Stall library · Buy

The store refused the AI agent’s add to cart

This stall is an add to cart that reached the store and was refused. The AI agent pressed the button, the page sent the cart request, and the store answered it with an error or a bot challenge instead of adding the product. Nothing is wrong with the button: the request went, and something between the agent and the cart said no.

Why the agent stops

Bot protection often treats the cart request differently from the product page. A page view is let through, while a request that changes state, such as adding to a cart, is scored more strictly and answered with a challenge. A shopper in a browser solves it without noticing; an AI agent cannot solve a challenge at all.

Firewall and rate limit rules do the same thing from a different direction: a rule written to stop cart abuse refuses the request from an automated browser, and the page shows nothing, so the agent is left with a product it chose and no cart to put it in.

How often we see this

Not stated here. A frequency means nothing without the cohort it was counted over, and this page is about one stall rather than one category. Where a category has enough stores measured at every stage, the share of them showing this stall is published on its benchmark page, with the methodology beside it.

See it for yourself

  1. Open a product page, open the browser developer tools on the Network tab, and press add to cart.
  2. Find the cart request (for Shopify, /cart/add.js or /cart/add; for WooCommerce, ?wc-ajax=add_to_cart) and read its status.
  3. A 403 or 503 whose response headers include cf-mitigated: challenge is a Cloudflare challenge. Any other 4xx or 5xx is a refusal from the store or a rule in front of it.
  4. Check your bot protection, firewall and rate limit logs for the same moment to find the rule that matched.

What to change

What Ottom looks at

The journey agent presses add to cart and watches the page and its network traffic. This is raised when the cart request went to the store and came back refused (a 4xx or 5xx) and nothing reached the cart. A Cloudflare challenge is named as one only when Cloudflare said so in its own response header.

Questions

Why does my store refuse the cart but not the product page?

Because bot protection usually scores requests that change something, like adding to a cart, more strictly than page views. The product page was let through and the cart request was not, so the agent got as far as choosing a product and no further.

Is a refused add to cart the same as needing JavaScript?

No. A cart that needs JavaScript never sends a request an agent can make. Here the request was made and the store refused it, so the fix is in your bot protection or firewall rules, not in the theme.

Check your store for this