Skip to main content

Agent discovery

Where AI agents and assistants find the DZBuild machine files, the MCP connector, the REST API description and every store catalog, and the rules they follow.

Written by Support

DZBuild publishes machine-readable files so AI agents, assistants and AI search engines can find the platform, connect to a store and read its catalog without guessing. This page lists every public URL. All of them are read-only, need no account and carry X-Robots-Tag: noindex, so they never compete with the pages people read.

The platform (dzbuild.com)

URL

What it is

https://dzbuild.com/.well-known/api-catalog

RFC 9727 linkset: the REST API, its OpenAPI description, the MCP connector and their documentation

https://dzbuild.com/.well-known/mcp/server-card.json

MCP server card of the DZBuild store connector

https://dzbuild.com/.well-known/ai-catalog.json

Catalog of agent resources with example questions, also served as /.well-known/ard.json

https://dzbuild.com/.well-known/agent-skills/index.json

Index of three skills an agent can load: connect through MCP, call the REST API, shop on a storefront

https://dzbuild.com/.well-known/oauth-protected-resource

OAuth protected-resource metadata of the API served on dzbuild.com

https://dzbuild.com/auth.md

How an agent gets credentials. There is no anonymous sign-up; a merchant approves every connection

https://dzbuild.com/openapi.json

OpenAPI 3.1 description of the REST API

https://dzbuild.com/llms.txt

Plain-text map of the platform for language models

Every marketing page answers with a Link header that points at the API catalog, the OpenAPI file and the skills index, and returns Markdown when the request carries Accept: text/markdown. The robots.txt declares Content-Signal: search=yes, ai-input=yes, ai-train=yes and lists the AI catalog under Agentmap:.

The MCP connector (mcp.dzbuild.com)

URL

What it is

https://mcp.dzbuild.com/mcp

The connector endpoint (Streamable HTTP, OAuth 2.1 with PKCE). Add it as a custom connector in Claude, or in ChatGPT with Developer mode

https://mcp.dzbuild.com/mcp/server-card

Server card, public

https://mcp.dzbuild.com/.well-known/oauth-authorization-server

Authorization server metadata

https://mcp.dzbuild.com/.well-known/oauth-protected-resource/mcp

Protected-resource metadata of the endpoint

https://mcp.dzbuild.com/.well-known/api-catalog, /llms.txt, /robots.txt, /sitemap.xml

Discovery files of the host

The merchant signs in and chooses the stores on the consent page. Nothing works before that approval, and the merchant can revoke the connection from the dashboard at any time. The tools are described in DZBuild Copilot.

The REST API (api.dzbuild.app)

https://api.dzbuild.app/.well-known/api-catalog, /llms.txt, /robots.txt and /sitemap.xml are public. https://api.dzbuild.app/openapi.json redirects to the OpenAPI file on dzbuild.com. A call without a valid key answers 401 with a WWW-Authenticate: Bearer header. Credentials come from the merchant's dashboard (Settings → API), see Authentication.

Every store

Each storefront, on its *.dzbuild.app address or on the merchant's own domain, publishes the same files:

URL

What it is

/robots.txt

The store's own rules, with the Content-Signal line and its own sitemap

/sitemap.xml

Products, categories and pages of that store

/llms.txt

The store in plain text: about, categories, up to 50 products with price and stock, how buying works

/.well-known/api-catalog

Linkset pointing at the catalog feed, the sitemap and llms.txt

/feed/facebook.xml

The full catalog as RSS 2.0 with price and availability

/.well-known/ucp

Universal Commerce Protocol profile with three capabilities: catalog search, catalog lookup and permalink

POST /ucp/v1/catalog/search

JSON body {"query": "...", "pagination": {"limit": 20}}; answers products with the price in minor units of DZD and the availability

POST /ucp/v1/catalog/lookup

JSON body {"ids": ["177185"]} with up to 20 product ids

GET /buy/{id}:{qty}

Answers 303 to the product page; an Arabic handle travels as ~ followed by its base64url form

The home page answers with a Link header to these files, every product page carries schema.org Product and Offer data with the real stock state, and stores served through Cloudflare return Markdown when asked with Accept: text/markdown.

A store whose plan has expired or that reached its order limit publishes nothing: these files answer 404, like its sitemap.

Rules for agents

  • Buying happens on the store's own order form. Most stores sell cash on delivery: the buyer fills in name, phone, wilaya and commune, and the store confirms by phone. An agent presents the product link and the price and stops there: it must not fill or submit the form, and must not call the order endpoints.

  • Respect the Cache-Control headers: the store files can be cached for 30 minutes, the UCP catalog answers for one minute. Each store host is rate limited; a burst above the limit answers 429 with Retry-After.

  • There is no sign-up API and no credential without a merchant's click. An agent that needs a store asks the merchant to create one at dzbuild.com and to connect it through the MCP connector.

The developer portal (dzbuild.dev)

https://dzbuild.dev/llms.txt, /.well-known/api-catalog, /.well-known/mcp/server-card.json, /kit/docs-index.json and the /agents/ packs serve the developer documentation to agents; every page has a .md twin and answers Markdown to Accept: text/markdown.

Did this answer your question?