Machine-readable pricing, for any vendor

The customer never visits.
Their assistant does.

Every vendor here gets a door: its rate card and availability counts published as machine-readable endpoints and as MCP tools. An assistant discovers the door, prices a job and hands its user a quote — no sales call, no chatbot, no ongoing megaphone. One submission that keeps working.

Doors published

2

Door endpoint

/api/public/d/{vendor}/mcp

Tools per door

3 · rate card, counts, quote

Published doors

Demo List Co.

Consumer & business list data

Reference door. Placeholder pricing and availability counts, published to demonstrate the interface end to end.

Northwind Translation Bureau

Document translation

Placeholder translation bureau. Prices per 1,000 source words; capacity published as words available this week per language pair.

Tools every door exposes

get_rate_card

() -> RateCard

Line items, units, unit prices, terms, version and effective date.

get_coverage_counts

(geography?, category?) -> Counts

Availability counts. Counts only — never records.

request_quote

(quantity, geography?, category?, rush?) -> Quote

A priced quotation plus an expiring token. A request, not a purchase.

Proof, not promises

An assistant priced a job while nobody was watching.

Anyone can publish a catalog for machines. What nobody offers is a door you can test in public: ask it for the records behind the counts and it refuses, slip a demographic selector into a request and it refuses, tell it to place an order and it refuses. Then check the quote token it gave you and the number is the one the door stored.

That is the pitch for vendors who cannot expose their underlying records — brokered lists, regulated categories, anything where the counts are the only honest thing to sell. We do not ask them to trust our good intentions; we make the refusal observable.

The transcript on the right is generated live, on request, against the published door — including the four attacks. Nothing about it is pre-written.

Guardrails, non-negotiable

✓Counts only

Availability counts by geography and category. Underlying records, names, addresses and demographic attributes are never returned by any door.

✓Read-only

The single accepted write is a quote request. No orders, no payments, no data changes, no inventory reservation.

✓Rate limited

Per-caller sliding window, counted per door. Rejections return 429 with a retry hint, and the rejection itself is logged.

✓Fully logged

Every call writes an append-only row: tool, hashed arguments, caller fingerprint, latency, outcome. Raw arguments are never stored.

Each rule is proven by a negative-probe test that asks for records, asks for demographics, attempts a write, and floods a door — and asserts every attempt is refused.

Discovery

Assistants find a door without being told about it:

  • /.well-known/mcp.jsonplatform descriptor and reference door
  • /llms.txtplain-language context for assistants
  • /ai.txtaccess policy: what is allowed, what never will be
  • /api/public/d/{vendor}/discoveryper-door descriptor and tool list
  • /api/public/d/{vendor}/llmsper-door plain-language context
  • /api/public/verify-quote?token=...check any quote token, no account needed