Commerce Guide

Agentic Commerce in Production in 2026: OpenAI's Own Launch Checklist, Explained

OpenAI publishes exactly what it tests before a merchant goes live with checkout in ChatGPT. That turns a vague integration into a project with a defined finish line, and it shows which decisions can block launch if you leave them late.

Distk Editorial Oct 2026 12 min read

OpenAI's agentic commerce production guide lists the tests a merchant must complete and document in a sandbox before going live, each shown end to end with request and response logs: creating sessions with and without an address, updating shipping options, creating a delegated payment token with correct signing, completing an order that returns the completed state with HTTP 201, sending signed order_created and order_updated webhooks, handling missing, out_of_stock and payment_declined errors, proving idempotency with a 409 idempotency_conflict, checking Terms and Privacy links, and allowlisting OpenAI's IP ranges. Traffic must use TLS 1.2 or later on port 443. Feed and checkout specs are out of PCI scope, but direct delegated payment integration will likely be in scope, and OpenAI may require an attestation of compliance before production access. The merchant is merchant of record and owns refunds and chargebacks.

What Is OpenAI's Agentic Commerce Production Checklist in 2026?

It is a list of tests OpenAI says you must complete and document in a sandbox before going live with agentic checkout, each demonstrated end to end with request and response logs. It covers session creation, shipping updates, payment tokenisation, order completion, order webhooks, error handling, idempotency, legal links and IP allowlisting. Alongside it sit security and PCI requirements and a short set of FAQs that settle who owns refunds and chargebacks.

A vendor-published launch checklist is unusually useful, because it tells you exactly what certification will look at. It also makes clear that checkout is an engineering project with a defined finish line rather than a plugin. This guide is the production spoke in our guide to the Agentic Commerce Protocol product feed, and it assumes you have already been accepted as an approved partner via chatgpt.com/merchants, which OpenAI states is currently required for feed onboarding.

What Tests Must Be Demonstrated Before Launch in 2026?

Nine groups of tests, each with specific pass conditions. The table restates them as OpenAI lists them, with the evidence you should keep. Every item should be demonstrated end to end with logs, so plan to capture request and response pairs from the start rather than reconstructing them later.

Test groupWhat OpenAI asks you to demonstrate in 2026Evidence to keep
Session creation and address handlingCreate a checkout session with and without a shipping address; shipping options and tax totals returned once a valid address is provided; API-Version header present and supported.Both request and response pairs, showing totals appearing after the address.
Shipping option updatesUpdate the selected shipping option and recompute order totals correctly.Before and after totals.
Payment tokenisationCreate a delegated payment token via POST /agentic_commerce/delegate_payment with a valid payment_method, allowance, billing_address, risk_signals and metadata; all required headers; canonical JSON serialisation and correct detached signature.Signed request, token response.
Order completionComplete the order with a tokenised payment; final order object in the completed state; HTTP 201 Created.Completion response with order object.
Order updatesorder_created and subsequent order_updated webhooks sent with a valid HMAC signature.Webhook payloads and signature verification.
Error scenariosTrigger and log missing (for example invalid_request / 400), out_of_stock and payment_declined.One logged example of each.
IdempotencyRepeat create and complete calls with the same Idempotency-Key: duplicates return the same result, mismatched parameters return idempotency_conflict with HTTP 409.Paired duplicate calls and the 409.
Documentation and linksTerms of Service and Privacy Policy links present and functional.Working URLs.
IP egress rangesAllowlist OpenAI's published IP ranges, since OpenAI will call your action from them.Firewall configuration.

Why Do Idempotency and Error Handling Get Their Own Tests in 2026?

Because an agent retries. A conversational checkout has more places for a request to be repeated than a web checkout does, and the cost of a non-idempotent complete call is a double charge on a real customer. OpenAI's checklist tests both halves: identical duplicates must return the same result, and a reused key with different parameters must fail with idempotency_conflict and HTTP 409 rather than silently doing something new.

Error handling is tested for a related reason. In the checkout spec, errors such as out_of_stock and payment_declined are not only HTTP failures; they are messages surfaced to the shopper with a path to the part of the cart they concern. A store that returns a generic 500 when stock runs out gives ChatGPT nothing to tell the customer, and the session simply fails. The three named scenarios in the checklist are the three a real launch will hit in its first week.

What Are the Security Requirements in 2026?

Two are stated precisely. All traffic to you must use TLS 1.2 or later on port 443 with a valid public certificate. And OpenAI will call you from its published IP ranges, which you are expected to allowlist. The checkout specification adds the per-request discipline: authenticate every request, verify signatures, enforce idempotency, validate inputs and support safe retries.

PCI scope is where planning most often goes wrong, so OpenAI's wording is worth keeping close. The product feed and checkout specs are deliberately kept out of PCI scope and do not transmit cardholder data. Using your PSP's implementation of the Delegated Payment Spec may avoid any change in your PCI scope. Using your PSP's forwarding APIs, or integrating directly with OpenAI's delegated payment endpoints, involves handling cardholder data and will likely be in scope. OpenAI says it intends to migrate entirely to network tokens as they become supported, and that it may require your attestation of compliance before enabling production access.

Before you book a launch date in 2026

OpenAI's guidance is to check with your PSP and consult your Qualified Security Assessor or other PCI compliance advisor about the impact on your specific obligations. If production access can depend on an attestation of compliance, that conversation belongs at the start of the project, not the week before launch.

Who Owns Refunds, Chargebacks and Shipping Questions in 2026?

You do. OpenAI's production FAQs are direct: the merchant actually selling the goods and taking payment is the merchant of record, not OpenAI or the payment provider, and customers see the merchant's name on their card statement as if they bought on the merchant's website. Because you accepted the payment, refunds and chargebacks are yours to handle.

What Feed Quality Work Should Happen Before Launch in 2026?

Checkout only works on products ChatGPT already understands, so OpenAI's feed best practices belong in the same launch plan. They are short and practical, and each one prevents a specific class of bad listing.

Best practiceWhat OpenAI recommends in 2026
DescriptionsConcise, factual copy; plain text and bullet-style text are both acceptable.
Optional fieldsFields such as description.html, description.markdown, categories.taxonomy and seller.links can improve answer quality but are not required. If a field needs brittle transforms, omit it until data quality is stable.
URLsKeep url, media.url and seller link URLs valid and encoded, for example %20 for spaces.
Seller attributionSet seller.name to the seller users should see, use durable public URLs in seller.links, and reuse supported link types consistently.
VariantsStable parent product id, unique variant id per purchasable option, variant-specific title, URL, media, availability and price where they differ.
AttributionAdd feed attribution parameters to url, such as utm_medium=feed, and keep tracking parameters consistent across snapshots.

The attribution point is the one marketing teams should own. Without a consistent feed parameter, sales that start in ChatGPT and finish on your site look like direct or organic traffic, and you cannot tell whether the channel is working. Field-level detail is in our ChatGPT product feed requirements guide.

What Does a Realistic Launch Sequence Look Like in 2026?

One that front-loads the decisions that can block launch and back-loads the ones that only need time. The sequence below is our ordering of OpenAI's published requirements, not a timeline OpenAI publishes.

  1. Confirm eligibility. Approved-partner access, a supported payment provider, and the markets OpenAI has confirmed for your integration.
  2. Settle PCI scope with your PSP and QSA, and decide on your PSP's delegated payment implementation versus direct integration.
  3. Ship a clean product feed with stable IDs, valid availability, and feed attribution parameters.
  4. Build the five checkout endpoints with signature verification, idempotency and full cart state.
  5. Build signed order webhooks, including refund and chargeback updates.
  6. Run every checklist test in the sandbox and keep the logs.
  7. Allowlist OpenAI's IP ranges and confirm TLS on port 443.
  8. Check legal links and request production access.

For the endpoint-level specification behind steps four and five, see our agentic checkout merchant guide.

What Are the Common Production Mistakes in 2026?

Key Takeaways for 2026

Distk helps D2C and e-commerce teams in India and internationally plan agentic commerce launches against the published requirements, sequence the work so PCI and eligibility questions are answered first, and set up the attribution that proves whether the channel pays. If you are planning a ChatGPT checkout launch in 2026, that plan is where we start.

Sources

Agentic Commerce in Production: FAQs

What does OpenAI test before an agentic checkout goes live?

Session creation with and without an address, shipping option updates, delegated payment token creation, order completion with HTTP 201, signed order webhooks, the missing, out_of_stock and payment_declined error scenarios, idempotency with a 409 on conflicts, legal links, and IP allowlisting, each shown end to end with logs.

What security is required for ChatGPT agentic checkout?

All traffic must use TLS 1.2 or later on port 443 with a valid public certificate, and you should allowlist OpenAI's published IP ranges. The checkout spec also requires authenticating every request, verifying signatures, enforcing idempotency and validating inputs.

Will agentic checkout bring my business into PCI scope?

The feed and checkout specs are kept out of PCI scope. Your PSP's delegated payment implementation may avoid a scope change, while forwarding APIs or direct integration involve cardholder data and will likely be in scope. OpenAI may require an attestation of compliance before production access.

Who handles refunds and chargebacks?

The merchant, as merchant of record. OpenAI advises using the order update webhook to tell ChatGPT when a refund or chargeback status changes so order state stays in sync.

Can one checkout ship to multiple addresses?

Not today. The protocol models a single shipping address and one selected shipping option per checkout session, and OpenAI advises consolidating split shipments into one buyer-visible selection with aggregate totals.

How do I track sales that come from ChatGPT?

OpenAI's best practices recommend adding feed attribution parameters to product URLs, for example utm_medium=feed, and keeping tracking parameters consistent across feed snapshots.

Sequence the launch so nothing blocks you late

Distk plans agentic commerce launches against OpenAI's published requirements, settles eligibility and PCI questions first, and sets up the feed attribution that shows whether the channel actually pays.

Start the conversation →