ARC · DEVELOPERS
Free tools to make stores work for AI agents.
Free developer tools for agentic commerce: a UCP profile validator, the arc-check CLI and CI step for UCP and WebMCP, a no-key REST API with OpenAPI, and an MCP server for Claude, Cursor and ChatGPT. Everything here is free, needs no account, and returns the evidence behind every answer.
UCP profile validator
Paste a URL or JSON. Errors and warnings against the published UCP 2026-08-25 schema and spec rules, instantly in your browser.
arc-check CLI
One command: is the UCP profile valid and is WebMCP live? Exit codes for scripts.
CI check
Fail a build or a daily job when a store's UCP profile or WebMCP setup breaks.
REST API + OpenAPI
No key, CORS open. Checkout checks, protocol adoption, directory, submissions, leaderboard.
MCP server
Every public tool for Claude, Cursor, ChatGPT and VS Code, with a docs page per tool. No login.
Open dataset
Weekly CSV and Parquet snapshots, CC-BY-4.0, with a citation file.
Protocol Matrix
UCP, ACP, PAP, WebMCP, MCP and payments: declared, valid, usable, transacts.
Agent leaderboard
ARC-100: a fixed public set of 100 stores. Submit your agent's run.
Check a store from the terminal
arc-check fetches the store's /.well-known/ucp live and validates it against the published UCP schema, and reads ARC's latest HTTP agent check for WebMCP, the agent catalog, a checkout link, storefront MCP, robots.txt, product data and policies. Zero dependencies, Node 18+. Exit codes: 0 every required check passed, 1 one failed, 2 network error, 3 rate limited.
curl -fsSLO https://www.arcreport.ai/arc-check.mjs node arc-check.mjs yourstore.com # exit 1 if UCP or WebMCP breaks node arc-check.mjs yourstore.com --require checkout # can agents reach checkout? node arc-check.mjs a.com b.com --require all --json
The npm package is built and waiting to be published. Once it is: npx arcreport-check yourstore.com (the name arc-check belongs to an unrelated package). Checks: ucp, webmcp, catalog, checkout, mcp, robots, product-data, policies. Flags: --require (default ucp,webmcp; all; none), --json, --summary. MIT licence.
Fail CI when UCP or WebMCP breaks
Run it on every deploy and once a day. A theme change, an app uninstall or a CDN rule can silently remove a store's UCP profile or WebMCP adapter; this catches it before agents do. In GitHub Actions, failures show as annotations and in the job summary.
# .github/workflows/arc-check.yml
name: ARC agent-commerce check
on:
push:
branches: [main]
schedule:
- cron: "17 6 * * *" # daily
workflow_dispatch:
jobs:
arc-check:
runs-on: ubuntu-latest
steps:
- name: UCP profile and WebMCP still work
run: |
curl -fsSLO https://www.arcreport.ai/arc-check.mjs
node arc-check.mjs yourstore.com --require ucp,webmcp --summary "$GITHUB_STEP_SUMMARY"A packaged action (action.yml with host, require and strict inputs and ok, exit-code and report outputs) is ready to publish to the Marketplace. Once published:
- uses: arcreport/arc-check@v1 # planned location
with:
host: yourstore.com
require: ucp,webmcpThe same command works in GitLab CI, CircleCI, Jenkins or cron. WebMCP, catalog and checkout reuse ARC's latest check of the store (cached up to 24 hours); the UCP check is always live.
Call the API
JSON over HTTPS, no key, CORS open. The full description is /openapi.json (OpenAPI 3.1). Please keep it polite: per-network daily limits apply and are stated in each response.
# Validate a UCP profile (live fetch + published schema + spec rules)
curl "https://www.arcreport.ai/api/ucp/validate?url=allbirds.com"
# Can an agent reach checkout? (catalog, product, checkout link, UCP, WebMCP)
curl "https://www.arcreport.ai/api/agent-checkout?url=https://allbirds.com"
# Protocol Matrix: declared, valid, usable, transacts per protocol
curl "https://www.arcreport.ai/api/protocols"
# Stores where agents reached checkout in the last 7 days
curl "https://www.arcreport.ai/api/agent-checkout/stores?category=footwear&limit=10"
# Add stores to the open directory (up to 50)
curl -X POST "https://www.arcreport.ai/api/stores/submit" \
-H "content-type: application/json" \
-d '{"hosts":["yourstore.com"]}'// Node 18+, Deno, Bun or the browser (CORS is open). No key.
const arc = (path) => fetch(`https://www.arcreport.ai${path}`).then((r) => r.json());
const ucp = await arc("/api/ucp/validate?url=allbirds.com");
console.log(ucp.valid, ucp.errors, ucp.warnings);
const store = await arc("/api/agent-checkout?url=" + encodeURIComponent("https://allbirds.com"));
console.log(store.ucpProfile, store.webmcp, store.cartLink, store.resultUrl);
// MCP over plain JSON-RPC
const rpc = await fetch("https://www.arcreport.ai/api/ask", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ jsonrpc: "2.0", id: 1, method: "tools/call",
params: { name: "protocol_matrix", arguments: { protocol: "ucp" } } }),
}).then((r) => r.json());
console.log(JSON.parse(rpc.result.content[0].text).rows[0]);# Python 3, standard library only. No key.
import json, urllib.parse, urllib.request
ARC = "https://www.arcreport.ai"
def get(path):
with urllib.request.urlopen(ARC + path, timeout=30) as r:
return json.load(r)
ucp = get("/api/ucp/validate?url=allbirds.com")
print(ucp["valid"], [e["message"] for e in ucp["errors"]])
store = get("/api/agent-checkout?url=" + urllib.parse.quote("https://allbirds.com", safe=""))
print(store["ucpProfile"], store["webmcp"], store["cartLink"])
matrix = get("/api/protocols")
for row in matrix["rows"]:
print(row["id"], {stage: v["percentage"] for stage, v in row["stages"].items()})Connect the MCP server
One URL, no login, streamable HTTP: https://www.arcreport.ai/api/ask. Your agent gets every public ARC tool, from validate_ucp_profile and can_agent_checkout to protocol_matrix, submit_store and agent_leaderboard. Read-only except submissions. Reference: arguments and examples for all 15 tools →
https://www.arcreport.ai/api/askClaude
Claude.ai and Claude Desktop: Settings → Connectors → Add custom connector, paste the URL, no authentication. Claude Code:
claude mcp add --transport http arc https://www.arcreport.ai/api/ask
Older Claude Desktop builds without custom connectors can bridge with mcp-remote in claude_desktop_config.json:
{
"mcpServers": {
"arc": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://www.arcreport.ai/api/ask"]
}
}
}Cursor
Add to Cursor (one click), or put this in .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):
{
"mcpServers": {
"arc": { "url": "https://www.arcreport.ai/api/ask" }
}
}ChatGPT
In ChatGPT on the web, open Settings → Apps (turn on Developer mode under Advanced settings if your plan needs it), create a custom MCP app or connector, paste the URL and choose No authentication. ChatGPT scans the tools; then enable ARC in a chat. Menu names vary by plan and workspace policy; see OpenAI's help article.
VS Code and others
{
"servers": {
"arc": { "type": "http", "url": "https://www.arcreport.ai/api/ask" }
}
}Discovery for crawlers and registries: /.well-known/mcp.json, server card, llms.txt. A signed-in server for running new scans lives at /mcp.
Honest limits
- Validation is not certification. A valid UCP profile does not prove the endpoints work; the checkout check is the closer test, and it never places an order.
- WebMCP is detected from the store's server HTML (Shopify's adapter). ARC can't see tools registered in a live browser session.
- Checking a store adds it to ARC's free open directory and dataset (CC-BY-4.0). No personal data is collected.
- Limits per network per day: 300 UCP profile fetches (pasted JSON is unlimited) and 50 checkout reads with 10 fresh checks.
- Found a wrong result or want a new check? Tell us. Method changes are logged in the changelog.