Being callable, not just findable
Work out whether your business should be an app an AI assistant can act inside, what that costs, and what to do instead when it should not.
on this page · 0 / 0 checked
A customer opens an assistant and says “order what I need for this recipe” or “put together a flyer for Saturday”. Increasingly the assistant does not answer with instructions. It starts the job inside somebody else’s product, using an account the customer has linked. Google began this in Search in July 2026, when AI Mode started letting people in the US “securely link and interact with” Instacart, Canva and YouTube Music from inside the conversation [1]. The question that lands on your desk afterwards is not philosophical. It is whether your business should be one of the products an assistant can act inside, and what that would cost you.
This guide is for a solo operator or a small team with something a customer buys or books: a store, a service with a calendar, a small software product. It is not for enterprise teams with a partnerships function, and it is not for a business whose value is judgement delivered in conversation, because there is no single action to expose and the honest answer for you is at the bottom. Prices and program rules below were fetched on 4 September 2026 and the platforms change them without notice.
Two kinds of distribution, and only one of them is SEO
Being cited and being called are different products with different economics. Being cited means your page’s words end up summarised in an answer with a link somewhere near them. Being called means an assistant does work inside your product with the account the customer linked. In AI Mode that looks like asking “Canva to show you some template options”, or curating a playlist and saving it “instantly” to YouTube Music [1]. With Instacart the assistant puts the ingredients “straight into your Instacart shopping cart”, and the customer finishes checkout “with just a few taps on their app or website” [1]. Even the flagship example hands off at the end.
The first is ordinary search work. Google is unusually blunt about it: “There are no additional requirements to appear in AI Overviews or AI Mode, nor other special optimizations necessary”, and “You don’t need to create new machine readable files, AI text files, or markup to appear in these features” [4]. Nothing you buy makes you more citable than a page that is crawlable, in text, and matches its own structured data.
The second is a partnership plus an engineering job, gated by a review queue. No amount of content work gets you there, and no vendor selling “AI visibility” can put you there either. Keeping the two separate is the single most useful thing in this guide, because most of the money small operators waste on this topic is spent buying the first thing while hoping for the second.
There is a third category worth naming, and for a lot of local businesses it is the one that matters. Google’s own advice for AI features includes “making sure your Merchant Center and Business Profile information is up-to-date” [4]. That is not an integration and it is not content. It is structured data about your business held in someone else’s database, and it is what an assistant reads when a customer asks for opening hours, a price or a place nearby. It costs nothing and almost nobody keeps it accurate.
For most small operators, someone else builds the integration
The plumbing has standardised faster than most people noticed. Google set out the Universal Commerce Protocol on 11 January 2026 as an “open-source standard designed to power the next generation of agentic commerce”, endorsed by more than 20 global partners including Shopify, Etsy, Stripe, Walmart and Target [3]. A business exposes its capabilities through a manifest at /.well-known/ucp, and the protocol supports “multiple transports including A2A, MCP and APIs” [3]. It is built to be compatible with the Agent Payments Protocol for the payment leg [3].
Read that partner list again. Shopify and Etsy are on it. If you sell through a platform, the protocol work is the platform’s problem, not yours. Your part is being eligible. On Google’s side, integrating with UCP lets you “implement a checkout button on eligible product listings in AI Mode in Google Search and on Gemini”, where customers “checkout quickly with Google Pay, using payment methods and shipping information already saved in Google Wallet” [2]. Getting there means meeting the published technical requirements, submitting an interest form, doing the implementation, tagging products with the native_commerce(checkout_eligibility) attribute, and keeping Merchant Center data such as product feeds and brand assets in good shape [2]. The feature is “available for select merchants at this time”, and eligibility is limited to products in the United States, Canada and Australia [2].
So the realistic first move for most readers is not to build anything. It is to find out what your store, booking or marketplace platform already ships, get your product feed and Merchant Center data accurate enough to be eligible, and put your name on the interest form. That is a morning of work, not a quarter.
The one action a stranger could complete without you
If you do have something worth exposing directly, the platforms narrow the design before you start. OpenAI’s app submission guidelines allow commerce “only for physical goods”, and selling digital products or services is not allowed [6]. Apps “must not serve advertisements and must not exist primarily as an advertising vehicle”, and must be “suitable for general audiences, including users aged 13–17” [6]. Tool names should be “human-readable, specific, and descriptive of what the tool actually does”, without “misleading, overly promotional, or comparative language”, and tools should take “minimal and purpose-driven inputs” [6].
Those rules read like bureaucracy and are actually a design brief. What passes review is one bounded action a stranger’s model can complete without asking you anything: add these items to a cart, generate this asset, save this list. What fails is a tool that needs three follow-up questions, a human to interpret the result, or a category the platform has excluded. If your revenue is a retainer, a subscription or a service booking, the commerce path inside a ChatGPT app is closed to you today, and what is left is an app that helps without taking the payment [6].
There is an upside for the ones that clear the bar. Apps that “demonstrate strong real-world utility and high user satisfaction may be eligible for enhanced distribution opportunities”, such as directory placement or proactive suggestions [6]. That is the actual prize, and it is awarded after the fact, not applied for.
The gate is a review queue and an account plan
Both large directories are gated by human review, and both describe your product to the model as a set of tools. On the OpenAI side, MCP tools “act as the manual for ChatGPT to use your app”, submissions “must come from verified individuals or organizations”, and a user with the Owner role or the api.apps.write permission creates the draft and submits it from the OpenAI Platform Dashboard [6]. Anthropic’s Connectors Directory accepts remote MCP servers, desktop extensions and MCP Apps [7]. Every tool must carry a title and the applicable readOnlyHint or destructiveHint, authenticated services must “use OAuth 2.0”, and for local connectors “missing or incomplete privacy policies result in immediate rejection” [7].
The review is a product review, not a security scan. OpenAI wants apps that show “stability, responsiveness, and low latency across a wide range of scenarios”, and singles out one avoidable failure: apps requiring “new account sign-up or 2FA through an inaccessible account” will be rejected, and reviewers expect a “login and password for a fully-featured demo account” [6]. Anthropic’s portal asks for the listing copy as well as the plumbing, including a server name of up to 100 characters, a tagline of up to 55, a description of up to 2,000, one to five categories, use cases, whether the connector reads data, writes data or both, and a URL slug that “is permanent once published” [7]. Budget a working day for the paperwork and pick the slug as carefully as you would a domain.
There is a cost most solo operators do not see coming. Remote MCP server submissions happen in a portal inside your organisation’s settings on Claude.ai, and organisation settings “aren’t available on individual plans”, so a remote listing needs a Team or Enterprise organisation; on Team, submitting stays with Owners and Primary owners [7]. Claude Team is $25 per seat per month billed monthly, or $20 per seat per month billed annually, for teams of 2 to 150 [8]. That is a subscription you carry before the listing earns anything, on top of hosting the server, and it does not shorten the queue: “review times vary with queue volume” [7]. Desktop extensions are the exception, submitted through a separate form that does not require the portal [7].
Claude Team is $25 per seat per month billed monthly, $20 billed annually, for teams of 2 to 150 [8]. Remote connector submissions happen in a portal inside organisation settings, which needs a Team or Enterprise organisation [7]. Server hosting and your own time are extra. Computed in the page; nothing is sent anywhere.
Tools written for a stranger’s model, not for your docs
The rules the two reviews share are the durable part, and they will outlive both directories. Name every tool for what it does in words a person who has never seen your product would understand [6]. Mark write and destructive tools honestly: OpenAI requires that write or destructive tools “must be clearly marked using the readOnlyHint and destructiveHint” [6], and Anthropic’s portal syncs your tools and groups them by whether their annotations declare them read-only or write, flagging any that are missing titles or annotations before you submit [7]. Take the fewest inputs that can possibly work, and return “only data that is directly relevant to the user’s request and the tool’s stated purpose” rather than the whole record [6].
The privacy rules are equally blunt and worth adopting whether or not you ever submit. Tools should “request the minimum information necessary to complete their task”, and must not request “the full conversation history, raw chat transcripts, or broad contextual fields” [6]. Restricted categories stay out entirely: payment card information, health data, government IDs and authentication credentials are prohibited [6]. Use OAuth 2.0 for authenticated services [7]. If your connector opens external links, declare the destinations, and every origin or URI scheme you list “must be owned by you”, because entries you do not own “will be removed during review” [7].
None of this is specific to one vendor’s directory. It is what any client, including your own internal agent, needs in order to call your product safely. Build it that way and the submission is paperwork rather than a rewrite.
Measuring the citation side, and knowing what the number is not
Google now reports the citation half in Search Console. The generative AI performance report covers AI Overviews and AI Mode, and “as of August 31, 2026, we’ve rolled out these insights to all websites worldwide” [5]. The metric is impressions, defined as “how many times links to your site were shown to a user in a generative AI feature on Google Search” [5]. AI Overviews and AI Mode are combined in one report rather than split, and Search Console “doesn’t include data from experiments in Search Labs, as these experiments are still in active development” [5].
Use it as a trend, not as attribution. It tells you whether the surface is showing you at all. It does not tell you which surface, what the query was worth, or whether anyone clicked. Google also warns that “the newest data can be preliminary, meaning it’s still being collected and might change in the next few hours”, and that chart totals can differ from table totals “due to differences in aggregation (property vs. page)” [5]. Check it monthly, not daily, and do not rebuild anything on one week of movement.
If you want less exposure rather than more, the existing controls still apply. Google lists nosnippet, data-nosnippet, max-snippet, noindex, and robots.txt directives for Googlebot as the way to manage Search, while Google-Extended is the control for other Google systems [4]. Blocking is a real option, and it is also a decision to be absent from the surface where the question is now being asked.
What still goes wrong
The biggest gap is between the announcement and the door. Google’s connected apps started rolling out in the US with three partners, and the company says only that it is “working with a range of partners” and looks “forward to launching with more apps soon” [1]. There is no published sign-up, no queue you can join, no criteria you can meet. The commerce side has a form, but the checkout is open to select merchants and the product eligibility covers three countries [2]. Small operators reading platform news as an invitation is the most common mistake in this whole area. Most of these are partner deals, and partner deals go to businesses with volume.
The second gap is categories. Selling digital products or services is not allowed in ChatGPT app commerce [6], which excludes a large share of the people most excited about agentic distribution. Freelancers, consultants and software subscriptions do not have a checkout path here, and pretending otherwise wastes a build.
The third is that a listing is a liability as well as an asset. By submitting, you agree to “maintain your connector’s security and functionality” and to “respond to security issues promptly” [7], and the compliance step requires seven policy acknowledgments, one of them covering prompt injection [7]. An MCP server is an internet-facing endpoint that a language model is allowed to drive on a stranger’s behalf. If you cannot answer a security report within a week, you are not ready to run one, and the plain website with a good booking page will serve your customers better than a half-maintained integration.
The last thing that goes wrong is timing. The interfaces are converging fast, and the same protocol now shows up on all three sides of this, as one of the transports in Google’s commerce standard [3], as the interface a ChatGPT app exposes its tools through [6], and as what Anthropic’s directory accepts [7]. That convergence is the reason the underlying work is safe to do. It is not a reason to do it early. The businesses that will benefit first are the ones already receiving orders through a platform that is doing the integration for them, and for everyone else the honest sequence is to fix the data, watch the impressions, and keep the build for the quarter when a real customer asks for it.
- 01Google — Connect more of your apps to Searchblog.google
- 02Google Merchant Center Help — About the Universal Commerce Protocol (UCP) and UCP-powered checkoutsupport.google.com
- 03Google Developers Blog — Under the Hood: Universal Commerce Protocol (UCP)developers.googleblog.com
- 04Google Search Central — AI features and your websitedevelopers.google.com
- 05Search Console Help — Generative AI performance report (Search)support.google.com
- 06OpenAI Developers — App submission guidelines (Apps SDK)developers.openai.com
- 07Claude Docs — Submitting to the Connectors Directoryclaude.com
- 08Claude — Pricingclaude.com