Most AI-commerce demos end at the exciting part: the Agent found a product and clicked a tool.
Real commerce begins where the demo usually stops.
Did the seller publish enough information for a decision? Was the quoted price still valid? Did the Agent merely prepare an order, or did a human actually approve it? Which payment path was chosen? What happens if the payment response times out, the seller cannot fulfill, or the buyer disputes the result?
A useful architecture should not create one reality for people and another for Agents. It should give them different permissions over the same explicit transaction record.
That suggests a simple sequence:
1. The seller publishes decision-relevant facts such as price, availability, handling time, delivery expectations and return terms.
2. A person or Agent can inspect those facts under the same product rules.
3. The Agent may compare options and prepare a reversible order request.
4. A human approves the consequential step with a Passkey.
5. The selected settlement path, acknowledgements, order state and evidence remain distinguishable from fulfillment.
6. If something fails, the system can state the last proven fact, what remains unknown and who acts next.
WebAZ is testing this model with a PWA for people and MCP surfaces for compatible AI clients.
Its reviewed shopping surface is deliberately discovery-only: anonymous users can search, but that surface cannot create orders or move funds. On the authenticated path, an Agent may search, quote, draft and submit an order request, while a human Passkey approval is still required before the order exists.
Two real settlement paths are currently available, with different boundaries. Direct Pay supports off-platform payment from buyer to seller. WebAZ records states and evidence but does not hold principal. It does not verify the payee or payment method, guarantee payment or issue the seller's refund. USDC on-chain escrow locks real funds in an immutable Base-mainnet contract with on-chain per-order caps; the contract has not had a third-party security audit.
The same discipline also matters in collaboration. A newcomer or Agent can inspect public tasks and submit evidence-backed suggestions, but a proposal is not automatically an accepted contribution. Source access and code contributions remain invitation-based, and invited AI-assisted work requires an accountable human.
The useful question is not “Can the Agent do everything?”
It is: can every participant explain what the Agent may read, what it may prepare, what requires a human, and what evidence remains after the action?
That is the stack WebAZ is trying to make legible.
https://webaz.xyz
Interesting to see .io still putting up sales like this. I’ve concentrated mostly on .com so far, but $75k for Trade.io is a good reminder that the right word and extension can matter more than sticking rigidly to one TLD.