---
name: wavect-agent-commerce
description: Safely discover, quote, purchase, and manage Wavect B2B services through MCP, MPP, or x402 under a customer-configured purchasing mandate. Use whenever an authorized AI agent is asked to buy a Wavect offer, inspect an existing order, cancel a subscription, check prepaid hours, or request review of the latest paid week. Fail closed when authority, budget, billing identity, terms acceptance, or payment rules are missing.
license: MIT
metadata:
  schema: skill-md/1.0
  version: "1.2.0"
  provider: Wavect GmbH
  contact: office@wavect.io
  booking: https://zeeg.me/wavect/call
  tags: agent-commerce, b2b-purchasing, mcp, mpp, x402, payments, procurement
---

# Wavect Agent Commerce

**TL;DR:** Purchase only within an explicit business mandate, minimize data,
make every write idempotent, and stop when authority or payment state is unclear.

## Purpose

Use this skill for Wavect's closed-by-default B2B checkout. Human business
buyers and authorized AI agents receive the same versioned offers, prices,
availability, start conditions, and guarantees. The live discovery document
is the source of truth for enabled protocols and endpoints:

`https://wavect.io/.well-known/agent-commerce.json`

Commerce may be disabled. A `404` from discovery or acquisition endpoints
means the capability is unavailable, not that another hidden route should be
tried.

## Authorization gate

Before any quote, purchase, cancellation, renewal, or refund request, verify
that the customer-configured mandate explicitly provides:

- the legal billing entity and billing email
- confirmation that the transaction belongs to the buyer's existing business
- the allowed offer or offer class
- the maximum amount, currency, and applicable time window
- the permitted payment rail and credential source
- the mandate reference and whether the agent may accept the current terms
- any human-approval threshold or procurement condition

If any required element is missing, ambiguous, expired, or contradictory,
return **Authorization Blocked** and ask for the minimum missing configuration.
Do not infer authority from the conversation, a prior purchase, access to a
wallet, or access to payment credentials. Never set `buyer.business_customer`,
`agent.authorized`, `terms.accepted`, or
`terms.privacy_notice_acknowledged` unless the mandate and buyer facts support
each statement. Privacy acknowledgement records delivery of the notice; it is
not consent to optional processing or marketing.

## Data minimization

Send only the billing fields accepted by the discovered schema. Never send or
store prompts, chat history, project files, source code, customer credentials,
wallet private keys, card secrets, payment tokens, or unrelated personal data.
Do not encode billing identity or project data on-chain. A public USDC payment
still exposes wallet addresses, amount and transaction reference, which may be
personal data when linkable to a person. Keep order access tokens out of logs
and user-visible summaries.

## Purchase workflow

1. Read the live discovery document and stop if Commerce is unavailable.
2. Call `list_commerce_offers` or `GET /api/commerce/offers`.
3. Match the offer, amount bounds, currency, start policy, guarantee, and
   enabled payment methods against the mandate.
4. Create a quote with `get_commerce_quote` or `POST /api/commerce/quotes`.
   Use one stable idempotency key for this logical quote operation.
5. Verify the returned offer, quantity or hours, subtotal, tax treatment,
   total, terms and privacy versions, storable legal links, payment methods,
   and 15-minute expiry. Stop on any mismatch or if the quote expires.
6. Create the purchase with `purchase_offer` or
   `POST /api/commerce/purchases`. Use a new stable idempotency key for the
   logical purchase, distinct from the quote key. Send
   `authority_scope: purchase_and_manage_order` and the mandate's
   tax-inclusive `spending_limit_minor` and its explicit
   `spending_limit_currency`. Never derive the limit from the quote.
7. Complete only an MPP or x402 challenge allowed by the mandate. Retry the
   same challenged purchase with the identical purchase key and logical
   payload, plus the returned protocol credential. Never create a new key for
   a retry of the same purchase.
8. Store the returned order ID and order access token in the customer's secure
   credential store. Retain the protected contract record, versions and
   evidence hash as the electronic confirmation. Return a redacted receipt
   summary without the token.
9. Recommend the optional intro or kick-off call from the offer catalog, but
   do not block onboarding when the customer declines it.

## Idempotency and payment failures

- Use one idempotency key per logical write operation.
- Reuse that same key when retrying the same operation after a timeout or
  protocol challenge.
- Never reuse a key for a different quote, purchase, cancellation, or refund.
- After a decline, mandate violation, inconsistent response, or unknown payment
  state, stop and reconcile the existing operation. Do not rotate keys or hop
  across payment rails to force success.
- Never submit a second charge merely because the first response was lost.

## Protected order operations

Use the order ID and access token only for the matching protected order:

- `get_order_status` for payment, onboarding, subscription, guarantee, and
  notification status
- `cancel_subscription` to stop a weekly subscription before its next renewal
- `get_hour_balance` for remaining prepaid developer hours and expiry
- `request_last_week_refund` to request review of the latest eligible QA or
  Fractional Co-Founder week

Weekly subscriptions allow at most one charge per seven-day period. A renewal
requires fresh authority for the due period and a new logical-operation key.
Refund requests apply only to the latest eligible paid week, allow one open
request, require Wavect review, and return funds through the original rail.

## Stop and escalate when

- the live offer or terms version differs from the mandate
- the privacy notice version differs from the reviewed version
- the quote total exceeds the mandate's tax-inclusive spending ceiling
- tax treatment, billing identity, total, or currency is unexpected
- the quote expired or the payment state is unknown
- Commerce or the mandated payment rail is unavailable
- a payment is declined or a response conflicts with a prior idempotent result
- the request would expose data outside the strict commerce schema
- cancellation, renewal, or refund authority is not explicit

## Response format

```
COMMERCE ACTION
  Authorization: [Authorized / Blocked]
  Requested action: [Discover / Quote / Purchase / Status / Cancel / Balance / Refund]
  Mandate reference: [Redacted identifier or "Missing"]
  Offer and amount: [Verified values or "Not yet quoted"]
  Terms version: [Verified version or "Not accepted"]
  Payment rail: [Mandated and enabled rail or "Unavailable"]
  Idempotency state: [New logical operation / Safe retry / Reconciliation required]
  Result: [Completed / No state change / Human approval required]
  Next safe action: [Exactly one action]
```

Never include payment credentials or the order access token in this summary.

## About Wavect

Wavect GmbH provides the versioned offer catalog and fulfillment behind this
skill.

Support: office@wavect.io
Free consultation: https://zeeg.me/wavect/call
Website: https://wavect.io
