Docs
Firmly Agentic Commerce
Set theme to dark (⇧+D)

UCP

The Universal Commerce Protocol is an open standard launched in early 2026 by Google in collaboration with major retailers and platforms. It defines how AI agents conduct complete commerce transactions — from cart initialization to payment to order placement — through a single, interoperable interface.

UCP powers purchasing on Google’s AI surfaces. When a user instructs a Google AI surface to buy something, UCP is the protocol that handles the checkout session between Google and the merchant’s backend.

​​ Session model

Every UCP purchase flows through three steps:

  1. CreateCheckoutSession — initialize a cart with the selected products
  2. UpdateCheckoutSession — collect shipping address, method, buyer info, and payment
  3. CompleteCheckoutSession — place the order and return confirmation

A cancel operation is also available to abort sessions that don’t progress to completion. Sessions move through states (incomplete → ready_for_complete → complete_in_progress → completed) — this is the happy path; see Checkout flow for the full state table, including canceled and requires_escalation.

​​ Transport

UCP can run over REST, MCP, A2A (Agent2Agent), or as an Embedded Protocol (a UCP session embedded directly inside the host surface rather than reached over a network binding). Firmly implements the REST binding (the primary path) and the MCP binding (Streamable HTTP / JSON-RPC 2.0, advertised in the discovery manifest); A2A and the Embedded Protocol are not implemented. Beyond checkout, Firmly also exposes the pre-purchase Cart resource and catalog search/lookup over both bindings — see the Roadmap for the full capability status.

​​ Discovery

Merchants publish a capability manifest at /.well-known/ucp, telling UCP clients what payment methods, extensions, and signing keys they support. Firmly generates this manifest dynamically per merchant.

​​ Division of responsibility

Google owns discovery (its Shopping index, product feeds, Merchant Center) and the checkout UI — it collects the user’s address and payment. The merchant’s backend owns cart orchestration, shipping rates, payment processing, and order placement.

UCP is the contract between them.

​​ Why Firmly integrates with UCP

UCP creates an opportunity on two sides:

​​ Destination side — implemented

Firmly has merchant adapters across a broad, growing set of industry-standard commerce platforms and custom platforms. When Firmly implemented UCP, every one of those merchants became available on Google’s AI surfaces and any AI agent that speaks UCP — without any additional integration work on the merchant’s part.

The mechanics: Firmly built a UCP wrapper service that sits in front of its existing cart and checkout APIs. Google calls Firmly’s UCP endpoints; Firmly translates those calls into its internal cart operations, retrieves shipping options, tokenizes payment, and places the order on the merchant’s native platform. The merchant never changes anything. The user never leaves the AI surface. Firmly handles everything in between.

Google owns the user-facing checkout UI. Firmly owns the commerce infrastructure behind it.

​​ Merchant side — planned

UCP also creates a new category of merchants: platforms and retailers that natively speak UCP. Once a merchant implements UCP, any compliant agent can transact with them using a single, reusable integration.

For Firmly, this represents a future direction in how merchant adapters are built. Rather than a bespoke integration for each new merchant, Firmly could build one UCP merchant adapter — and any merchant that has implemented UCP would automatically be supported. This is not yet built; it represents a planned direction as UCP adoption grows.

​​ Architecture

Firmly sits between Google and the merchant’s native platform. The UCP service receives requests from Google, translates them into Firmly’s internal cart and checkout APIs, and forwards results back in UCP format. The merchant platform — regardless of which commerce platform the merchant runs — is unaware of UCP entirely. It sees only Firmly’s standard adapter calls.

On the Google side, Firmly publishes a dynamic discovery manifest per merchant, advertising supported payment methods, active extensions, and the public JWK used for signature verification. On the merchant side, Firmly calls into its existing adapter layer — the same code that powers every other Firmly checkout flow.

The boundary is clean by design: Google owns the user and the UI; Firmly owns the commerce.

​​ Sub-pages

​​ External references

Resource Description
ucp.dev Protocol specification and overview
Google UCP Guide Google’s integration guide for merchants and platforms
UCP REST Binding REST API specification for checkout session endpoints
Native Checkout Guide How native checkout works on Google’s surfaces