# Lumora, for automated readers Every live shop is listed at /catalog.json, and each shop's offers at /s/{slug}/catalog.json, newest first, with a paid placement marked as featured and never moved up the list. Shops live at /s/{slug} and each product at /s/{slug}/p/{id}, and a shop that has not claimed a slug is at /b/{id} with the same page on it. A piece somebody wrote and published lives at /w/{id}, under their name. All are plain HTML with no script, no cookie and nothing loaded from another host, so they can be read as they are. A shop counts opens of its own pages, so its owner can see what people look at. A piece of writing counts nothing at all: the page is rendered from the piece and keeps no record of anybody who reads it. You are welcome to read a catalogue, quote a price, and send a buyer to it, and to quote a piece of writing with its author and its address. What an agent can do here, and where each one stops: - Buy one thing: https://lumora.medallionmaze.com/buy/{id} opens the card page for the person to review and pay. Only offerings that carry a schema.org BuyAction can be bought this way. - A basket: https://lumora.medallionmaze.com/buy?ids={id},{id} (up to eight, one shop) opens one card page for all of them. - Book: the ReserveAction on a bookable offering opens the business in the Lumora app with the time already written in a message the person sends. - Ask: the AskAction opens the same message box with the question in it. - A shop's own tools, where it has published any, are at https://lumora.medallionmaze.com/a/{name}. Nothing here pays, books or sends on its own: every one of those ends at a screen the person confirms. WebMCP: shop pages mark the basket as a declarative tool (toolname="start_checkout", and never toolautosubmit, so the browser stops at the button). Pages that run script load https://lumora.medallionmaze.com/agent-tools.js, which registers list_offerings, get_offering, start_checkout, request_booking, ask_business from the page's own structured data. Every one of them returns an address and does nothing else. Each tool says its class in its description: Answer (list_offerings, get_offering); Action (request_booking, ask_business); Sensitive action (start_checkout). An Answer reads only; an Action ends at a screen the person confirms; a Sensitive action leads to money and always waits for the person, and never submits itself. Every kind of page, and what an agent can do on it: - Shop and offering pages (schema.org Organization, LocalBusiness, Store, and kin): /s/{slug}, /s/{slug}/p/{id}, /b/{id}, /b/{id}/p/{id}, /r/{id}, a merchant's own domain. Tools: list_offerings (Answer), get_offering (Answer), start_checkout (Sensitive action), request_booking (Action), ask_business (Action). As declarative forms on the page: start_checkout, request_booking, ask_business. - Event pages (schema.org Event, MusicEvent, SportsEvent, and kin): /s/{slug}/p/{id} and /b/{id}/p/{id}, when the offering is an event. Tools: get_event (Answer), reserve_ticket (Sensitive action), ask_business (Action). As declarative forms on the page: reserve_ticket, ask_business. - Pieces of writing (schema.org Article, BlogPosting, NewsArticle, and kin): /w/{id}. Tools: read_piece (Answer), list_works (Answer), connect_person (Action). As declarative forms on the page: connect_person. - Creator and member pages (schema.org Person, ProfilePage): /p/{handle}. Tools: get_profile (Answer), list_works (Answer), connect_person (Action). As declarative forms on the page: connect_person. - Records and certificates (schema.org EducationalOccupationalCredential, Dataset, Report): /cert/{id}, /proofed/{code}, /p/{id} (a proof card), /v/{id}. Tools: get_record (Answer). - Club sign up sheets (schema.org SportsTeam, SportsOrganization): /join/{code}. Tools: list_programs (Answer), start_signup (Sensitive action). As declarative forms on the page: start_signup. - Apply pages (schema.org ContactPage): /apply/{code}. Tools: get_apply_page (Answer), start_application (Action). As declarative forms on the page: start_application. - Tip jars (schema.org DonateAction): /tip/{code}. Tools: get_jar (Answer), leave_tip (Sensitive action). As declarative forms on the page: leave_tip. - Drops and objects (schema.org CreativeWork, VisualArtwork, MusicRecording, and kin): /c/{id}, /o/{id}. Tools: get_work (Answer). - Courses (schema.org Course, CourseInstance): not served by Lumora yet; registered from an owner's own page by the one line. Tools: list_courses (Answer), enrol_course (Sensitive action). - Job postings (schema.org JobPosting): not served by Lumora yet; registered from an owner's own page by the one line. Tools: get_job (Answer), start_application (Action). - Invoices (schema.org Invoice): not served by Lumora yet; registered from an owner's own page by the one line. Tools: get_invoice (Answer), pay_invoice (Sensitive action). An Answer is the page's own structured data, which you can read directly on a page that runs no script. https://lumora.medallionmaze.com/agent-tools.js registers only the tools of the kinds a page's own JSON-LD @type names, and a site anybody runs can load it with one line. Forms that fill for you stop at the button; none of them submits itself. Pages that carry no tool on purpose: /r?orgId=&jobId=&token=; /story/{token}; /e/{id}; /a/{id}; /k/{id}; /buy and /buy/{id}; /, /sellers, /privacy, /terms, /guidelines, /legal, /trust, /transparency; the music, age check and connect sign in returns; /book/{shop} and /book/done|cancel/{signed}. Each is plain HTML you can read. What we ask: - Say what you are in your user agent. Traffic that declares itself is excluded from the seller's visitor numbers, which is what stops a crawl turning one shop owner's pricing decisions into fiction. Declaring yourself helps the merchant, not us. - Keep to roughly one page every two seconds per shop. - Do not buy on somebody's behalf without their instruction. Checkout is a real payment to a real small business and a reversal costs them the goods and the fee. - /v1/ is an application interface for the Lumora app, not a public data source. No part of a shopper's record is on these pages. There is nothing here to harvest about a person, because nothing about a person is kept here. See https://lumora.medallionmaze.com/trust.