Information to provide
A staging environment is strongly preferred but is not required. If no staging environment is available, Firmly will coordinate production-safe validation with the technical contact.
Merchant actions
Most merchant integrations do not require storefront code changes. Firmly uses the merchant’s existing commerce interfaces and normalizes them into Firmly APIs and supported commerce protocols. The merchant may need to:- Confirm that Firmly is authorized to access the storefront and complete integration testing.
- Provide test products, accounts, or payment instructions when normal public test paths are unavailable.
- Configure network access if existing security controls block Firmly requests.
- Notify Firmly before material storefront, CDN, WAF, checkout, or authentication changes.
Network access
Firmly supports three ways for a merchant’s security layer to recognize Firmly traffic:- Web Bot Auth (preferred where supported): verify Firmly’s cryptographic request signature or allow the verified FirmlyAI Bot identity.
- Header-based allowlisting (broadly compatible): match a merchant-specific
x-agentic-authvalue. - IP allowlisting (fallback only): allow Firmly’s fixed outbound egress addresses when request-level identity is unavailable.
Merchant allowlisting controls traffic from Firmly to the merchant storefront. It is separate from the credentials that destinations and partners use to call Firmly APIs.