Agentic Commerce Readiness Index – UCP, ACP & AI Audit
Pricing
from $16.00 / 1,000 merchant readiness audits
Agentic Commerce Readiness Index – UCP, ACP & AI Audit
Audit merchant websites for UCP, ACP, Product JSON-LD, prices, availability, trust policies, and technical AI-shopping readiness in one scored report.
Pricing
from $16.00 / 1,000 merchant readiness audits
Rating
0.0
(0)
Developer
Muhammad Afzal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 days ago
Last modified
Categories
Share
Agentic Commerce Readiness Index – UCP, ACP & AI-Shopping Audit
Free-plan limit: Apify free-plan runs can return at most 5 dataset records per run. This Actor normally emits one summary record per run.
Audit a merchant website for public Universal Commerce Protocol (UCP), Agentic Commerce Protocol (ACP), product-data, policy, and technical signals. Each merchant URL produces one evidence-backed report with a transparent score out of 100, a grade, all weighted findings, and prioritized remediation steps.
This Actor is for ecommerce teams, agencies, technical SEO specialists, commerce platforms, and developers preparing stores for AI-assisted product discovery and agent-mediated checkout. It performs a bounded public audit. It does not create carts, call authenticated checkout operations, reserve inventory, process payments, prove conformance of a private integration, or certify eligibility for Google or OpenAI programs.
What the index measures
| Category | Points | Public evidence checked |
|---|---|---|
| UCP readiness | 30 | /.well-known/ucp, profile JSON, date-version, services, HTTPS endpoint, checkout capability, payment-handler registry, public keys, and the official versioned profile schema |
| ACP readiness | 25 | /.well-known/acp.json, protocol and supported versions, HTTPS API base URL, REST transport, checkout service, capability structure, caching, and extension declarations |
| AI-shopping discoverability | 20 | Crawlable product pages, schema.org Product and Offer JSON-LD, price/currency, availability, identifiers, canonical URLs, Open Graph previews, and /llms.txt |
| Trust and merchant policies | 15 | Return/refund, shipping/delivery, privacy, support/contact, terms, and machine-readable merchant identity |
| Technical access | 10 | HTTPS, public storefront response, robots.txt, XML sitemap, and homepage indexability |
Grades are A for 90–100, B for 75–89, C for 60–74, D for 40–59, and F below 40. A low score is not a claim that the storefront is unsafe or unsuccessful. It means the checked public surface lacks evidence needed by the index. A high score is not a production checkout certification: authenticated session negotiation, payment processing, inventory accuracy, webhook delivery, and partner-program review remain outside this public audit.
Input
| Field | Type | Default | Purpose |
|---|---|---|---|
startUrls | array | required | One to 20 public HTTPS merchant URLs |
maxPagesPerSite | integer | 8 | Bounded HTML sample per merchant, from 1 to 20 pages |
requestTimeoutSecs | integer | 12 | Per-request timeout, from 5 to 30 seconds |
checkProtocolResources | boolean | true | Validate a discovered UCP profile against the official schema for its declared version |
proxyConfiguration | object | direct access | Optional Apify Proxy fallback after a block or network failure |
Example:
{"startUrls": [{ "url": "https://shop.example" },{ "url": "https://another-shop.example/store" }],"maxPagesPerSite": 10,"requestTimeoutSecs": 12,"checkProtocolResources": true,"proxyConfiguration": { "useApifyProxy": false }}
The Actor normalizes host-only inputs to HTTPS, follows at most four validated redirects, rejects credentials and private/reserved network targets, limits every response to 3 MB, and bounds the number of pages and time per request. It checks robots.txt before following internal links. Product-like URLs are prioritized so a small sample is more likely to include useful commerce evidence.
Output
One default-dataset item is written for each successfully audited merchant. Important fields include:
| Field | Meaning |
|---|---|
readinessScore, readinessGrade | Overall 0–100 score and A–F grade |
categoryScores | Earned points beside the fixed category maximums |
ucp, acp | Discovery URL, HTTP status, version, API endpoint, capabilities, payment handlers, and protocol issues |
pagesScanned, productPagesDetected, productJsonLdCount | Size and product coverage of the bounded public sample |
findings | Every check, whether it passed, its evidence URL, points, severity, and recommendation |
topRecommendations | Highest-value distinct remediation steps |
outcome | complete, partial, or blocked |
Compact example:
{"requestedUrl": "https://shop.example","finalUrl": "https://www.shop.example/","domain": "www.shop.example","outcome": "complete","readinessScore": 78,"readinessGrade": "B","categoryScores": {"ucp": 22,"acp": 17,"aiShopping": 17,"trust": 13,"technical": 9},"pagesScanned": 8,"productPagesDetected": 4,"productJsonLdCount": 4,"topRecommendations": ["Resolve every profile issue and validate against the official schema for the declared date-version."],"summary": "www.shop.example scored 78/100 (B): UCP 22/30, ACP 17/25, AI shopping 17/20, trust 13/15, technical 9/10.","auditedAt": "2026-08-31T12:00:00.000Z"}
The OUTPUT key-value record contains the run-level outcome, requested and delivered counts, warning count, average score, and all delivered reports. Diagnostics for a rejected run are also saved there.
UCP and ACP interpretation
UCP discovery is read from the origin’s public /.well-known/ucp business profile. When enabled, the Actor selects the official schema at https://ucp.dev/{ucp.version}/schemas/profile.json; it never silently validates an unknown version against a newer contract. It also checks for the shopping checkout capability, HTTPS service endpoints, required registries, and accidental private JWK material.
ACP discovery is read from /.well-known/acp.json. The audit checks the public DiscoveryResponse surface promoted with ACP 2026-04-17: protocol version information, api_base_url, transports, and seller-level services. ACP payment handlers and intervention compatibility are negotiated for a checkout session and can vary by transaction, so this Actor does not guess them from unauthenticated website content. It never sends POST /checkout_sessions.
Product feeds and catalog onboarding may be hosted by an agent or commerce partner rather than publicly on the merchant origin. This Actor scores public product structured data and ACP service advertising only. Private feed acceptance, feed freshness, and checkout ID mapping require an authorized integration test.
Pricing
This Actor uses pay-per-event pricing. These are the current Apify Store event prices:
| Event | Price (USD) | When it is charged |
|---|---|---|
apify-default-dataset-item | $0.02 | Merchant readiness audit — One complete 100-point UCP, ACP, AI-shopping, trust, and technical readiness report for one merchant URL. |
apify-actor-start | $0.00005 | Actor Start — Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). — Charged once per run. |
Apify platform usage for this Actor run is included alongside the event prices above; no separate per-run platform-usage fee is passed to users.
This covers Apify platform usage for this Actor run. Other Apify products or usage outside this Actor run may still follow your account plan.
Reliability and limits
The Actor tries direct HTTPS first. If you explicitly configure Apify Proxy, it retries a blocked or failed request through that route. 403, 429, challenge HTML, timeouts, malformed protocol files, and unavailable official schemas are preserved as findings instead of being converted into invented passes. A blocked homepage can still yield a report when public discovery endpoints are measurable, but its outcome is blocked and missing website evidence receives no points.
The bounded crawl is a sample. JavaScript-only product details, region-specific catalog content, pages not linked from the sampled storefront, or bot-protected routes may not be observed. Increase maxPagesPerSite cautiously or enable a permitted proxy when evidence shows that direct cloud access is blocked. The Actor does not bypass authentication, CAPTCHAs, paywalls, or access controls.
Legal, privacy, and security
Audit only storefronts you are authorized to inspect. Public pages and well-known discovery documents can still be subject to site terms, robots policies, rate limits, and local law. Do not place API keys, bearer tokens, cookies, payment data, customer data, or private network URLs in the input. The Actor intentionally accepts no checkout credentials and blocks private/reserved network destinations and credential-bearing URLs.
For a production launch, follow this public audit with authorized UCP/ACP conformance tests, checkout state and idempotency tests, payment-provider review, inventory and pricing verification, privacy/legal review, and the relevant platform onboarding process.
Support
When reporting an issue, include the Apify run ID, the affected merchant domain, the finding code, and whether a proxy was configured. Remove secrets and personal data before sharing logs or outputs.
