{"_id":"@botmetria/ucp","_rev":"4-eddf075d68276cf9200c9beefbdf3541","name":"@botmetria/ucp","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@botmetria/ucp","version":"0.1.0","keywords":["ucp","agentic-commerce","ai-agents","ecommerce","chatgpt","catalog","express"],"author":{"url":"https://botmetria.com","name":"Botmetria","email":"info@botmetria.com"},"license":"MIT","_id":"@botmetria/ucp@0.1.0","maintainers":[{"name":"botmetria","email":"info@botmetria.com"}],"homepage":"https://botmetria.com/help/ucp-custom/","dist":{"shasum":"92806cdd0eebe810d51ea121b177ad77343e8b8e","tarball":"https://registry.npmjs.org/@botmetria/ucp/-/ucp-0.1.0.tgz","fileCount":13,"integrity":"sha512-dm50RRCB1HKT5IvRMxf8iIyrsKt3feQvXfn3pJFechywI9ncK9mNkNrkYKExL7Ec70m/pIgh6i2QK9Mg42H8Og==","signatures":[{"sig":"MEYCIQCAyO6087QeWf+YlKZ1bdAwiOg0coBjRJBDohocgqXCQAIhAIzEzPwHstgXeWx9AKEiTlnHJ4MrcLQkpK0UNXaov0+s","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67690},"main":"index.js","types":"index.d.ts","engines":{"node":">=18"},"exports":{".":"./index.js","./collect":"./collect.js"},"gitHead":"37bd53fc21b25379ba05902dd0f9701831003f7f","scripts":{"test":"node --test"},"_npmUser":{"name":"botmetria","email":"info@botmetria.com"},"deprecated":"crash on malformed request; upgrade to 0.1.2","_npmVersion":"10.9.3","description":"UCP (Universal Commerce Protocol) store-side SDK: make any Node.js shop visible and shoppable for AI agents — manifest, agent-readable catalog, checkout sessions with signed cart hand-off. Bundles the Botmetria AI-bot analytics collector as a second entry","directories":{},"_nodeVersion":"22.20.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ucp_0.1.0_1785665926532_0.09015350757064033","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@botmetria/ucp","version":"0.1.1","keywords":["ucp","agentic-commerce","ai-agents","ecommerce","chatgpt","catalog","express"],"author":{"url":"https://botmetria.com","name":"Botmetria","email":"info@botmetria.com"},"license":"MIT","_id":"@botmetria/ucp@0.1.1","maintainers":[{"name":"botmetria","email":"info@botmetria.com"}],"homepage":"https://botmetria.com/help/ucp-custom/","dist":{"shasum":"5001555e75d1a112d47ed044ac4a29d4b2af9cfb","tarball":"https://registry.npmjs.org/@botmetria/ucp/-/ucp-0.1.1.tgz","fileCount":13,"integrity":"sha512-OhIXAThqRsOGV0+9tOfZR64PXBQ+/64/X3QoDE6jPhkfjmr8WyGCNwLHjSZAmvwol3GCnSN4wKHuZai9Zqa52Q==","signatures":[{"sig":"MEYCIQDzOBU+OiAHlPDODYZ57mgC1C7/oeTxesAZsucJQBKUFAIhAMiLxSM3aAGzstr6eLLvJdIUGYf+H9x0+U7R563v+hcx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68764},"main":"index.js","types":"index.d.ts","engines":{"node":">=18"},"exports":{".":"./index.js","./collect":"./collect.js"},"gitHead":"3b41ea55836120b34ea21b8e7f913e268c276dbe","scripts":{"test":"node --test"},"_npmUser":{"name":"botmetria","email":"info@botmetria.com"},"_npmVersion":"10.9.3","description":"UCP (Universal Commerce Protocol) store-side SDK: make any Node.js shop visible and shoppable for AI agents — manifest, agent-readable catalog, checkout sessions with signed cart hand-off. Bundles the Botmetria AI-bot analytics collector as a second entry","directories":{},"_nodeVersion":"22.20.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/ucp_0.1.1_1785690522590_0.7685776843627405","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@botmetria/ucp","version":"0.1.2","description":"UCP (Universal Commerce Protocol) store-side SDK: make any Node.js shop visible and shoppable for AI agents — manifest, agent-readable catalog, checkout sessions with signed cart hand-off. Bundles the Botmetria AI-bot analytics collector as a second entry","license":"MIT","author":{"name":"Botmetria","email":"info@botmetria.com","url":"https://botmetria.com"},"homepage":"https://botmetria.com/help/ucp-custom/","keywords":["ucp","agentic-commerce","ai-agents","ecommerce","chatgpt","catalog","express"],"engines":{"node":">=18"},"main":"index.js","types":"index.d.ts","exports":{".":"./index.js","./collect":"./collect.js"},"scripts":{"test":"node --test"},"_id":"@botmetria/ucp@0.1.2","gitHead":"fd659110de8ed0e1ada73f256ad27116c3bdcec0","_nodeVersion":"22.20.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-kwCnW+JcWxWAg47malGO0fUeozV14veeCtSI5T7on9UyU5zlFAOh9wUorLV39QiueQqrrmKA5OWn1Xd16p4Whg==","shasum":"0d05949d3cbe6b719ee79e3e887176c0f8fb7169","tarball":"https://registry.npmjs.org/@botmetria/ucp/-/ucp-0.1.2.tgz","fileCount":13,"unpackedSize":69090,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBDvWUMEd0Po7G7vcRJLnN14KMIiFhD2VAJ6Z4pU+BjuAiArscZDnrsspIe9pXXZsQaYOZGbbD2Tr9KAC2YVsz6y6g=="}]},"_npmUser":{"name":"botmetria","email":"info@botmetria.com"},"directories":{},"maintainers":[{"name":"botmetria","email":"info@botmetria.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ucp_0.1.2_1785693697445_0.18651023917638687"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-02T10:18:46.394Z","modified":"2026-08-02T18:01:37.750Z","0.1.0":"2026-08-02T10:18:46.679Z","0.1.1":"2026-08-02T17:08:42.742Z","0.1.2":"2026-08-02T18:01:37.593Z"},"author":{"name":"Botmetria","email":"info@botmetria.com","url":"https://botmetria.com"},"license":"MIT","homepage":"https://botmetria.com/help/ucp-custom/","keywords":["ucp","agentic-commerce","ai-agents","ecommerce","chatgpt","catalog","express"],"description":"UCP (Universal Commerce Protocol) store-side SDK: make any Node.js shop visible and shoppable for AI agents — manifest, agent-readable catalog, checkout sessions with signed cart hand-off. Bundles the Botmetria AI-bot analytics collector as a second entry","maintainers":[{"name":"botmetria","email":"info@botmetria.com"}],"readme":"# @botmetria/ucp — make your Node.js shop shoppable for AI agents\n\nStore-side SDK for **UCP** (Universal Commerce Protocol): AI agents discover\nyour store through `/.well-known/ucp`, read the catalog, build a cart via\ncheckout sessions and hand a signed cart link to the human — **payment always\nstays with your store**. Same protocol surface as the\n[Botmetria WooCommerce plugin](https://botmetria.com/) and the\n[`botmetria/ucp` Composer SDK](https://botmetria.com/help/ucp-custom/), for any\nNode.js platform: Express, plain `node:http`, custom engines.\n\n- **Zero dependencies**, Node ≥ 18, plain CommonJS (+`index.d.ts` types).\n- **Two capability levels** from one integration:\n  - a `ProductProvider` (`list`/`get`, sync or async) → agents see your catalog\n    (manifest honestly reports `checkout: false` — \"storefront mode\");\n  - add a `CartProvider` (`fill`) → full agent checkout with HMAC-signed cart\n    hand-off into your native checkout.\n- Wire format pinned by cross-implementation golden fixtures (`test/` verifies\n  parity with the WooCommerce plugin, the PHP SDK and the Botmetria cloud).\n- **Bonus**: the Botmetria AI-bot analytics collector ships as a second entry\n  point — one package for visibility *and* measurement.\n\n## Install\n\n```bash\nnpm install @botmetria/ucp\n```\n\n## Quick start (Express)\n\n```js\nconst { Ucp, ArrayProductProvider, expressMiddleware } = require(\"@botmetria/ucp\");\n\nconst ucp = new Ucp({\n  store_name: \"My Shop\",\n  store_url: \"https://my-shop.com/\",\n  currency: \"EUR\",\n  products: new ArrayProductProvider(items),  // or your own provider\n  // cart: myCartProvider,                    // optional: enables agent checkout\n});\n\napp.use(expressMiddleware(ucp));  // FIRST, before routes and body parsers\n```\n\nPlain `node:http`:\n\n```js\nconst { nodeHandler } = require(\"@botmetria/ucp\");\nconst handleUcp = nodeHandler(ucp);\n\nhttp.createServer(async (req, res) => {\n  if (await handleUcp(req, res)) return;  // the request was UCP's\n  // ... your app\n});\n```\n\n## Your adapters\n\n```js\nconst products = {\n  async list(offset, limit, query, category) {\n    return db.products.page(offset, limit); // canonical items: id, name, url,\n  },                                        // price, currency (+optional fields)\n  async get(id) { return db.products.byId(id); },\n};\n\nconst cart = {\n  async fill(items, ctx) {\n    // ctx = { req, res } of the hand-off request — attach YOUR session here.\n    const sid = readOrCreateSessionId(ctx.req);\n    await carts.replace(sid, items);\n    return { url: \"/checkout\", headers: { \"Set-Cookie\": `sid=${sid}; Path=/` } };\n  },\n};\n```\n\n~30 lines for catalog-only, ~50 with checkout.\n\n## Bundled analytics collector\n\n```js\nconst { middleware } = require(\"@botmetria/ucp/collect\");\napp.use(middleware()); // BM_SITE / BM_KEY / BM_SECRET from env — see the\n                       // Botmetria dashboard's connection instructions\n```\n\nCounts and (optionally) blocks AI-bot traffic; fail-open by design.\n\n## Sessions, rate limiting, orders\n\nCheckout sessions live 24h in a pluggable store (`MemoryStore` default —\nsingle process; `FileStore` for multi-process on one machine; bring your own\nRedis store for clusters). A sliding-window limiter (120 req / 60 s per IP)\nguards `/ucp/v1/*`. When an agent-born order is placed, call\n`await ucp.markOrdered(sessionId, orderId)` — sessions also carry `source`\n(chatgpt / perplexity / claude / …) detected from the agent's User-Agent.\n\n## Verify\n\nRun the free [agent purchase demo](https://botmetria.com/agent-demo/) on your\ndomain — a real agent walks manifest → catalog → cart against your store.\n\n## License\n\nMIT © Botmetria — [botmetria.com](https://botmetria.com/)\n","readmeFilename":"README.md"}