Commerce connectors (sandbox)
NextThe connector catalogue, MCP gateway and spend firewall that let agents buy groceries, book cabs, order food and keep cloud bills inside budget.
Coming next. The connectors hub is being built now (wave T12) against sandbox simulators. No real merchant is connected, and we name categories rather than companies until a merchant agrees to a connector.
Agents need to buy from real services. The connectors hub gives them a catalogue of services and puts one spend firewall in front of all of them.
The pieces
| Piece | What it does | Status |
|---|---|---|
| Connector catalogue | A registry of external MCP servers and APIs. Each connector declares its merchant type (A to D below), what it can do, and which of its tools can spend money | Next |
| MCP gateway | An agent reaches every connector through one MCP connection to TatvaPay | Next |
| Spend firewall | Every tool call that can spend money is stopped and must pass the mandate, the rules and any approval; it then lands in the signed receipt. Other calls (search, menus, prices) pass straight through | Next |
| Sandbox simulators | Groceries on an ONDC/Beckn-style network, cab booking, food delivery and a cloud bill, so the whole flow works before real merchants sign | Next |
| Budgets for bills | For merchants that bill the customer directly: watch, alert before a limit, ask before an increase, help with a dispute | Next |
| ONDC buyer app | Real grocery and retail sellers on ONDC; needs ONDC registration (not an RBI licence) | Planned |
| Real merchant connectors | Added when a merchant exposes an API or MCP server and agrees | Planned |
How an agent pays, by merchant type
| Type | The merchant | How the agent pays | Status |
|---|---|---|---|
| A | Uses TatvaPay checkout (directly or through a platform) | TatvaPay checkout, MCP, ACP or AP2, then a mandate debit through a licensed payment aggregator | Next |
| B | Takes payments through another payment company | A second payment aggregator through routing, or the merchant adds TatvaPay agent checkout | Planned |
| C | Bills customers itself and has no agent API (cloud hosting, many apps) | The customer's own AutoPay with that merchant; our agent watches bills and enforces budgets. Card agent tokens later | Next (budgets), Planned (tokens) |
| D | Any UPI merchant | NPCI's agent payment standard, when final | Planned |
Rules the hub keeps
- Agents say they are agents. Each request carries the signed agent header from the agent passport.
- No scraping and no logging in as the customer. A connector exists only where the merchant offers an interface and agrees.
- Money is always gated. A connector cannot mark a spending tool as safe; the catalogue entry decides, and the firewall checks it on every call.
- The ₹2,000 rule applies everywhere. See Mandates and AutoPay.
Related: Agent checkout, MCP server, Integrations.
Last updated 2 October 2026
Something unclear or wrong? Tell us