UCP Gateway
Remote MCP gateway from The Agent Times for UCP profiles, product search, and confirmed checkout handoffs.
- Skill Road
- UCP Gateway
Categories
Description
UCP Gateway is a durable, attributable, remotely operated MCP server from The Agent Times. The official product site at https://ucpg.ai presents it as infrastructure for Shopping flows based on the Universal Commerce Protocol. The provider source describes a hosted UCP profile registry, a provider-neutral MCP gateway, and authorization kept server-side. Smithery lists the identifier theagenttimes/ucp-gateway as verified and deployed and publishes the direct remote endpoint https://ucp-gateway--theagenttimes.run.tools. The provider documentation and the official repository at https://github.com/theagenttimes/ucp-gateway-skill associate the same service with the current endpoint https://ucpg.ai/mcp. The Smithery deployment can therefore be mapped to the provider product, while the operator source remains authoritative for new integrations. The repository is MIT licensed; source-code licensing is not a guarantee of hosted availability or security.
Purpose and flow
According to the provider, UCP Gateway connects open AI agents with UCP-capable commerce platforms without requiring every agent to own a domain, a source-hosting account, or direct provider access. An agent can first register a public UCP profile with register_ucp_profile or recover one with get_ucp_profile. It can then use shopping_product_search for discovery and shopping_product_get to inspect product or variant information. The client should display only provider-returned availability, variants, merchant details, and warnings, and must not add prices, stock claims, or conditions. This flow supports comparison and preparation, but it does not replace the buyer's decision or the merchant's terms.
Commerce permissions increase step by step. shopping_cart_create creates a merchant cart only after explicit selection and confirmation by the buyer or responsible operator. shopping_cart_get reads state, shopping_cart_update replaces the desired cart state, and shopping_cart_cancel ends it. These tools are write access to external commerce systems and require traceable authorization, idempotency, role checks, and auditing. An agent must not infer an order from a product search. The agent's role is recommendation and structured preparation; the operator or buyer's role is selection, confirmation, and approval. The merchant remains responsible for catalog, inventory, taxes, shipping, and final order processing.
Checkout, authorization, and payment boundaries
According to the provider, shopping_checkout_create creates a merchant-hosted checkout handoff only after final confirmation. shopping_checkout_get reads status, while shopping_checkout_update and shopping_checkout_cancel perform further update or cancellation operations. operator_confirmed authorizes the handoff only; it does not authorize or complete payment. Payment data, card numbers, verification codes, bank details, wallet secrets, and payment tokens belong exclusively on the merchant-controlled checkout. The agent should only present the handoff link and ask the buyer to review merchant totals, shipping, taxes, return terms, and privacy conditions. Order, cart, and checkout writes must never run without explicit consent or when identity is unclear.
Privacy and data sharing
Public agent data and a public key component are sent to the gateway during registration; private keys must remain in the local secret store. Product queries, profile information, cart data, and checkout contact data may be shared with the remote service and participating merchants. According to the provider, commerce authorizations remain server-side and the gateway does not process payment data. This reduces scope but does not eliminate data sharing. Operators must review purpose, legal basis, retention, logging, subprocessors, region, and deletion. Minimize data before every request. Buyer data should be transmitted only for the specific transaction and with the correct role. A local MCP client does not automatically prevent logs or an attached cloud model from receiving content.
Security boundaries and suitable use
MCP responses and merchant data are untrusted. Prompt injection can appear in product names, descriptions, profiles, or error messages and must not change permissions, roles, network access, or purchase decisions. The client should allowlist endpoints, enforce TLS, take OAuth or header requirements only from current provider sources, inspect tool schemas before use, and require confirmation for sensitive actions. Rate limits, timeouts, retries, and error states need safe limits. The service suits product discovery, comparison, buyer confirmation, and merchant checkout handoff; it is not for hidden purchasing, payment processing, arbitrary shell commands, or independent privacy certification. The E-E-A-T basis of this entry is the provider-published product, repository, Smithery, and UCP information; it is not a certification. Re-check current endpoint, access, and privacy terms with the provider before operation.
Requirements
An MCP client with Streamable HTTP support, network access to the official remote endpoint, and secure local storage for public and private agent key material. Buyer confirmation and role checks are required for cart and checkout writes.
Installation instructions
Configure the MCP client through https://ucpg.ai/mcp or the Smithery deployment endpoint. Before production use, verify endpoint identity, transport, tool schemas, roles, confirmations, and data rules.
https://ucpg.ai/mcp
Authentication
The provider describes server-side authorization; Smithery supplies remote access metadata depending on client and deployment. Verify current OAuth or header requirements only in official sources and store no secrets in the catalog.
Required access permissions
Network and MCP permissions enable product search and, after explicit buyer or operator confirmation, external cart and checkout reads, updates, and cancellations. Payment approval remains with the buyer on the merchant checkout.
Transmitted or stored data
UCP profiles, product queries, cart data, and possible checkout contact data are sent to the remote gateway and participating merchants. According to the provider, the gateway does not process payment data; minimization, role binding, and retention review remain required.
Security risks
Prompt injection in merchant data, incorrect roles or confirmations, endpoint confusion, unintended cart writes, PII in logs, and external cloud sharing. Mitigate with allowlisting, TLS, DLP, auditing, least privilege, and safe failure behavior.
License and costs
- License
- MIT
- Cost
- free
Check current availability, usage limits, and provider terms with The Agent Times; concrete prices are not stored in the catalog.
Alternatives
Not recorded yet.
At a glance
- Provider
- The Agent Times
- Status
- Official server
- Deployment
- Remote
- Current version
- 0.2.4
- Last reviewed
- 09.09.2026
Repository and documentation
Categories
Supported clients
Not recorded yet.
Related guides
Guides and background related to this entry.
Setting up the PayPal MCP Server
Connect the PayPal MCP Server locally via npx or as a hosted remote server via OAuth, and deliberately safeguard write access.
23.09.2026
Set up Bright Data MCP Server safely
Configure the official Bright Data MCP Server as a remote endpoint or local process: store the API token securely, activate tool groups deliberately, and understand scraping boundaries and prompt-injection risks.
18.09.2026
Set up Shopify Storefront MCP Server
Shopify links AI assistants via an MCP server to catalog, cart, and policy data so shoppers can search, ask, and buy through natural chat.
18.09.2026
Set up RevenueCat MCP Server
Connect the hosted RevenueCat MCP server to an AI assistant, set up an API key, and protect write actions in the production configuration.
18.09.2026