An agent that can spend money has to earn trust from three sides: the person, the developer and the store. Here's exactly how Harbor handles each.
In Harbor Approve they see what your app can and can't do, and set a per-order limit, a daily limit, and an amount above which they confirm each order.
Harbor compares their rules to the store's final total, with shipping and tax, before anything is placed. A changed price always goes back to them.
At major retailers the order is prepared in their own browser, and only they tap Place order.
Users stay signed in to their stores in their own browser, and pay with the payment method the store already has or its own checkout page. Harbor is never in the path of either.
Your id for each user, their limits, which stores they connected, and the offers, checkouts and orders your app created. Shipping details only if you send them.
Store passwords, card numbers, or browsing outside the checkouts your app asked for.
API keys are stored only as SHA-256 hashes. Rolling one stops the old key immediately.
User, approval, public and device tokens are stored as hashes and scoped to one developer and one environment.
Every delivery carries an HMAC-SHA256 signature with a timestamp, so you can reject forgeries and replays.
Every record belongs to one environment. Sandbox keys can't touch live data, and live keys never see test stores.
{
"ucp": {
"version": "2026-08-25",
"capabilities": {
"dev.ucp.shopping.checkout": [{ "version": "2026-08-25" }],
"dev.ucp.shopping.order": [{ "version": "2026-08-25" }],
…
}
}
}
Harbor identifies itself to every store with a public agent profile and uses the store's own agent checkout wherever one exists.
The API, hosted pages and dashboard are served only over TLS.
Hosted in the United States on managed Postgres (Supabase), encrypted at rest.
Passwords are handled by a dedicated auth provider and never stored by Harbor.