Security and trust

The user stays in charge.By design, not by promise.

An agent that can spend money has to earn trust from three sides: the person, the developer and the store. Here's exactly how Harbor handles each.

For the people your agent shops for.Limits they set, enforced on every order.

consent

They approve your app once

In Harbor Approve they see what your app can and can't do, and set a per-order limit, a daily limit, and an amount above which they confirm each order.

real totals

Limits checked at the last moment

Harbor compares their rules to the store's final total, with shipping and tax, before anything is placed. A changed price always goes back to them.

final tap

Place order is theirs

At major retailers the order is prepared in their own browser, and only they tap Place order.

what Harbor never sees

No passwords. No card numbers.

Users stay signed in to their stores in their own browser, and pay with the payment method the store already has or its own checkout page. Harbor is never in the path of either.

  • Harbor for Chrome never fills sign-in forms or reads what users type.
  • Platform store orders are paid on the store's own checkout.
  • Harbor never holds or moves the purchase money.
stored

What Harbor keeps

Your id for each user, their limits, which stores they connected, and the offers, checkouts and orders your app created. Shipping details only if you send them.

never stored

What it doesn't

Store passwords, card numbers, or browsing outside the checkouts your app asked for.

For developers.Credentials handled the way you'd want them handled.

keys

Hashed, shown once

API keys are stored only as SHA-256 hashes. Rolling one stops the old key immediately.

tokens

Hashed too

User, approval, public and device tokens are stored as hashes and scoped to one developer and one environment.

webhooks

Signed

Every delivery carries an HMAC-SHA256 signature with a timestamp, so you can reject forgeries and replays.

environments

Sandbox is sandbox

Every record belongs to one environment. Sandbox keys can't touch live data, and live keys never see test stores.

/.well-known/ucp-agent.json
{
  "ucp": {
    "version": "2026-08-25",
    "capabilities": {
      "dev.ucp.shopping.checkout": [{ "version": "2026-08-25" }],
      "dev.ucp.shopping.order": [{ "version": "2026-08-25" }],
      …
    }
  }
}
for stores

An agent that says who it is.

Harbor identifies itself to every store with a public agent profile and uses the store's own agent checkout wherever one exists.

  • No CAPTCHA solving, no disguised traffic, no evasion.
  • At major retailers, the user's own browser does the shopping, as the user.
  • If a store asks a question, the user answers it.

Infrastructure.Plain, well-understood pieces.

transport

HTTPS everywhere

The API, hosted pages and dashboard are served only over TLS.

data

Postgres, encrypted at rest

Hosted in the United States on managed Postgres (Supabase), encrypted at rest.

accounts

Dashboard sign-in

Passwords are handled by a dedicated auth provider and never stored by Harbor.