A browser and a budget. Not the power to pay.
ProxyCart sends an OpenAI agent with its own cloud browser into three fictional stores. It compares prices, signs in for team pricing and builds the carts, then stops and asks you. The stores refuse payment unless you issued a signed mandate for that exact cart.
You approve every store
The cloud browser asks before it opens each new site, and its network only reaches the three demo stores.
It signs in without seeing the password
The demo account goes straight into the browser form. The model only learns that sign-in happened.
The store enforces your approval
Each payment needs a single-use mandate bound to one store, one cart and one amount. A prompt cannot forge it.
The mission
The same task every time, so runs can be compared. Without team pricing at Harbour, no basket fits the budget.
Watch it shop
Recorded runs replay real sessions with the same agent and stores. A live run lets you allow each store, sign the agent in, trigger a stock-out and approve or decline the purchase yourself.
As it happened
The buyer's decisions and what each store's server saw, in real time.
The cloud browser is starting. The first store visit usually appears within a minute.
The agent's own log
The Agents API publishes the agent's actions and notes when its turn ends, so they arrive together.
Waiting for the agent to finish its turn.
How the guardrail works
OpenAI's guidance is clear: approving a site does not confirm each action, so purchases must be blocked by the resource itself. ProxyCart puts the final check in the store, not in the prompt.
A cloud browser on a short leash
The Agents API runs computer use in an OpenAI-hosted browser. Its network is restricted to the three store hosts, and each new origin needs your approval.
The agent proposes, code checks
The agent calls a request_purchase_approval function with its carts. ProxyCart recomputes every price, stock level, deadline and total from the catalogues before you see it.
You approve one exact plan
Approval issues one HMAC-signed mandate per store. Each code is bound to the run, the store, the cart contents and the total, and expires in 15 minutes.
The store verifies and logs
At checkout the store server re-prices the cart, verifies the signature and marks the mandate as used. A changed cart, another store or a reused code is refused.
What this demo is and isn't
What is real
- OpenAI's Agents API with computer use and gpt-6-luna, browsing in an OpenAI-hosted cloud browser.
- Real approval requests for each site and for sign-in, answered by you or, in recordings, by the person running them.
- Server-side mandate checks in each store, with an independent log of what the stores saw.
What is simulated
- The stores, products, prices and delivery times are fictional. Orders are test orders and no money moves.
- Agents make mistakes. The checks catch arithmetic and catalogue errors; they do not make the agent's choices right.
- This is a pattern for agent-safe checkout, not a payments integration or a compliance claim.
Will agents use your product?
We build AI features and agent-ready flows for startups, with the guardrails in the system rather than in a prompt. Bring your use case and we'll scope a first version together.