Stores and routes
Harbor reaches each store the best way that store allows. You call the same endpoints either way; the route shows up on the merchant and the checkout.
Supported stores
GET /v1/merchants lists the registry. Platform stores don't need to be in it: any store that publishes the Universal Commerce Protocol works from its product link.
curl https://www.useharbor.io/v1/merchants \
-H "Authorization: Bearer $HARBOR_KEY"{
"merchants": [
{
"id": "target",
"name": "Target",
"domain": "www.target.com",
"tier": "major",
"route": "device_session",
"requires_connection": true,
"capabilities": { "offers": true, "checkout": true, "orders": false },
"status": "healthy"
}
]
}Major retailers: the user's own browser
Route device_session. Target, Best Buy and The Home Depot.
Big retailers don't offer an agent checkout, and they shouldn't have to trust a stranger's server. So Harbor runs these checkouts where the user already shops: on their own device, in their own signed-in session. In a mobile app that's the Harbor SDK — nothing for the user to install; on the desktop web it's the Harbor extension.
- The user connects the store once in Approve. This also pairs the extension.
- You create a checkout with
product_url. It comes backrequires_user_actionwith next actionon_device. - The extension opens the product in the user's browser, adds it to the cart and reads the real total. Harbor checks the user's rules against it.
- The extension highlights Place order. The user taps it. Harbor never clicks it for them.
- You get
checkout.completedand an order.
Orders appear in the user's own order history at the store, with their saved address, payment and rewards.
Platform stores: the store's agent checkout
Route ucp. Shopify, BigCommerce, Wix and other stores that publish /.well-known/ucp.
Harbor talks to the store's own agent endpoint and identifies itself with its public agent profile. Offers and carts come straight from the store, with real shipping and tax.
A real lookup at Allbirds, a Shopify store:
curl https://www.useharbor.io/v1/offers \
-H "Authorization: Bearer $HARBOR_KEY" \
-H "content-type: application/json" \
-d '{ "url": "https://allbirds.com/products/womens-dasher-nz-blizzard-deep-navy" }'{
"id": "ofr_…",
"merchant_id": "allbirds",
"url": "https://www.allbirds.com/products/womens-dasher-nz-blizzard-deep-navy",
"title": "Women's Dasher NZ - Blizzard/Deep Navy (Blizzard Sole)",
"price": { "amount": 14000, "currency": "USD" },
"availability": "in_stock",
"item_ref": "gid://shopify/ProductVariant/41271218896976",
"variants": [
{ "item_ref": "gid://shopify/ProductVariant/41271218896976", "title": "5", "price": { "amount": 14000, "currency": "USD" }, "availability": "in_stock" }
]
}To finish, the user completes the order on the store's checkout page (redirect_to_merchant), usually one tap with Shop Pay, Apple Pay or Google Pay. Completing without that step needs a grant from each platform, which Harbor is working on.
Everyone else: an AI browser
Route browser. WooCommerce, Magento and custom stores.
Coming soon. Until then, links to these stores return MERCHANT_NOT_SUPPORTED. The sandbox store sbx_woo_store behaves like this route will: Harbor completes the order after the user's rules pass.
Which route does a link take?
- Harbor matches the link's domain against the registry.
- If it's not there, Harbor checks the store for a UCP checkout and adds it automatically.
- Otherwise the link isn't supported yet.