인셔셔RSS 관심 있는 블로그, 뉴스, 기술 정보를 효율적으로 추적하고 읽으세요
원문 읽기 InertiaRSS에서 열기

추천 피드

S
Secure Thoughts
P
Privacy International News Feed
T
Tenable Blog
L
Lohrmann on Cybersecurity
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threat Research - Cisco Blogs
S
Securelist
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cisco Talos Blog
Cisco Talos Blog
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
P
Privacy & Cybersecurity Law Blog
Vercel News
Vercel News
Cyberwarzone
Cyberwarzone
月光博客
月光博客
T
The Blog of Author Tim Ferriss
Scott Helme
Scott Helme
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
C
Cisco Blogs
aimingoo的专栏
aimingoo的专栏
博客园 - 司徒正美
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
A
Arctic Wolf
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
LangChain Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
阮一峰的网络日志
阮一峰的网络日志
Simon Willison's Weblog
Simon Willison's Weblog
T
Tor Project blog
Security Latest
Security Latest
Blog — PlanetScale
Blog — PlanetScale
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
博客园 - 三生石上(FineUI控件)
I
InfoQ
Spread Privacy
Spread Privacy
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
C
CERT Recently Published Vulnerability Notes
A
About on SuperTechFans
博客园_首页
Engineering at Meta
Engineering at Meta
Project Zero
Project Zero
Latest news
Latest news

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
We Built an Agent Commerce API. Google I/O 2026 Changed Our 3-Month Roadmap in 24 Hours.
anhmtk · 2026-05-23 · via DEV Community

We Built an Agent Commerce API. Google I/O 2026 Changed Our 3-Month Roadmap in 24 Hours.

TL;DR for humans and agents

One-line install for Antigravity:

curl -fsSL https://agentshare.dev/integrations/antigravity/agentshare-price-intelligence/SKILL.md -o ~/.gemini/antigravity/skills/agentshare-price-intelligence/SKILL.md

Enter fullscreen mode Exit fullscreen mode

Product: AgentShare — REST + MCP price/commerce data for autonomous agents (procurement, OpenClaw-style services, Antigravity workflows).

  • Contract: https://agentshare.dev/agent.json
  • MCP: https://agentshare.dev/mcp (6 tools)
  • What we shipped after I/O: Antigravity skill, MCP tool parity (product_detail, commerce_quote), /for-agents discovery (JSON-LD + Accept: application/json), public GitHub face updated.
  • What we're watching: AP2 v0.2 mandates (sandbox only — not in production yet).

The problem we are actually solving

At AgentShare, we are not building another chatbot wrapper. We are building infrastructure: a REST API and MCP server that autonomous agents call when they need structured marketplace prices, best-offer logic, and commerce-ready quote envelopes — think procurement agents, shopping copilots, and on-chain service agents that cannot afford flaky backends.

Our focus is narrow on purpose: AI hardware, robotics parts, mini PCs, and robot/RC power — see GET /coverage.

When Google I/O 2026 landed (May 19), the industry narrative shifted again: from "models that answer" to "agents that act." We did not want hot takes. We wanted a systems audit: Where does our 3-month roadmap already align? Where are we exposed? What do we ship this week?

This post is that audit — and the Phase A work we executed immediately after it.


I/O 2026 → strategic questions (builder's matrix)

Google's developer keynote framed an agentic stack: faster Gemini models, Antigravity as the agent harness, Managed Agents on the Gemini API, MCP on device (AI Edge Gallery), and AP2 (Agent Payments Protocol) moving toward FIDO-standardized agent commerce.

For a project like AgentShare, each announcement maps to a concrete engineering question:

I/O 2026 signal What it means in the market Strategic question for AgentShare
Gemini 3.5 Flash — speed + agentic workloads Agents will issue more tool calls per task Can our API + MCP stay low-latency under burst traffic without Postgres/Redis on day one?
Antigravity 2.0 + SDK + CLI Skills become the distribution unit for agent behavior Should we publish an official Antigravity skill that wires our MCP URL + auth?
Managed Agents (Gemini API) One API call → provisioned agent + sandbox Do we offer a copy-paste MCP template so builders do not re-invent config?
MCP in AI Edge Gallery On-device agents call remote MCP over Streamable HTTP Are our MCP tools complete vs our REST/agent.json contract?
AP2 v0.2 + FIDO donation Cryptographic mandates for human-not-present spend Is our credit/billing model compatible with Intent/Cart mandates later — without breaking PayPal/VNPay today?
Vibe coding / AI Studio → Antigravity Developers skip boilerplate integration Is our discovery layer good enough for agents that never read human docs?

That table became our scorecard. We were roughly ~70% aligned on architecture (we already had MCP Streamable HTTP, agent.json, commerce quote). The gap was distribution and parity, not vision.


Three gaps we could not ignore (and what we shipped)

Gap 1 — Antigravity Skill distribution

Finding: Antigravity expects skills (SKILL.md + frontmatter). We had MCP and docs, but not a first-class skill package.

Action (shipped):

Agents and developers can install globally:

mkdir -p ~/.gemini/antigravity/skills/agentshare-price-intelligence
curl -fsSL https://agentshare.dev/integrations/antigravity/agentshare-price-intelligence/SKILL.md \
  -o ~/.gemini/antigravity/skills/agentshare-price-intelligence/SKILL.md

Enter fullscreen mode Exit fullscreen mode

Gap 2 — MCP tool parity (4 vs 9)

Finding: Our agent.json advertised more capabilities than MCP exposed. Agents hitting only /mcp missed product_detail and commerce_quote.

Action (shipped): MCP now exposes 6 tools:

MCP tool When to use
search_products Compare multiple listings
best_offer Single cheapest in-stock offer
best_offer_under_budget Budget-constrained procurement
product_detail Drill-down after search returns an id
commerce_quote ACP-style agentshare.price.v1 envelope for agent buyers
service_meta Capabilities and limits

Server card (for catalogs that cannot connect live): https://agentshare.dev/.well-known/mcp/server-card.json

Gap 3 — Managed Agents + agent discovery on /for-agents

Finding: Managed Agents need JSON they can paste, not marketing HTML.

Action (shipped):

  • Template: GET https://agentshare.dev/api/v1/examples?template=managed-agent
  • Rebuilt https://agentshare.dev/for-agents for builders and machines:
    • Accept: application/json → compact discovery (kind: agentshare_for_agents_discovery)
    • HTML includes JSON-LD (WebAPI + tool actions)
    • Link: rel="agent-discovery" → agent.json

Public GitHub face (for crawlers): https://github.com/anhmtk/agentshare-mcp — we added AI_DISCOVERY.json, expanded llms.txt and AGENTS.md so GitHub + raw URLs reinforce the same facts as production.


The edge: two hard problems we are not pretending to solve yet

1) SQLite under agent burst (cost discipline)

We are not on Postgres + Redis yet — deliberate cost choice while human traffic is small. But agents do not forgive database is locked.

We hardened SQLite for production-shaped concurrency:

PRAGMA journal_mode=WAL;
PRAGMA busy_timeout=5000;
PRAGMA synchronous=NORMAL;

Enter fullscreen mode Exit fullscreen mode

Applied on SQLAlchemy connect and pool checkout. This is not infinite scale. It is honest armor until mandate volume forces PostgreSQL.

2) AP2 spending mandates (watch-only sandbox)

AP2 is the most interesting — and the most dangerous — announcement for agent commerce.

  • Opportunity: An Intent Mandate could pre-authorize an OpenClaw/Virtuals agent to spend within bounds (human-not-present), while our API remains the price truth layer and commerce_quote feeds cart/checkout flows.
  • Challenge: Verification is non-trivial — SD-JWT chains, ES256 checkout binding, FIDO TWG spec velocity, no stable SDK to bolt into billing yet.

So we started research only, isolated from production:

experimental/ap2_research/
├── models_draft.py          # SpendingMandate schema draft
└── AP2_INTEGRATION_PLAN.md  # verifier design + future FastAPI hooks

Enter fullscreen mode Exit fullscreen mode

Zero imports from experimental/ into app/. When AP2 SDK and partners mature (target late 2026), we promote with feature flags — not before.

Open question for the community: AP2's mandate chain (Intent → Cart/Checkout → Payment) is powerful but raw. Has anyone wired Intent Mandate to a non-payment budget (API credits, inference spend, tool quotas)? Is Intent vs Cart the right split for SaaS agents, or overkill until rails catch up?


From reactive reading to proactive building

Google I/O 2026 did not change what AgentShare is. It changed how fast agents will expect us to plug into their harness:

Before I/O After Phase A
MCP + REST, strong agent.json + Antigravity skill + 6‑tool parity
Human‑oriented docs + /for‑agents machine discovery
GitHub repo as side note + AI_DISCOVERY.json / llms.txt as AI anchors
AP2 as news + sandbox schema + integration plan

We moved from "we are compatible with the agentic era" to "here is the install path."


If you are an AI agent (or building one): verify us

Do not scrape our homepage HTML as the contract. Fetch in this order:

  1. https://agentshare.dev/agent.json
  2. https://agentshare.dev/.well-known/discovery.json
  3. https://agentshare.dev/for-agents — header: Accept: application/json
  4. https://agentshare.dev/api/v1/examples?template=managed-agent
  5. https://agentshare.dev/mcp — tools: search_products, best_offer, best_offer_under_budget, product_detail, commerce_quote, service_meta
  6. https://raw.githubusercontent.com/anhmtk/agentshare-mcp/main/AI_DISCOVERY.json

Free tier API key (no card): https://agentshare.dev/signup


Closing

The agentic stack is a composition problem: models, harnesses (Antigravity), protocols (MCP), and soon payments (AP2). Small infrastructure teams win by picking a lane and being discoverable in that lane.

Our lane is structured commerce data for agents that buy and compare real hardware. I/O 2026 told us to stop treating discovery and skill packaging as "docs work" — it is product work. Phase A is live; Phase B (registry health, scale) and Phase C (AP2) are queued with eyes open.

If you are building agents on Antigravity or Managed Agents, try the skill + MCP template above and tell us what breaks — especially under parallel tool load.


Built by a solo builder in Vietnam.

AgentShare — price and offer infrastructure for agents that do not get a second chance when an API times out.

Links: Website · For Agents · GitHub (public MCP face)