What Is OpenAI's Agentic Commerce Production Checklist in 2026?
It is a list of tests OpenAI says you must complete and document in a sandbox before going live with agentic checkout, each demonstrated end to end with request and response logs. It covers session creation, shipping updates, payment tokenisation, order completion, order webhooks, error handling, idempotency, legal links and IP allowlisting. Alongside it sit security and PCI requirements and a short set of FAQs that settle who owns refunds and chargebacks.
A vendor-published launch checklist is unusually useful, because it tells you exactly what certification will look at. It also makes clear that checkout is an engineering project with a defined finish line rather than a plugin. This guide is the production spoke in our guide to the Agentic Commerce Protocol product feed, and it assumes you have already been accepted as an approved partner via chatgpt.com/merchants, which OpenAI states is currently required for feed onboarding.
What Tests Must Be Demonstrated Before Launch in 2026?
Nine groups of tests, each with specific pass conditions. The table restates them as OpenAI lists them, with the evidence you should keep. Every item should be demonstrated end to end with logs, so plan to capture request and response pairs from the start rather than reconstructing them later.
| Test group | What OpenAI asks you to demonstrate in 2026 | Evidence to keep |
|---|---|---|
| Session creation and address handling | Create a checkout session with and without a shipping address; shipping options and tax totals returned once a valid address is provided; API-Version header present and supported. | Both request and response pairs, showing totals appearing after the address. |
| Shipping option updates | Update the selected shipping option and recompute order totals correctly. | Before and after totals. |
| Payment tokenisation | Create a delegated payment token via POST /agentic_commerce/delegate_payment with a valid payment_method, allowance, billing_address, risk_signals and metadata; all required headers; canonical JSON serialisation and correct detached signature. | Signed request, token response. |
| Order completion | Complete the order with a tokenised payment; final order object in the completed state; HTTP 201 Created. | Completion response with order object. |
| Order updates | order_created and subsequent order_updated webhooks sent with a valid HMAC signature. | Webhook payloads and signature verification. |
| Error scenarios | Trigger and log missing (for example invalid_request / 400), out_of_stock and payment_declined. | One logged example of each. |
| Idempotency | Repeat create and complete calls with the same Idempotency-Key: duplicates return the same result, mismatched parameters return idempotency_conflict with HTTP 409. | Paired duplicate calls and the 409. |
| Documentation and links | Terms of Service and Privacy Policy links present and functional. | Working URLs. |
| IP egress ranges | Allowlist OpenAI's published IP ranges, since OpenAI will call your action from them. | Firewall configuration. |
Why Do Idempotency and Error Handling Get Their Own Tests in 2026?
Because an agent retries. A conversational checkout has more places for a request to be repeated than a web checkout does, and the cost of a non-idempotent complete call is a double charge on a real customer. OpenAI's checklist tests both halves: identical duplicates must return the same result, and a reused key with different parameters must fail with idempotency_conflict and HTTP 409 rather than silently doing something new.
Error handling is tested for a related reason. In the checkout spec, errors such as out_of_stock and payment_declined are not only HTTP failures; they are messages surfaced to the shopper with a path to the part of the cart they concern. A store that returns a generic 500 when stock runs out gives ChatGPT nothing to tell the customer, and the session simply fails. The three named scenarios in the checklist are the three a real launch will hit in its first week.
What Are the Security Requirements in 2026?
Two are stated precisely. All traffic to you must use TLS 1.2 or later on port 443 with a valid public certificate. And OpenAI will call you from its published IP ranges, which you are expected to allowlist. The checkout specification adds the per-request discipline: authenticate every request, verify signatures, enforce idempotency, validate inputs and support safe retries.
PCI scope is where planning most often goes wrong, so OpenAI's wording is worth keeping close. The product feed and checkout specs are deliberately kept out of PCI scope and do not transmit cardholder data. Using your PSP's implementation of the Delegated Payment Spec may avoid any change in your PCI scope. Using your PSP's forwarding APIs, or integrating directly with OpenAI's delegated payment endpoints, involves handling cardholder data and will likely be in scope. OpenAI says it intends to migrate entirely to network tokens as they become supported, and that it may require your attestation of compliance before enabling production access.
OpenAI's guidance is to check with your PSP and consult your Qualified Security Assessor or other PCI compliance advisor about the impact on your specific obligations. If production access can depend on an attestation of compliance, that conversation belongs at the start of the project, not the week before launch.
Who Owns Refunds, Chargebacks and Shipping Questions in 2026?
You do. OpenAI's production FAQs are direct: the merchant actually selling the goods and taking payment is the merchant of record, not OpenAI or the payment provider, and customers see the merchant's name on their card statement as if they bought on the merchant's website. Because you accepted the payment, refunds and chargebacks are yours to handle.
- Sync state back. Use the order update webhook to notify ChatGPT when a refund or chargeback status changes, so order state stays synchronised.
- One shipment per session. The protocol currently models a single shipping address and one selected shipping option per checkout session.
- Consolidate split shipments. If your system splits orders across warehouses, present a single buyer-visible selection and return aggregate shipping and tax totals.
What Feed Quality Work Should Happen Before Launch in 2026?
Checkout only works on products ChatGPT already understands, so OpenAI's feed best practices belong in the same launch plan. They are short and practical, and each one prevents a specific class of bad listing.
| Best practice | What OpenAI recommends in 2026 |
|---|---|
| Descriptions | Concise, factual copy; plain text and bullet-style text are both acceptable. |
| Optional fields | Fields such as description.html, description.markdown, categories.taxonomy and seller.links can improve answer quality but are not required. If a field needs brittle transforms, omit it until data quality is stable. |
| URLs | Keep url, media.url and seller link URLs valid and encoded, for example %20 for spaces. |
| Seller attribution | Set seller.name to the seller users should see, use durable public URLs in seller.links, and reuse supported link types consistently. |
| Variants | Stable parent product id, unique variant id per purchasable option, variant-specific title, URL, media, availability and price where they differ. |
| Attribution | Add feed attribution parameters to url, such as utm_medium=feed, and keep tracking parameters consistent across snapshots. |
The attribution point is the one marketing teams should own. Without a consistent feed parameter, sales that start in ChatGPT and finish on your site look like direct or organic traffic, and you cannot tell whether the channel is working. Field-level detail is in our ChatGPT product feed requirements guide.
What Does a Realistic Launch Sequence Look Like in 2026?
One that front-loads the decisions that can block launch and back-loads the ones that only need time. The sequence below is our ordering of OpenAI's published requirements, not a timeline OpenAI publishes.
- Confirm eligibility. Approved-partner access, a supported payment provider, and the markets OpenAI has confirmed for your integration.
- Settle PCI scope with your PSP and QSA, and decide on your PSP's delegated payment implementation versus direct integration.
- Ship a clean product feed with stable IDs, valid availability, and feed attribution parameters.
- Build the five checkout endpoints with signature verification, idempotency and full cart state.
- Build signed order webhooks, including refund and chargeback updates.
- Run every checklist test in the sandbox and keep the logs.
- Allowlist OpenAI's IP ranges and confirm TLS on port 443.
- Check legal links and request production access.
For the endpoint-level specification behind steps four and five, see our agentic checkout merchant guide.
What Are the Common Production Mistakes in 2026?
- Not keeping logs from the start. Every test must be demonstrated end to end with request and response logs.
- Leaving PCI scope until the end. OpenAI may require an attestation of compliance before production access.
- Returning generic errors. Out of stock and payment declined must be handled as recoverable, logged scenarios.
- Assuming retries are rare. Idempotency conflicts must return 409, not a second order.
- Forgetting the IP allowlist. OpenAI calls you from published ranges.
- Skipping feed attribution. Without it, ChatGPT-sourced sales disappear into direct traffic.
- Assuming OpenAI handles refunds. As merchant of record, you do.
Key Takeaways for 2026
- OpenAI requires sandbox tests for sessions, shipping updates, tokenisation, completion, webhooks, errors, idempotency, legal links and IP allowlisting, all logged end to end.
- Completion must return the order in the
completedstate with HTTP 201, and idempotency conflicts must return HTTP 409. - TLS 1.2 or later on port 443 with a valid public certificate is mandatory.
- Feed and checkout specs are out of PCI scope; direct delegated payment integration likely is not, and an attestation may be required.
- You are merchant of record, own refunds and chargebacks, and sync them by webhook.
- Feed attribution parameters such as
utm_medium=feedare how you will measure the channel at all.
Distk helps D2C and e-commerce teams in India and internationally plan agentic commerce launches against the published requirements, sequence the work so PCI and eligibility questions are answered first, and set up the attribution that proves whether the channel pays. If you are planning a ChatGPT checkout launch in 2026, that plan is where we start.