Repository navigation
Document AgentCard checkout origin matching - #652
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 99d998e. Configure here.
| `merchant_origin` from its preparation instead of this field. Card updates | ||
| replace the full `spec`, so include `checkout_origin` again when you want to | ||
| keep using it. An autopilot match doesn't guarantee processor acceptance or | ||
| payment success. |
There was a problem hiding this comment.
Packed checkout origin caveats paragraph
Low Severity
The checkout_origin paragraph now combines origin format, non-prepared versus prepared behavior, omit semantics, full-spec replace rules, and separate autopilot-approval caveats in one run of prose. Those are distinct constraints that are hard to scan together.
Triggered by learned rule: Use bullet lists when covering multiple distinct points in guides
Reviewed by Cursor Bugbot for commit 99d998e. Configure here.


Summary
checkout_originmatching for non-prepared checkout authorizations, including canonical origin requirements and prepared checkout behavior.Validation
git diff --checkTesting
Note
Low Risk
Documentation-only updates to the AgentCard guide with no runtime or API behavior changes in this diff.
Overview
Documents the optional AgentCard card
spec.checkout_originfield in the AgentCard integration guide.Examples now include
checkout_originon create and update paths (TypeScript, Python, CLI). The item reference table lists it alongsidecard_idas optional.New prose explains canonical origin formatting (HTTPS shop origins or
http://localhost), that Kernel forwards the value to AgentCard for autopilot rule matching on non-prepared checkouts (not a substitute for user approval), prepared checkout’s use ofmerchant_origininstead, and that fullspecreplacement on update requires re-sendingcheckout_origin. It also states the trust boundary: callers must supply a validated origin; Kernel does not compare it to the browser page.Reviewed by Cursor Bugbot for commit dd52b11. Bugbot is set up for automated code reviews on this repo. Configure here.