True & Co

True & Co is a direct-to-consumer women's intimates and lingerie brand, originally venture-backed (Cowboy Ventures, Uncork Capital) and now operating under PVH Corp. It sells bras, underwear, and loungewear online through a Shopify-hosted storefront at trueandco.com. The store exposes no traditional developer API, but it does expose a modern agent-commerce surface: a hosted Universal Commerce Protocol (UCP) MCP endpoint for catalog, cart, and checkout, Shopify Customer Account OAuth 2.0 / OIDC for buyer identity, a public read-only storefront JSON surface, and an agent-facing llms.txt / agents.md.

True & Co publishes 1 API on the APIs.io network. Tagged areas include Company, Consumer, Retail, E-Commerce, and Apparel.

True & Co’s developer surface includes authentication and 8 more developer resources.

17.4/100 emerging ▬ flat Agent 25/100 agent aware Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
1 APIs 1 MCP Servers
CompanyConsumerRetailE-CommerceApparelIntimatesAgentic CommerceShopifyMCP

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 17.4/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 3.9 / 20
Commercial Clarity 4.2 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 25/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/true-and-co: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

True & Co UCP Agent Commerce

Agent-facing commerce surface for the True & Co Shopify storefront: a hosted Universal Commerce Protocol (UCP) MCP endpoint for catalog search, cart, and checkout, backed by Sho...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

True And Co Authentication

1 scheme

SECURITY

True And Co Domain Security

no transport/DNS hardening detected

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

True And Co Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Resources

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Access & Security 3

Authentication, authorization, and security posture

Commercial 2

Pricing, plans, and the legal terms of use

Source (apis.yml)

apis.yml Raw ↑
aid: true-and-co
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/true-and-co.png
name: True & Co
description: 'True & Co is a direct-to-consumer women''s intimates and lingerie brand, originally venture-backed (Cowboy Ventures,
  Uncork Capital) and now operating under PVH Corp. It sells bras, underwear, and loungewear online through a Shopify-hosted
  storefront at trueandco.com. The store exposes no traditional developer API, but it does expose a modern agent-commerce
  surface: a hosted Universal Commerce Protocol (UCP) MCP endpoint for catalog, cart, and checkout, Shopify Customer Account
  OAuth 2.0 / OIDC for buyer identity, a public read-only storefront JSON surface, and an agent-facing llms.txt / agents.md.'
url: https://raw.githubusercontent.com/api-evangelist/true-and-co/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- cowboy-ventures
- uncork-capital
x-parent-company: PVH Corp
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Consumer
- Retail
- E-Commerce
- Apparel
- Intimates
- Agentic Commerce
- Shopify
- MCP
apis:
- name: True & Co UCP Agent Commerce
  description: 'Agent-facing commerce surface for the True & Co Shopify storefront: a hosted Universal Commerce Protocol (UCP)
    MCP endpoint for catalog search, cart, and checkout, backed by Shopify Customer Account OAuth for buyer identity. Payment
    completion always requires explicit human buyer approval.'
  humanURL: https://trueandco.com
  baseURL: https://trueandco.com/api/ucp/mcp
  tags:
  - Agentic Commerce
  - MCP
  - Shopify
  - UCP
  properties:
  - type: MCPServer
    url: mcp/true-and-co-mcp.yml
  - type: WellKnown
    url: well-known/true-and-co-well-known.yml
  - type: OAuthScopes
    url: scopes/true-and-co-scopes.yml
  - type: Authentication
    url: authentication/true-and-co-authentication.yml
  - type: Conventions
    url: conventions/true-and-co-conventions.yml
  - type: LLMsTxt
    url: llms/true-and-co-llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: MCPServer
  url: mcp/true-and-co-mcp.yml
- type: WellKnown
  url: well-known/true-and-co-well-known.yml
- type: OAuthScopes
  url: scopes/true-and-co-scopes.yml
- type: Authentication
  url: authentication/true-and-co-authentication.yml
- type: DomainSecurity
  url: security/true-and-co-domain-security.yml
- type: Conventions
  url: conventions/true-and-co-conventions.yml
- type: LLMsTxt
  url: llms/true-and-co-llms.txt
- type: TermsOfService
  url: https://trueandco.com/policies/terms-of-service
- type: PrivacyPolicy
  url: https://trueandco.com/policies/privacy-policy
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 10
  pass: local-v1