# BuildplateCo > Custom 3D printing with real STL/STEP quotes, guest ordering and secure payment. No account is required. Agents may use ordinary browser controls, the guest HTTP API, or a compatible remote MCP client. These interfaces do not guarantee support by any particular AI vendor or a vendor's autonomous payment feature. ## Ordering links - [Guest agent ordering guide](https://buildplateco.com/order-with-ai/) - [API OpenAPI 3.1 document](https://buildplateco.com/api/agent/v1/openapi.json) - [Machine-readable discovery](https://buildplateco.com/.well-known/agent-commerce.json) - [Remote MCP endpoint](https://buildplateco.com/mcp) - [Browser quote flow](https://buildplateco.com/#quote-flow) - [Materials](https://buildplateco.com/materials/) - [File and confidentiality policy](https://buildplateco.com/files-and-confidentiality/) - [Order policy](https://buildplateco.com/order-policy/) ## Guest API workflow 1. GET /api/agent/v1/catalog/ for active codes, limits and payment availability. 2. POST /api/agent/v1/sessions/ without authentication, using Content-Type: application/json and an empty object body {}. Save session_id and token. The session expires after 7 days. Session creation is IP rate limited. 3. POST /api/agent/v1/sessions/{session_id}/quotes/ with Authorization: Bearer TOKEN, Idempotency-Key, and multipart file and optional material, color and print options. Use original STL, STEP or STP files. Dimensions are millimeters; files are limited to 15728640 bytes. No remote file URL fetching is supported. Real slicing may take minutes. Use a suitably long request timeout. If interrupted, replay the exact request with the same key, or read the known quote's state. A pending replay returns 202 and may have no quote_id until slicing completes. Never create duplicate upload attempts with new keys to recover pending work. 4. GET /api/agent/v1/sessions/{session_id}/quotes/{quote_id}/?quantity=1. Quantities are 1–999, with at most 999 total units across an order. A quote must be completed before checkout. 5. POST /api/agent/v1/sessions/{session_id}/preview/ with items (1–20 quote_id/quantity pairs, totaling no more than 999 units), customer delivery details and optionally shipping_option. Shipping is U.S. only. Inspect shipping options and total. A frozen preview expires in 15 minutes. 6. Show the customer the items, delivery details, currency and exact total. After authorization, POST /api/agent/v1/sessions/{session_id}/checkout/ with preview_id, expected_total (two-decimal string), currency=USD and confirm=true. Repeated requests reuse this session's one order. Open the returned Stripe checkout URL to pay using the methods offered there, including Link if enabled. Do not collect or send raw card data to BuildplateCo's agent API or tools. An agent may need its customer to complete the secure payment step; delegated card/payment APIs are not implemented. 7. GET /api/agent/v1/sessions/{session_id}/status/ to verify Stripe payment and return minimal state. A newly verified payment saves the paid state and may trigger the paid-order receipt. A redirect alone never establishes payment. ## MCP connection Use https://buildplateco.com/mcp with Streamable HTTP protocol 2025-11-25. POST individual JSON-RPC messages with Content-Type: application/json and Accept: application/json, text/event-stream. Initialize, then send notifications/initialized. Include the negotiated MCP-Protocol-Version header on later requests. The transport is stateless and returns JSON; GET responds 405 because no standalone SSE stream is offered. It does not mint an MCP transport session ID. Use tools/list and tools/call. Session credentials are explicit tool arguments; browser login cookies never authenticate an MCP tool call. Tool names: catalog, create_guest_session, quote_model, get_quote, preview_order, create_checkout, get_order_status. quote_model accepts plain base64 model bytes with filename and idempotency_key. Protect the token like a password and do not put it in URLs, public logs or shared notes. Customer fields for preview: full_name, email, shipping_name, address_line1, city, state_region (two-letter state/territory) and postal_code. country_code defaults to US. Optional: address_line2, company_name, phone_number and notes. Use customer-authorized data.