The agent integrates
without a sales conversation.

An agent gets the same door as a person — capture, query, get_event, trace_epc and translate as typed MCP tools, JSON-RPC over POST /mcp, re-dispatched through the same worker fetch with the same key. A door, not a second path. You do not persuade an agent; it arrives pre-mandated, it matches, it does not want — so this page is spec, not story.

Proof, not adjectives. The gateway's conformance tests pass against GS1's normative artefacts — verified by this build: 698/698 tests green, 2026-07-31. The machine face below is live on this origin, and npx epcis.dev mcp runs the same server on your bench. The write tools open with a capture key; the ledger is at What ships today.

The tools, and the two that refuse.

toolwhat it doesreadOnlyHintstate
capturePOST an EPCIS document through the gateway laws: strip → validate → project-check → stamp → appendnoshipped
querySimpleEventQuery over whatever was capturedyesshipped
get_eventone event, by its CBV §8.9 hash identityyesshipped
trace_epcthe full event chain for one EPCyesshipped
translateEPCIS 1.1 / 1.2 / 2.0 XML → 2.0 JSON-LD, with a per-job fidelity reportyesshipped
resolverefuses honestly: identity resolution lives at id.org.ai — Agent. Human. Thing. — and is deferred. Returns a tool error, never a fabricated resolutionhonest refusal
subscriberefuses honestly: a typed tool error, never a silent downgrade to a one-shot pullhonest refusal

readOnlyHint: true is set exactly where it is true, with complete descriptions — which is what lets a deputized agent clear auto-approval inside already-granted scope without a mid-task human. The two refusing tools are the honesty law in tool form: an agent that calls resolve or subscribe gets a tool error that says why, never a fabricated answer.

Paste-ready, honestly labelled.

One block, pasted into your client's configuration, and the door is in the toolchain:

{
  "mcpServers": {
    "epcis": {
      "command": "npx",
      "args": ["epcis.dev", "mcp"]
    }
  }
}

Every tool call dispatches through the same capture pipeline as the REST interface, so validation, refusals and envelope stamping are byte-identical — strip, validate, stamp, append, on your own bench.

The machine face is a contract, not a brochure.

An arriving agent reads three documents on this origin: /llms.txt (the ledger and summariser rules),/agent-classes.json (the single enumeration of agent classes), and /icp.json (this property's derivation contract: which classes arrive here, the hint → face → fallback classification ladder, the free zone, and where the gates land). Both JSON faces are built from one frozen enumeration — the same module a runtime selector must read — so the published contract and the runtime selection cannot drift.

The gate law an agent can rely on: the free zone is compute — translate, validate, hash, capture at $0/event (intent, until published terms bind it). Gates land on durable statefulness, authority and licensed data, never on compute. And where a scope needs a human: Absent a pre-registered notification channel, every human-gated scope fail-closes (never a silent grant).

Who an observer is resolves via id.org.ai — Agent. Human. Thing. The mechanics are deferred, and no surface here describes them.

For the human provisioning an agent seat: the deputization ceremony — a mandate with a named scope and a named ceiling — is a ceremony for a person, not a route for an agent.

We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.