplaces have it.
- **AIPREF Content-Usage** (specification only, rising). The IETF's standards-track vocabulary for stating how content may be used by AI systems.
  Effort: low. Running cost: none. Needs: Usage preferences declared in robots.txt or an HTTP header, once the standard settles.
- **auth.md** (early pilots, rising). Telling an agent how to register for an account and get its own credentials, without a signup form or a consent screen.
  Effort: low. Running cost: none. Needs: A Markdown file explaining how agents should sign in; Only worth writing once the convention settles.
- **MCP server card** (early pilots, rising). Advertises a Model Context Protocol endpoint agents can call.
  Effort: low. Running cost: none. Needs: A JSON file at /.well-known/mcp.json giving your server's address, transports and tools. It describes an MCP server you already run. Building, hosting and securing that server is a separate project, and the bigger one. 0.6% of marketplaces have it 22% of all published ones are broken.
- **WebMCP** (early pilots, rising). In-page tools a browsing agent can call directly.
  Effort: medium. Running cost: low. Needs: Front-end code that registers your page's actions as tools; Tool design: names, descriptions and inputs an agent can rely on.
- **ACP** (early pilots, receding). The Agentic Commerce Protocol, which powered checkout inside ChatGPT.
  Effort: high. Running cost: medium. Needs: A platform to sell through: OpenAI closed Instant Checkout, the main one, in March 2026; Checkout endpoints that follow the specification; A payment provider that supports delegated payments.
- **AP2** (early pilots, flat). The Agent Payments Protocol, covering how an agent proves it was authorised to pay.
  Effort: high. Running cost: medium. Needs: A payment provider that supports agent mandates; Checkout changes to accept and verify them.
- **MCP authorization** (early production, rising). The OAuth discovery chain protecting that MCP endpoint.
  Effort: high. Running cost: medium. Needs: An OAuth authorization server, or a provider that runs one; Protected-resource metadata so agents can find it; Token checks on every MCP request. It protects an MCP server you already run, which is a separate project. The authorization itself is the effort rated here. 1 of 4,211 marketplaces have it 37% of all published ones are broken.
- **NLWeb endpoint** (early pilots, receding). Microsoft's conversational /ask route returning schema.org answers.
  Effort: high. Running cost: high. Needs: A vector database; An embedding model; A pipeline that keeps the embeddings in sync with your content; A language model to write the answers, paid per question; An /ask endpoint to host and scale. None of the 4,211 marketplaces we scanned have it yet.

## Not for you yet

These do not fit your answers above. Change an answer and they move.

- API catalog: Only if you offer an API.
- OpenAPI description: Only if you offer an API.
- MPP (Machine Payments Protocol): Only if you offer an API.
- Web Bot Auth directory: Only if you run bots or agents of your own.
- x402: Only if you offer an API.
