# Agent Instructions — Fly2High

This document describes how AI agents can interact with the Fly2High storefront at https://fly2high.net.

Fly2High sells third-party and in-house add-ons for Microsoft Flight Simulator (MSFS 2020, MSFS 2024) and X-Plane 12 — scenery, utilities, and GSX ground-handling profiles. It is a custom-built storefront, not a Shopify or WooCommerce store.

## For Personal Shopping Assistants and Agents Acting On Behalf of a User

Fly2High does **not** currently expose a programmatic commerce protocol. There is no UCP endpoint, no MCP endpoint, and no `SKILL.md`-style purchase skill for this store. Any agent that needs to complete a purchase on a buyer's behalf must do so by driving the browser-based checkout at https://fly2high.net/checkout with the buyer present and approving each step.

If and when this changes, this document will be updated to list the supported protocol version(s) and endpoints — reading this file is the canonical way to discover whether agent-driven commerce is supported.

## Checkout and Human Approval

- **Checkout requires contemporaneous human approval.** Payment is handled through Stripe Elements and PayPal; both require the signed-in buyer to approve each payment at the moment of charge.
- **Credentials, saved payment methods, and gift-card balances cannot be used by agents on the buyer's behalf without the buyer being present.**
- **Automated form submissions to `/checkout` or `/api/*` paths will fail** on authentication or rate limits. Do not retry aggressively; back off on `401`, `403`, and `429` responses.

## Read-Only Browsing (No Authentication Required)

For agents that only need to read store data without transacting:

### Product data
- All products: `GET /allproducts`
- Scenery category: `GET /scenery`
- Utilities category: `GET /utilities`
- Vendor directory: `GET /vendors`
- Vendor storefront: `GET /vendor-storefront?vendor={name}`
- Product page: `GET /products/{slug}` (slug is `{vendor}-{name}`, lowercased, non-alphanumeric replaced with `-`)
- Bundle page: `GET /bundles/{slug}`
- Current sales / promotional collections: `GET /special-deals`

### Store metadata
- Main sitemap: `GET /sitemap.xml`
- Agent discovery sitemap: `GET /sitemap_agentic_discovery.xml` — points at this document
- Agent discovery (this document): `GET /agents.md` — canonical agent-facing description of the store
- Robots directives: `GET /robots.txt`

### Newsletter and informational content
- Newsletter index: `GET /forum/fly2high-newsletter`
- Published newsletter articles: `GET /forum/fly2high-newsletter/{slug}`
- About the company: `GET /about`
- Companion app (Fly2Manager): `GET /fly2manager`
- Product-transfer policy: `GET /product-transfers`
- Support (human-only): `GET /get-support`

## Paths Agents Should NOT Probe or Index

The following paths are gated by Firebase Auth and role checks. Requests from unauthenticated clients return `401`/`403` and are logged.

- `/profile`, `/profile/order` — buyer account data
- `/admin-*`, `/vendor-manager`, `/partner-manager`, `/forum/vendor-manager` — role-gated management interfaces
- `/api/*` — mostly `POST` endpoints requiring a Firebase ID token
- Any URL containing `?token=`, `?paymentIntentId=`, `?reset_token=`, or `?autoapply=` — single-use links intended for a specific recipient. Do not index, cache, or share these.
- `?ref=` query parameters — referral tracking; the canonical URL is the same page without `?ref=`.

## Store Policies

- Privacy policy: https://fly2high.net/privacy-policy
- Terms and conditions: https://fly2high.net/terms-and-conditions
- Cookie policy: https://fly2high.net/cookie-policy

## Platform

Fly2High is a custom-built storefront on PHP + Firebase (Firestore, Auth, Cloud Functions), with Stripe and PayPal for payments. It is **not** on Shopify, WooCommerce, or any other commerce platform, so platform-specific agent conventions (Shop skill, UCP merchant discovery, etc.) do not apply here.

- Site: https://fly2high.net
- Operator contact: ashtonsweet.business@gmail.com

## Last updated

2026-10-04
