GPV-1 · The conditions that must all be true before an agent checks out
On October 6, 2026, Meta, Walmart, Stripe and Sierra published an open standard for how AI agents identify themselves to businesses online. It joins Shopify Checkout WebMCP (execution), Web Bot Auth (identity) and the UCP consent census: the transactional layers of agentic commerce — identity, consent, execution, transparency — are being standardized by the largest platforms on earth. None of them standardizes the purchase decision itself. Every one of these protocols ends where an unverified star rating begins.
This specification fills that layer. GPV-1 defines the Verify Gate: a conjunction of eight conditions that must all evaluate true before an autonomous agent proceeds to checkout. Each condition carries a normative rule, an evidence source, a default threshold, and a failure action. The specification is open, versioned, and machine-readable; it makes no governance or certification claims. It is a contract an agent can keep with its principal.
FIG. 1 — The gate in the stack: others standardized the transactional layers; GPV-1 standardizes the decision.
The transactional stack of agentic commerce closed in a six-week window between September and October 2026. What did not close is judgment. An agent that can prove who it is, hold a user's consent, and execute payment can still be steered by a brushed rating, an expired-domain storefront, or a price that moved between consideration and checkout. The failures are not hypothetical; the evidence corpus behind GoBuy's Smart Scores documents review-brushing campaigns, verified-purchase badges on never-purchased reviews, and storefronts whose trust signals decay between visits.
A pattern is already emerging by convention — verify, then checkout — but conventions fragment. This specification writes the convention down, so that any agent, any framework, and any auditor can evaluate the same purchase the same way.
The key words MUST, MUST NOT, SHOULD, and MAY are to be interpreted as described in RFC 2119. Rules are normative; thresholds are defaults and MUST be recorded when overridden. Implementations MUST treat the ruleset as a conjunction: every rule must evaluate true for a PASS verdict. A single false rule produces FLAG or BLOCK per its failure action.
| ID | Condition (all must be true) | Evidence source | Default threshold | On false |
|---|---|---|---|---|
| R1 | Product identity resolved. The listing resolves to a stable identifier (ASIN or canonical URL), one offer, and a non-expired evidence snapshot. | Product index | identifier present; snapshot age ≤ 14 days | BLOCK |
| R2 | Review authenticity above floor. The review corpus passes authenticity filtering; organic review velocity is within natural bounds (no burst anomaly). | Smart Score corpus | authenticity subscore ≥ 40/100 | FLAG |
| R3 | Composite trust adequate. Smart Score meets the principal's stated floor. | Smart Score | ≥ 55/100 unless principal sets higher | BLOCK below 35 · FLAG 35–54 |
| R4 | Seller history clean. No unresolved counterfeit/misrepresentation pattern in the seller's recent record. | Seller signals | 0 open critical flags | BLOCK |
| R5 | Price within consistency band. Current price within k× of the trailing median for identical offer. | Price observations | within 1.5× trailing median | FLAG |
| R6 | Storefront agent-ready and non-decayed. For merchant-direct purchases: store trust tier and freshness pass; domain ownership continuous. | GoBuy Store Score | tier ≥ C; freshness ≤ 30 days | BLOCK tier D · FLAG stale |
| R7 | No revocation in force. The product/seller is not on an active revocation or watch entry since the snapshot was taken. | Observation ledger | no active entry | BLOCK |
| R8 | Decision recorded. The verdict, rule results, evidence hashes, and spec version are logged for audit before execution. | Agent-side log | record present | BLOCK |
Failure semantics. BLOCK: the agent MUST NOT proceed and MUST surface the failed rule(s) to the principal. FLAG: the agent MUST NOT proceed autonomously; it MAY proceed only after disclosing the flag to the principal and receiving explicit confirmation. Consent does not skip evidence: a principal's blanket authorization never waives R1–R7; it only permits the agent to act on their verdicts.
{
"spec": "gpv-1", "specVersion": "1.0",
"product": { "asin": "B08N5WRWNW",
"url": "https://example.com/offer" },
"store": { "domain": "example.com" }, // optional, merchant-direct
"principalFloor": 55 // optional override of R3
}
{
"spec": "gpv-1", "specVersion": "1.0",
"verdict": "PASS", // PASS | FLAG | BLOCK
"evaluatedAt": "2026-10-07T12:00:00Z",
"rules": [
{ "id": "R1", "pass": true,
"evidence": { "snapshotAge": "3d" } },
{ "id": "R3", "pass": true,
"evidence": { "smartScore": 72 } },
{ "id": "R5", "pass": false, "action": "FLAG",
"evidence": { "price": 89.99,
"trailingMedian": 41.50, "ratio": 2.17,
"reason": "price 2.17x trailing median" } }
],
"summary": "R5 failed: price anomaly. Ask principal."
}
Implementations MUST return per-rule results with machine-checkable evidence; human-readable summary is REQUIRED and MUST be shown to the principal on any non-PASS.
The normative ruleset, thresholds, and failure actions are published as JSON at docs.gobuy.ai/standard/v1.json. Implementations SHOULD fetch, pin, and record the spec version hash alongside each decision (satisfying R8). The JSON is the specification; this document is its human-readable form.
The check_product_trust() tool on GoBuy's public MCP server (mcp.gobuy.ai/mcp, keyless, read-only) evaluates R1–R7 against the live score corpus and returns the Gate result of §4.2. An open-source boilerplate (Next.js + Vercel AI SDK) wiring the gate into an agent's checkout flow is published as the reference integration. R8 is agent-side by design: the decision log belongs to the agent's operator, not the evidence provider — separation of powers.
GPV-1 is maintained by GoBuy under semantic versioning: thresholds tighten or loosen in minor versions; adding, removing, or re-scoping a rule is a major version. Changelogs accompany every release in the JSON envelope. This is a single-maintainer specification with no certification body, no conformance marks, and no paid tiers — deliberately. It becomes a standard when implementations adopt it, not when a committee blesses it.
GPV-1 is complementary to, and dependent on, the identity/consent/execution layers: Web Bot Auth answers who is acting; UCP and Checkout WebMCP answer with what permission and through which rails; the personal agent protocol announced October 6, 2026 standardizes how businesses recognize agents. GPV-1 answers the remaining question — should this purchase proceed — and nothing else.
GoBuy — the trust layer for agentic commerce · Homepage · docs.gobuy.ai · Spec GPV-1 v1.0 · October 2026