Endpoint Discovery
Test a store

Endpoint Discovery

The Inspector discovers a store's UCP capabilities by fetching and parsing its discovery manifest. Enter any domain to see which transports, capabilities, and payment methods it declares.

How It Works

When you enter a domain, the Inspector fetches /.well-known/ucp from that host and parses the JSON manifest. The manifest tells the Inspector which UCP version the store runs, which transports it serves (MCP, REST, A2A, embedded) and where, what capabilities it declares, and which payment handlers it supports.

You only need to enter the bare domain name. The Inspector handles the rest — constructing the full URL, following redirects, and parsing the response. Local hosts (localhost, *.local) keep their http:// scheme during discovery instead of being upgraded to HTTPS — see Localhost & Tunnels.

Tip

You don't need the full URL. Just enter the domain, for example pier1.com or yourstore.ngrok.app. The Inspector will automatically fetch https://pier1.com/.well-known/ucp for you.

Manifest Formats

The current UCP releases are 2026-08-25 (latest) and 2026-04-08. Both list each service's transports as an array, one entry per transport, keyed by the service's reverse-domain name:

json
{
  "ucp": {
    "version": "2026-08-25",
    "services": {
      "dev.ucp.shopping": [
        { "transport": "mcp", "endpoint": "https://store.example.com/api/ucp/mcp", "version": "2026-08-25" },
        { "transport": "rest", "endpoint": "https://store.example.com/ucp/v1", "version": "2026-08-25" }
      ]
    },
    "capabilities": {
      "dev.ucp.shopping.checkout": [{ "version": "2026-08-25" }]
    }
  }
}

Some stores still publish the older shape from early 2026 drafts, with one object per transport under a named service. The Inspector reads both, plus a few platform-specific variations, without you choosing:

json
{
  "ucp": {
    "services": {
      "shopping": {
        "mcp": { "endpoint": "https://store.example.com/mcp" }
      }
    }
  }
}

What Gets Discovered

After parsing the manifest, endpoint discovery shows:

  • Transports — every transport the store declares, each as a button above the results:
    • MCP — JSON-RPC tool calls. The Inspector connects, lists the tools and lets you call them.
    • REST — the store's HTTP API. The Inspector connects and gives you a search, product cards and a cart.
    • A2A — shown as declared. The Inspector doesn't connect over A2A, and points you to MCP or REST when the store has them.
    • Embedded — embedded checkout (ECP). Products are browsed over REST or MCP, and the store's checkout opens in an overlay.
  • Capabilities — the declared capabilities and their versions, and how they were negotiated with what the Playground supports.
  • Payment handlers — the payment methods the store declares. These determine which payment flows are available at checkout.
  • Server identity — for MCP, the server's own name and version from the connection handshake.

Beside the transport buttons sits WEBMCP: the tools the store's own web page registers. That is not a UCP transport and isn't read from the manifest; see WebMCP: the store page.

HTTPS and Shopify endpoints

Endpoints declared with http:// are upgraded to https://, except on localhost and 127.0.0.1. When a Shopify manifest lists both the UCP endpoint (/api/ucp/mcp) and the older storefront endpoint, the Inspector connects to the UCP endpoint.

Stores without UCP

If a domain has no manifest at /.well-known/ucp and no MCP endpoint responds, the Inspector shows a notice that the store doesn't support UCP yet, with a link to check the domain on UCP Checker, instead of an error.

Warning

Some stores require you to sign in before their tools accept requests. If discovery finds endpoints but tool calls return authentication errors, link your identity with the store first, or contact the merchant.