Signatures that do not verify
Request signing under RFC 9421 implemented against the wrong covered components, and order webhooks delivered unsigned and without retry.
Practice
Agentic checkout fails on protocol, not on prose. We find those defects in the reference implementations, send the fix upstream, and keep a public checker that catches each one on the way back.
None of these are model problems. Every one of them has shipped in a reference implementation.
Request signing under RFC 9421 implemented against the wrong covered components, and order webhooks delivered unsigned and without retry.
Keys scoped too widely, and a lost race answered with a 500 instead of the result the winner already committed.
Validation failures answered with a framework default shape instead of the error envelope the specification requires.
Code generation silently dropping value constraints, conditional rules and dependent requirements, so a schema check passes what the specification forbids.
Currency, totals, identifiers and omit marked members copied from the request into the response.
Roughly 99% of stores pass conformance while real agent checkouts still fail. The agent lane grades behaviour, not shape.
spck.dev/check points at any Universal Commerce Protocol server and returns a capability scoped report, in the browser with no install, or from PyPI in your CI.
Independent and unofficial. It reports only the checks it runs and never claims certified.
65 pull requests merged across the specification, both official SDKs, the reference samples and the official conformance suite, plus 53 defect reports filed.
Every check in the suite exists because the defect it catches was found, reported and fixed upstream first.