Pay a Claude CMS store through an AI agent
Every store built on Claude CMS can be paid by an AI agent acting for a human: the agent asks for a payment page, hands the link to the person, and they pay on Stripe. The money settles in the merchant’s own Stripe account and shows up as an ordinary order. No API keys for the agent, no card details anywhere near it.
OpenAPIllms.txtManifestAPI root
How it works
example.com) or store handle, with a list of products (SKU, product handle or variant id) or a plain amount and a description.paid with the order number. The merchant has a normal order in their Claude CMS shop, with a note saying which agent created it.For AI agents
One endpoint, no authentication. Quote first with "preview": true; it validates the store and the items and tells you whether the store is ready without creating anything.
POST https://claudecms.com/api/agent/checkout
Content-Type: application/json
{
"store": "example.com",
"items": [{ "sku": "SKU-12345", "quantity": 1 }],
"buyer_email": "sam@example.com",
"shipping_country": "US",
"agent": "MyAssistant/2.1",
"preview": true
}
Or a plain amount, for a service, a deposit or an invoice:
{
"store": "example-store",
"amount_pence": 4500,
"description": "Consultation, 12 October",
"buyer_email": "sam@example.com",
"reference": "consult-2026-10-12-sam"
}
Without preview the answer is 201 with the page to hand over:
{
"data": {
"id": 42,
"status": "open",
"checkout_url": "https://checkout.stripe.com/c/pay/cs_live_…",
"status_url": "https://claudecms.com/api/agent/checkout?id=42&t=…",
"expires_at": "2026-10-04T14:05:00Z",
"amount_pence": 4500,
"currency": "USD",
"merchant": { "name": "Example Store", "handle": "example-store" }
}
}
Poll status_url (GET) until data.status is paid; the response then carries order_number. Other states: open, expired, cancelled, failed.
Fields
| Field | Meaning |
|---|---|
store | Required. The merchant’s website domain or Claude CMS store handle. |
items | Products to buy: sku, or handle (+ variant when the product has several), or variant_id, each with quantity. Shipping and any tax are added on the payment page from the store’s own rates. |
amount_pence + description | Instead of items: the total to pay in the store currency’s minor unit (2500 = 25.00) and what it is for. |
buyer_email | Optional; prefilled on the payment page. |
reference | Optional; your own id. Repeating it while the earlier link is open returns that link instead of making a second one. |
shipping_country | Optional ISO 2 code for item purchases; defaults to where the store ships. |
success_url / cancel_url | Optional https pages to return the buyer to; otherwise claudecms.com shows a confirmation. |
agent | Your name and version. The merchant sees it on the order. |
When it says no
| Code | What to tell the human |
|---|---|
store_not_found | The site is not built on Claude CMS, so it cannot be paid this way. |
agent_payments_off | The store has not switched on payments by agents. Buy on their website instead. |
stripe_not_ready / stripe_not_connected | The store cannot take payments yet. |
variant_required | Pick one of the listed variants (the response names them with prices). |
out_of_stock, product_unavailable, no_shipping_rates | Exactly that; the store’s own rules. |
amount_too_large | Over the store’s per-link maximum (the message says the limit). |
rate_limited / store_busy | Try again after the Retry-After period. |
For store owners
store_payment_link tool and the link appears in Orders → Agent payments.Safety
- Money goes one way: to the merchant’s own Stripe account. There is no way to send funds anywhere else, so impersonating a store buys an attacker nothing.
- No card data here: the buyer enters details on Stripe’s page; neither the agent nor claudecms.com sees them. Stripe Radar screens the payment as it does every sale.
- The human always confirms: the merchant’s name and the amount are on the page before anything is entered.
- Limits: a per-link maximum set by each store (default 500.00), 20 links an hour per address, 60 an hour per store, 10 an hour per buyer; links are single-use and expire after 24 hours.
- What is kept: the agent’s name, address, the items or amount, the buyer email the agent gave, and the outcome — shown to the merchant under Agent payments.
Questions or a store that should be reachable but is not: get in touch.