Stickybit.← E-commercePortuguêsAnalysis · agentic web · 2026
Agentic web · one store, two customers

Your store has a new customer. It has no screen.

The web is splitting in two: the one people see and the one AI assistants read to research and buy. Paying, reading, searching and acting for these assistants is already in production. The same product page has to serve both, and today almost none does.

See my store the way the agent does
Specimen · one product page, three visitors
How the store delivers the page
    0/3tasks done
    0/7fields read
    —Where it gets stuck

    Illustrative: the page, the product and the results are an example we built, not a measurement of a real store. Each visitor behaves the way we see in the readings we run; every assistant has its own habits, and some do run JavaScript.

    In everyday life

    Whoever shops for you does not look at the window.

    Picture sending someone to the supermarket with a list: "washing powder, the 2 kg one, if it is under R$ 40". That person does not care about the window display, the music or the poster. They read the label: what it is, what it costs, whether it is there. If the label is smudged, they go to the store next door.

    The AI assistant is that shopper, at scale. It does not see the photo or the animated button: it reads the product data sheet written for machines, the structured data that states price, currency, stock, delivery time and barcode. Everything the store polished for human eyes, it skips.

    The infrastructure underneath is the same (servers, network, payment rails). What changed is that the same page now has two customers, and each needs a different entrance.

    WHAT THE PERSON SEES Pedestal fan ★★★★☆ 812 R$ 149,90 Arrives in 3 days · free shipping Buy WHAT THE ASSISTANT READS price: 149.90 currency: "BRL" in_stock: true delivery_days: 3 gtin13: 7891…895 rating: 4.3 order_url: /checkout No photo, no color, no animation. If the number is not here, it does not exist.
    The same product page, two readings. For the assistant, anything not written as data simply does not exist.
    What already works

    Five pieces, all already in production.

    Within a few weeks of 2026, companies that coordinated nothing with each other launched the infrastructure for the assistant to pay, read, search, act and be watched. It is not a roadmap: these are announced products. Below, what each piece does, without acronyms.

    Layer 1Pay · the agent with a wallet
    • Coinbase: the X402 protocol for machine-to-machine payments
    • Stripe: payment tokens with a time and spend limit: the agent buys without seeing the card number
    • Visa: trusted agent protocol (NRF, Jan 2026)
    • Google: Universal Commerce Protocol, an open standard

    Stripe had to retrain its fraud detector from scratch: decades of signals (mouse movement, time on page) are worthless when the buyer is software.

    Layer 2Read · the page in machine format
    • Cloudflare: "Markdown for Agents": serves the page as clean text when the visitor is an agent
    • llms.txt: a sign on the door saying where the machine-readable content is

    Cloudflare serves roughly a fifth of the web. When it decides that an agent is a customer, not a pest, the rule changes for many stores at once.

    Layer 3Search · search built for software
    • Brave, Exa, Firecrawl: search and extraction that return data, not a page of links

    In an independent test cited in the account, Brave answered in 669 ms and Perplexity Pro in 13.6 s. Across a chain of ten searches, that adds up to minutes.

    Layer 4Act · the agent that works
    • OpenAI: Skills and Shell Tools: a real environment to install, run and deliver
    • MCP: the standard socket an agent uses to call a system’s functions

    The agent stops just advising and starts doing: making a video from a product page, filling in an order, checking stock.

    Layer 5Protect · treat the agent as a suspect
    • Isolated containers: the agent runs in a closed box, with a list of what it may reach
    • Keys in hardware: spending limits the agent cannot change

    The right mental model is to treat the agent as a potential adversary, not a trusted employee. Most stores have not thought about this yet.

    Our reading, based on the companies’ announcements and a video account of the "agentic web" (transcript in our notes). The figures quoted in that account, such as X402’s 50 million transactions and the Brave and Perplexity timings, were not checked by us against the primary source.

    The fight has started

    Amazon shut the door on another company’s agent.

    On 20 September 2026 Amazon blocked Muse, Meta’s shopping assistant. According to Amazon, it entered the store without warning, did not identify itself as a robot and seemed to store customers’ passwords. Meta denies it and says the agent runs on the user’s phone.

    There is money in the middle: Forbes pointed to Amazon’s US$ 68 billion in ads, which depend on a person looking at the screen. And there is a contradiction: Amazon has its own agents, Rufus and "Buy for Me", which buys in other stores on the customer’s behalf.

    The lesson for a smaller store is neither "block" nor "let everything in". It is to decide which door the agent uses: identified, with the functions you chose and without taking anyone’s password. Without such a door, the agent comes in pretending to be a person, and then not even you know who is buying.

    Customer "buy it for me" Muse (Meta) outside agent Rufus · Buy for Me Amazon’s own agents Amazon ✗ blocked ✓ let in US$ 68 bn in ads that need a human on screen 20 Sep 2026 · per Bloomberg, GeekWire and Forbes
    Whoever controls the door controls the margin. The fight is over who gets to stand between the customer and the store.
    Every new door is also a gap

    What gives the agent power also gives power to whoever fools it.

    Every piece in the board above cuts both ways. The rule we take from real 2026 incidents: everything the agent reads is suspect, including your own page, because hidden text can give it orders. And the gate that matters most is the exit: what the agent is allowed to send out, pay for or confirm.

    Wallet

    Proper usepay on its own
    Attackget drained
    Protectioncap and expiry

    Running commands

    Proper usedo the work
    Attackrun an injected order
    Protectionisolated box

    Searching

    Proper usefind the product
    Attackland on a lure
    Protectioncheck the source

    Reading the page

    Proper useunderstand the offer
    Attackhidden text
    Protectionread, never obey
    ~70%of control people say they want to keep over what they delegate to agents
    100%is the autonomy the new infrastructure assumes
    passwordstored by the agent was one of Amazon’s stated reasons against Muse

    The "~70%" comes from the same video account, without the original survey cited: read it as an order of magnitude, not a measurement. The distance between what the infrastructure allows and what people accept is where the risk lives, and where a confirmation gate makes the difference.

    We have seen this movie

    The phone in 2007, the agent in 2026.

    In 2007 the web worked on phones, technically. But it was built for the desktop, and it took a decade to rebuild. Those who noticed the change of customer early won the following decade. The comparison is our reading, not a forecast with numbers.

    Phone, 2007Agent, 2026
    The new customersmall screen, touch, GPS, camerascreenless software that reads, decides, pays and acts
    What was missingGPS, notifications, tap to pay, app storesmachine-readable data sheets, token payments, search for software, a place to run
    What the store had to redopages that fit the screen; an appa ready page with the data sheet; a door for agents
    Where Stickybit comes in

    First, see your store through the agent’s eyes.

    The free reading shows, with evidence, what a shopping assistant can read in your store today: whether the page arrives ready, whether the data sheet exists and matches the storefront, whether the site’s doorman turns away the wrong visitors, whether the barcode is there.

    Then comes the work: fix what is missing, open a door for agents with the functions you choose (see the store’s socket) and put a confirmation gate on anything that moves money.

    Request the free reading

    What the agent checks

    Page arrives ready?
    Product data sheet?
    Sheet matches the storefront?
    Barcode?
    Doorman lets it in?
    Shipping without a form?
    Door for agents?
    Free readingin 24 h
    each item comes with the evidence: what the agent received
    Three words on this page
    Shopping assistant

    The AI that researches, compares and buys for the customer: ChatGPT, Gemini, Muse. It is the "agent".

    Machine-readable data sheet

    The page’s structured data: price, currency, stock, barcode, written for software to read without guessing.

    The site’s doorman

    The system that turns away automated visitors. If it cannot tell a legitimate agent from any robot, it shuts the door on the new customer.

    All the section’s words, explained →

    Limits

    Where this may be wrong.

    Some sources are second-hand

    Several figures on this page come from a video account of the agentic web, not from each company’s primary source. We flag where that happens.

    Agent traffic is still small

    Today, the share of purchases made by agents is small. The point is not today’s volume: it is that the entrance takes time to build and the new customer is growing fast.

    Standards may die

    Payment, reading and discovery protocols are fighting for room. Not all will survive. That is why we recommend what holds in any scenario: a ready page, a correct data sheet, an identified door.

    The specimen simplifies

    Each assistant behaves differently, and some do run JavaScript. The real reading of your store is what answers, not this page’s example.

    See also

    ← Agent-ready e-commerce · stickybit.com.br

    Sources