Your next customer may never visit your store.
They ask an agent on ChatGPT, Gemini or Copilot, and it comes back with three options. If your products, stock, delivery promise and terms are not readable by that agent, you are not one of them, and unlike an abandoned cart you never find out. Nyx makes what your systems already know answerable by an agent, and decides on the agent when it comes back to buy.
// and can they be returned?" · answered live · 74ms
{
"sku": "SKU_EXAMPLE…",
"in_stock": true,
"price": { "unit": 249.00, "currency": "SAR" },
"fulfilment": { "delivers_by": "2026-08-21" },
"policy": { "returns_days": 30,
"max_qty_per_customer": 5,
"agent_purchase": "allowed" },
"answered_from": "live inventory + your policy",
"audit_ref": "ofr_EXAMPLE…"
}
An agent has to find you before you get to decide about it.
Two jobs on the same shopfront, and they fail differently: one loses revenue you never see, the other loses money you have already booked. Both are the seller's, and both read the same catalogue and the same policy.
Products, variants, stock and price in a form an agent can read. The capabilities it needs before it commits: delivery windows, returns, warranty, financing, eligibility. Policy stated machine-readably: who may buy, quantity and geography limits, agent pricing rules. Answered from your systems at the moment of asking, not from last night's export.
PILOT READY
Is this agent what it claims, and who delegated to it. Was this purchase inside the mandate: scope, caps, expiry. Should it be accepted, challenged or refused. And can you reconstruct the call later, for a chargeback or a dispute.
OPEN TO DESIGN PARTNERS
Both sit on the seller's side. The trust half also exists on the issuing side, where a bank authorises its own cardholder's agent: the same engine, seen from the other end of the transaction.
The signals a fraud model leans on are the ones an agent does not have.
Not a new fraud typology to add to a model. A different actor, with a different kind of evidence.
Device fingerprint and reputation · typing cadence, dwell time, navigation path · session and IP as a proxy for the person · velocity read as human impatience · step-up challenges aimed at a human who is not there.
Agent credential and the principal it names · delegated scope: categories, merchants, purposes · per-transaction, daily and cumulative caps · mandate age, expiry and revocation · agent behavior over time, as its own baseline.
{
"action": "approve",
"score": 0.12,
"actor": { "type": "agent",
"agent_ref": "agt_EXAMPLE…",
"principal_ref": "cus_EXAMPLE…",
"credential": "verified" },
"mandate": { "in_scope": true,
"per_txn_cap": 1500.00,
"qty_within_policy": true },
"reason": "mandate verified · matches quoted offer",
"audit_ref": "dec_EXAMPLE…"
}
CONTEXT · AGENTIC PAYMENT RAILS LIVE 2025 (VISA TAP · MASTERCARD AGENT PAY · 2025) · $1.5T AGENTIC COMMERCE BY 2030 (JUNIPER · 2025) · 25% OF BREACHES FROM AI-AGENT ABUSE BY 2028 (GARTNER · 2024)
Most of this is machinery we already run.
Ingesting a catalog, canonicalizing it, holding policy and answering in real time is what the engine already does. The agent-facing surface is ready to pilot; deciding on the agent when it buys is the work in design.
Features, models, authored policy, a synchronous verdict under a hard timeout, and an audit record for every call. An agent transaction is another event through the same path.
Agent and principal as first-class entities, mandate and delegation as evaluable features, caps and scope enforced at decision time. Built on the credentials the rails already carry.
The surface a customer's agent reads: products, availability, the capabilities behind them, and policy in machine-readable form, answered live from your systems.
Two agents settling terms, bundles and substitutions under two sets of policy. We think the market gets here and the primitives point that way.
One catalogue slice, no replatforming.
We start with D2C brands, then smaller merchants, then marketplaces, acquirers and PSPs. That sequence is about where the first proof gets made, not about who we will work with.
How you get on it: enrol yourself, connect the catalog, and complete the setup steps. Then we review and approve the account before it answers a live agent. That review is deliberate. A platform that decides who can be trusted cannot let anyone switch itself on unchecked.
See yourself as an agent does
What an agent can read about your products today, where it gives up, and how much agent traffic is already hitting you.
Connect what you run
Your commerce platform, catalogue and stock, mapped once. Your store, checkout and PSP stay where they are.
Answer, and decide in shadow
A read-only agent-facing surface over a scoped set of products, while agent purchase decisions run beside your live checks.
Open it, narrowly
Widen the slice and start enforcing, with your own fallback and your own rollback, on evidence from your traffic.
What we are not claiming.
Agentic commerce is attracting a lot of language. Here is where ours stops, so an evaluator does not have to work it out in a meeting.
We do not issue agent identity.
Credentials belong to the networks and protocols carrying them. Nyx consumes what they present, checks it against the mandate, and decides.
We do not replace your commerce platform or PSP.
Your catalog of record stays where it is and money still moves on your existing rails.
We cannot promise you placement.
Readable is not the same as chosen. Ranking inside any agent surface belongs to that surface, and nobody can sell you a position in it.
Your platform may already cover part of this.
If it publishes a feed the agent surfaces consume, take it first. The gap is the live answer for a specific request, and the decision when the agent buys.
Agent-to-agent negotiation is direction, not product.
It is not in a pilot and not on a price list, and it carries a status label until it ships.
Nothing here is benchmarked.
Agent decision latency, accuracy and false-positive impact are design targets. Pilot numbers will replace them, and will say whose traffic produced them.
The rest of the engine, and how a pack declares a new decision domain, is on the Platform page →