One Commerce Protocol, Two Interfaces: Keeping AI and Human Actions Aligned
As AI agents gain the ability to perform commercial actions alongside human users, splitting the underlying transaction model between the two interfaces creates dangerous inconsistencies in state, permissions, and outcomes. The safer architectural approach is to build both a Progressive Web App (PWA) for humans and a Model Context Protocol (MCP) server for agents on top of a single shared state machine. Each interface handles what it does best — humans manage identity, review terms, and approve sensitive steps, while agents handle structured discovery, comparison, and request preparation. Authorization is made explicit through a capability matrix, where agent permissions must name specific actions and their boundaries rather than inheriting broad access from a credential. Irreversible or high-risk actions require live human approval via a Passkey ceremony in a browser, a protocol-level requirement that no agent scope declaration can override.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in