OACP Merchant Self-Service Config Boundary
Canonical end-to-end flow: OACP authority overview.
AgenticOrg owns merchant self-service configuration. Grantex does not store merchant connector secrets, payment-provider credentials, bank secrets, raw POS payloads, or merchant onboarding UI state. Grantex receives public-safe authority requests and issues or refuses OACP artifacts from redacted evidence.
Configuration Scope
AgenticOrg scopes merchant commerce configuration by tenant, merchant, and seller agent. A merchant can create the config during Seller Commerce Agent onboarding and update it later.
The config may include:
Runtime-Supported Vs Pending Adapter
Authority Request Boundary
Grantex rejects authority requests that include raw secrets, raw provider payloads, private merchant payloads, executable checkout/payment/order/refund targets, unsupported live claims, or certification/standardization claims.
Public Wording
Safe wording:
- “Merchant configuration is owned by AgenticOrg and scoped per tenant, merchant, and seller agent.”
- “Shopify is the current runtime source connector.”
- “WooCommerce, ERP, bank-owned rails, and custom providers are pending adapter until approved.”
- “Grantex signs or refuses OACP artifacts; it does not execute payments or host merchant connector runtime.”
Unsafe wording:
- “Grantex runs every buyer/seller message.”
- Any wording that presents UCP, ACP, AP2, IETF, NIST, provider, or external-program certification as already granted.
- “Configuring a bank provider means live payment execution is enabled.”
- “WooCommerce or ERP sync is live before the adapter and tests exist.”
Last modified on June 25, 2026