# Brand Design CLI and experimental WebMCP

Version: 1.0.1. Public reads only. Uses the existing canonical resources and commerce API, alongside the existing MCP at https://branddesign.ltd/mcp. No separate order engine.

## CLI: two plain files, no package installation

Requirements: Node.js 22 or newer, permitted shell access and HTTPS network access. Download both files into the same directory:

- https://branddesign.ltd/agent/branddesign-agent.mjs
- https://branddesign.ltd/agent/agent-core.mjs

Review the files and compare their SHA-256 values with the CLI artifact list in https://branddesign.ltd/.well-known/agent-bootstrap.json. No npm package or npx installation is required or claimed.

```sh
node branddesign-agent.mjs discover
node branddesign-agent.mjs services
node branddesign-agent.mjs service b2a-brand
node branddesign-agent.mjs pricing
node branddesign-agent.mjs catalog
node branddesign-agent.mjs evidence
node branddesign-agent.mjs capabilities
node branddesign-agent.mjs doctor
```

Results are JSON with source and retrieval date. Exit 0 means success; 1 means retrieval or integrity failure; 2 means invalid invocation. doctor checks bootstrap, four context file digests and public catalog/manifest availability. It does not test MCP authentication, buyer authority, WebMCP support or payment settlement. Requests have a 15-second timeout and an 8 MiB response limit. Unknown commands and resource URLs are rejected. No credentials are sent.

## WebMCP: supported browsers only

The English and Bulgarian Agentic Commerce pages load https://branddesign.ltd/agent/webmcp.mjs. It registers branddesign_discover, branddesign_services, branddesign_service, branddesign_pricing, branddesign_catalog, branddesign_evidence and branddesign_capabilities when the browser provides the WebMCP registration API. Unsupported browsers retain the ordinary pages and HTTPS resources. No polyfill is installed and no browser flags or security settings are changed.

WebMCP is experimental. Target draft: https://webmachinelearning.github.io/webmcp/ (30 September 2026). Feature detection supports Document.modelContext and the earlier Navigator.modelContext implementation. The draft is not a W3C Standard. Browser/API availability, permissions and cross-origin access may limit individual calls; errors are reported rather than replaced with guessed data.

## Scope and rights

Every exposed command/tool makes public GET requests only. There are no registration, quote creation, order creation, private order-status, invoice, payment or memory-write commands in this version. Current indicative prices are not accepted payable quotes. The existing authenticated MCP/API remains the separate path for buyer-authorised actions under https://branddesign.ltd/AGENTS.md.

Browser catalog and manifest reads use the same-origin https://branddesign.ltd/agent-commerce-read.php public GET bridge with only the fixed catalog/capabilities resources. It forwards no credentials and does not modify the merchant API. CLI reads the merchant directly.
