Understanding "On-Behalf-Of" for Delegated Agentic Commerce Using ACP & UCP
There's no shopping cart in this story, and no "Buy Now" button — because there never was one. Commerce here is a status code and a document: 402 when you haven't paid, 200 when you have. This ~5:19 field test asks what happens when an AI agent tries to read on a human principal's behalf, across both the ACP and UCP protocols — and shows, live, exactly where that works and where it rightly doesn't.
Updated 2026-09-24
— ACP/UCP clients now reorient after an initial 401 with an unauthenticated OPTIONS discovery probe
(offer + seller from Link rel="https://schema.org/offers").
The embedded video below predates this discovery step.
Participants — verified identities
Principal ("You")
Kingsley Uyi Idehen WebID · cert modulus & SAN verified
Agent ("Your AI Agent")
Claude Sonnet 5, delegate identity WebID · cert modulus & SAN verified
Delegation
Corroborated both sides: principal's hasIdentityDelegate + agent's onBehalfOf, consistent across Turtle/JSON-LD/RDFa
Chapters
0:00The Proposition — buying is just reading, once you're allowed to
—New (2026-09-24, not in video): after first 401, unauthenticated OPTIONS discovers offer + seller before auth choice
0:33UCP and ACP Meet at the Resource — different checkouts, same 402 boundary
1:05Establish the Baseline — 402, pay, retry, 200 on the Food Bookmark Collection file
1:36Verify the Entitlement — the server now recognizes a persistent relationship
2:02Agent Identity Alone Is Insufficient — authentication isn't authorization
2:36Add Explicit Delegation — On-Behalf-Of: direct 200, 11/11, verified three ways
3:20Now Test the Boundary — delegation extends a right, it doesn't create one
3:48Try to Break It — wrong identity, empty header, wrong header name all fail
4:27Why This Matters — identity distinct, delegation explicit, authorization stays with the resource
Enhanced discoverability — OPTIONS after 401 Updated 2026-09-24
After an initial 401, the ACP/UCP client now immediately sends an
unauthenticatedOPTIONS to the same resource URL before choosing Digest, WebID-TLS, or OAuth.
The probe is discovery only: no credentials, no authorized retry. Live evidence from Kingsley’s Mac,
2026-09-24 2:21–2:22 PM ET:
Food Bookmark Collection HTML —
anonymous GET → 401 (Digest challenge only; nonce/opaque redacted);
anonymous OPTIONS → 204 with Allow, DAV, rel=meta, rel=acl, and
Link: <http://data.openlinksw.com/oplweb/offer/FoodBookmarkCollectionHtmlFileAccessOneTimeOfferURIBurner#this>;
rel="https://schema.org/offers"; seller="https://ods-qa.openlinksw.com/shop#this".
Trackloaded Premium Knowledge Inventory TTL (the never-purchased control on this page) —
same pattern: GET 401, OPTIONS 204 with offer
TrackloadedPremiumInventoryFileAccessOneTimeOfferURIBurner#this and the same seller.
Tie-in: agent WebID-TLS alone on :5443 for the Food Bookmark HTML → 302 then 402.
Decoded Payment request (Payment id and raw base64 withheld):
amount: 299, currency: "usd",
externalId = the same Food Bookmark offer IRI from OPTIONS,
recipient: "https://ods-qa.openlinksw.com/shop/".
Honest gap: offer IRIs did not dereference to Turtle on 2026-09-24 (describe 406 / empty DESCRIBE);
the ,meta link required authentication (401). Offer identity and price come from the OPTIONS
Link and the decoded 402 request only.
If OPTIONS itself returns 401, keep only exposed metadata and continue
normal auth selection (per ACP/UCP client skill). The narrated MP4 embedded above predates this discovery step.
What was actually tested
An agent presenting its own WebID-TLS certificate plus an On-Behalf-Of header naming the principal retrieves the Food Bookmark Collection file — a resource the principal has already purchased — direct 200 OK, no payment challenge — confirmed via raw curl, the ucp-client skill, and the acp-client skill.
The same header on the Trackloaded Premium Knowledge Inventory file, which the principal has never purchased, is challenged identically to a first-time visitor — delegation inherits existing entitlements, it does not grant new spending authority.
A control battery (agent's own WebID, an unrelated WebID, an empty value, a different header name entirely) on the Food Bookmark Collection file confirmed the check is genuinely value-specific, not a blanket bypass.