Document AgentCard checkout origin matching - #652
hiroTamada wants to merge 2 commits into
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 99d998e. Configure here.
| `merchant_origin` from its preparation instead of this field. Card updates | ||
| replace the full `spec`, so include `checkout_origin` again when you want to | ||
| keep using it. An autopilot match doesn't guarantee processor acceptance or | ||
| payment success. |
There was a problem hiding this comment.
Packed checkout origin caveats paragraph
Low Severity
The checkout_origin paragraph now combines origin format, non-prepared versus prepared behavior, omit semantics, full-spec replace rules, and separate autopilot-approval caveats in one run of prose. Those are distinct constraints that are hard to scan together.
Triggered by learned rule: Use bullet lists when covering multiple distinct points in guides
Reviewed by Cursor Bugbot for commit 99d998e. Configure here.


Summary
checkout_originmatching for non-prepared checkout authorizations, including canonical origin requirements and prepared checkout behavior.Validation
git diff --checkTesting
Note
Low Risk
Documentation-only changes with no runtime or API behavior modified in this PR.
Overview
Documents the optional
checkout_originfield on AgentCard vault card specs and how it affects non-prepared checkout authorizations.The AgentCard guide now shows
checkout_originin create/update examples (TypeScript, Python, CLI), adds canonical origin rules (HTTPS shop origin orhttp://localhost), and clarifies that Kernel forwards the caller-supplied value to AgentCard for autopilot rule matching—not as payment approval—and that prepared checkout still uses preparationmerchant_origin. It also notes full-spec updates must re-include the field, autopilot matches can still fall back to user approval, and Kernel does not verify the origin against the browser page (apps must set it from trusted checkout context).The changelog gets a September 30 entry for the product capability and these doc updates.
Reviewed by Cursor Bugbot for commit 99d998e. Bugbot is set up for automated code reviews on this repo. Configure here.