Skip to main content

OACP Merchant Self-Service Config Boundary

Canonical end-to-end flow: OACP authority overview. AgenticOrg owns merchant self-service configuration. Grantex does not store merchant connector secrets, payment-provider credentials, bank secrets, raw POS payloads, or merchant onboarding UI state. Grantex receives public-safe authority requests and issues or refuses OACP artifacts from redacted evidence.

Configuration Scope

AgenticOrg scopes merchant commerce configuration by tenant, merchant, and seller agent. A merchant can create the config during Seller Commerce Agent onboarding and update it later. The config may include:

Runtime-Supported Vs Pending Adapter

Authority Request Boundary

Grantex rejects authority requests that include raw secrets, raw provider payloads, private merchant payloads, executable checkout/payment/order/refund targets, unsupported live claims, or certification/standardization claims.

Public Wording

Safe wording:
  • “Merchant configuration is owned by AgenticOrg and scoped per tenant, merchant, and seller agent.”
  • “Shopify is the current runtime source connector.”
  • “WooCommerce, ERP, bank-owned rails, and custom providers are pending adapter until approved.”
  • “Grantex signs or refuses OACP artifacts; it does not execute payments or host merchant connector runtime.”
Unsafe wording:
  • “Grantex runs every buyer/seller message.”
  • Any wording that presents UCP, ACP, AP2, IETF, NIST, provider, or external-program certification as already granted.
  • “Configuring a bank provider means live payment execution is enabled.”
  • “WooCommerce or ERP sync is live before the adapter and tests exist.”
Last modified on June 25, 2026