DESIGN EXCHANGE Intelligence Logs
Design Exchange Strategy · Zero-Click Marketing, Part 1 of 4 · Field Notes

Zero-Click Marketing (Part 1): Why an AEC Studio Built an MCP Storefront That Answers Back

A zero-click marketing strategy for an AEC firm is the practice of publishing a machine-callable interface — not a page that AI crawlers can read. Design Exchange, a small AI-augmented building design consultancy, deleted its Wix brochure on 1 January 2026 and in September 2026 gave the machines their own front door: a Model Context Protocol (MCP) server at https://designxc.com/api/mcp that any AI agent can call with no key, no account, and no page load. Three tools, one evening, zero new infrastructure.

This article is the build log, the reasoning, and the playbook for other AEC firms.

By Design Exchange · September 8, 2026 · Updated September 11, 2026 · Revision 5 · Status: verified against the live production endpoint · Canon: designxc.com/articles/zero-click-marketing · Zero-Click Series, Part 1 of 4

“Installed, not ranked; called, not clicked.”
— Design Exchange, September 2026

TL;DR


Definitions

Zero-Click Marketing (n.). Visibility earned without a website visit: the brand is consumed inside someone else's surface — a featured snippet, an AI Overview, or an agent's tool call — and the conversion can complete without your site ever loading. Three generations: featured snippets (v1), answer engines (v2), agentic interfaces (v3).

Model Context Protocol (MCP) (n.). An open protocol introduced by Anthropic in November 2024 and adopted by OpenAI (March 2025) and Google (April 2025) that lets one AI agent invoke a tool on a server and receive a structured result. JSON-RPC 2.0 over streamable HTTP. Tool-call semantics: pick a tool, supply arguments, receive a result.

AI→AI Endpoint (n., Design Exchange usage). A server whose response is an intelligence answer — synthesized on the serving side, grounded in a curated corpus, in the firm's own voice. The caller receives a verdict, not chunks. Coined by Design Exchange in this article, September 2026.

AI→Data Endpoint (n.). A server whose response is chunks, documents, or raw fields. The caller does all the synthesis, compliance checking, and judgment. The classical chunked-RAG pattern.

Concierge (n., Design Exchange usage). Design Exchange' production AI agent — a multi-model, multilingual terminal that replaced the firm's Wix brochure on 1 January 2026. Runs on Netlify Edge Functions with Supabase pgvector retrieval grounding.

Chunks (n.). Pre-written content segments indexed for retrieval-augmented generation. Serve answers that have already been written down. Do not serve answers that must be computed, conditioned, or committed by the firm.

Rate-Limit Backpressure (n.). Headers (RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Retry-After) returned with every endpoint response so a calling agent can pace itself, back off gracefully, and treat rate limits as customer success rather than as churn.

Attribute Value
Endpoint designxc.com/api/mcp
Protocol Model Context Protocol (JSON-RPC 2.0 over streamable HTTP)
Protocol version 2026-09-02
Transport streamable-http
Status active
Authentication none (open endpoint, no key, no account)
Runtime Netlify Edge Function (Deno)
Vector store Supabase pgvector
Concierge launch January 1, 2026 (replaced Wix brochure)
MCP-native since September 2, 2026
MCP public since September 8, 2026
A2A live since September 15, 2026
Live verification September 11, 2026
Public surfaces designxc.com/llms.txt · designxc.com/.well-known/agent-card.json · logs.designxc.com
Source github.com/Axotopia

01 / What zero-click marketing means for an AEC firm

Zero-click marketing is visibility earned without a website visit: the brand is consumed inside someone else's surface — a featured snippet, an AI Overview, or an agent's tool call — and the conversion can complete without your site ever loading.

For an architecture, engineering, or construction practice, this is not an abstraction. AEC has always been a referral business. Nobody has ever said “I found my architect through a Google ad.” The referral worked because a trusted party answered a question on your behalf. What changed in 2025 and 2026 is that the trusted party is increasingly a machine: a developer's research harness, a homeowner's assistant, another architect's tool-calling client. It assembles a shortlist before a human ever speaks to a firm. If an agent cannot reach you, you are not on the shortlist — and you never learn you were excluded. There is no impression to count, no bounce to analyze, no form abandonment to optimize.

Design Exchange is a small AEC design consultancy. We do not sell square footage. We sell judgment about what can be built: whether a lot yields two units or four, where the setback lands, whether the envelope can hit its energy target, what a feasibility study costs, and what we would need to see before we would stake our name on an answer. That product has an unusual consequence — in this business, the first thing a client does is ask a question. Not browse a portfolio. Not fill in a form. They ask can I build this, and they decide who to hire based on the quality of the answer.

We built a public MCP server for four reasons, in this order:

  1. The question moved. Agentic search is the new referral: an agent vouching for you by calling your tool and getting a real answer. That channel does not care how good your photography is.
  2. Principal time is the whole business. A small firm has a handful of billing brains. Every unqualified inquiry costs a conversation before it costs a drawing. Our $40-a-month Wix brochure was an operational tax — it attracted traffic that then had to be qualified by hand, one repeated FAQ at a time. We wanted a storefront that answers the FAQ itself and hands us only the residue.
  3. Our product is answers, so an API is the honest delivery mechanism. A brochure describes. It cannot tell a developer whether an ADU pencils out on a 6,000-square-foot lot, or tell a homeowner what “design-build” means for their budget. An endpoint can — grounded in real project data, in our own voice, at zero marginal cost per conversation.
  4. AEC answers are checkable, which is exactly why this works. Zoning, setbacks, lot coverage, floor-area ratio, window-to-wall ratio, energy envelopes, septic fields: these are not vibes. They are rules with jurisdictions attached. A machine can verify them, which means a machine can use them. Few industries are this well-shaped for an agent to interrogate.

And one reason we are careful: in AEC, a wrong answer is not a bad impression — it is a liability. A hallucinated setback, or a scope claim the firm cannot legally seal, is a professional risk rather than a marketing one. Everything below is downstream of that sentence.


02 / The click is a legacy paradigm: three generations of zero-click

Zero-click has moved through three generations — featured snippets, answer engines, and now agentic tool calls — and each generation moves the conversion further away from a page view. The data on generation two and three is unambiguous.

Metric Value Source
US Google searches ending in a click (2024) 360 of every 1,000 SparkToro/Datos 2024 Zero-Click Search Study
Google searches ending without a click (Jan–Apr 2026) 68.01% SparkToro, June 8, 2026
CTR loss for top result when AI Overview appears 58% Ahrefs, Feb 4, 2026
AI-assisted search visitors converting to signups (Ahrefs self-reported) 0.5% of visitors → 12.1% of signups Ahrefs, 2026
llms.txt files never read by AI 97% Ahrefs, 2026
GEO paper headline lift (citations, statistics, quotations) up to +40%; per-tactic Statistics +115.1%, Cite Sources +77.0%, Quotation Addition +72.2% Aggarwal et al., KDD 2024 (arXiv:2311.09735)

The 2026 crawler-telemetry literature (Vercel and others) converges on the same finding: AI crawlers largely do not execute JavaScript. For a growing share of buyers, a client-rendered portfolio site is a locked box with no handle.

Generation Surface AEC firm's role Win condition
v1 — Featured snippets Search results, paragraph extract You are a source, not a destination Win the box and lose the visit
v2 — Answer engines AI Overviews, chatbots, prose citations You are a quotation, often with no link Be cited, accept ghost citations
v3 — Agentic Tool calls into your server You are a counterparty on the wire Be the tool the agent chooses, then do not be dropped

The last number in the table is the strategy. The buyers are still out there — they are being answered somewhere else. Traditional zero-click marketing accepts this and optimizes snippets. We asked a different question: what if the conversion could complete without our website ever loading?


03 / Chunks or a concierge? The question that decides whether you should build this

Chunks serve answers you have already written down; a concierge serves answers that must be computed, conditioned, and committed. If your answers fall in the first category, do not build a concierge.

Capability Why chunks can't do it Receipt
Computed pricing Pricing is a function of scope, not a fact you can write down once Our endpoint returns differentiated ranges by service type — a computation, not a lookup
Liability-bearing reasoning An agent improvising from raw code chunks answers in your name Our position: hallucinate a building-code clause and the practice is exposed — which is why every answer runs through a five-layer verification stack rather than a model's confidence
Compliance at the answer boundary You cannot firewall professional terminology inside a chunk that gets quoted out of context Ours is enforced at synthesis time
The qualifying interview A lead is a dialogue ending in a transaction, not a retrieval Our booking tool writes a structured lead — site, scope, question — where a contact form would have collected an email address
Freshness Chunks freeze at index time and go stale silently A concierge answers from a database that updated an hour ago
Market intelligence Page analytics tell you which pages exist Query logs tell you what buyers actually ask. In our case, the tool-call log is the analytics suite and the sales pipeline in one file

Chunks expose your firm's memory. A concierge exposes your firm's judgment — priced, qualified, compliant, and logged — at a marginal cost of cents. Wix gives agents your brochure. The endpoint gives them the first five minutes of the meeting.


04 / What an AEC agent actually asks

The queries that reach an AEC practice's endpoint are the same queries that used to consume principal time on the phone — and they are the reason a chunked brochure cannot substitute for an answering endpoint. Representative of what we see and what our own test harnesses ask:

Read that list again as a marketer. Every line is a question, and every line ends in a decision — hire, shortlist, or discard. A portfolio page answers none of them. A contact form defers all of them to a meeting that costs the firm an hour. An endpoint answers them, and the ones it cannot answer honestly become the most valuable thing in the whole system: a stated limit, delivered to the exact person who was about to ask.

That last query — what do you not do — is worth dwelling on. In AEC, the single most useful thing an agent can learn about a firm before recommending it is the boundary of what the firm can legitimately deliver. Design Exchange states its position up front, where an agent can read it: the practice works as Building Designers, not Architects, and sealed work routes through licensed partners. That is not a hedge. It is the condition for publishing an answer at all, and it is the kind of scope statement a referral network has always relied on verbally.


05 / The architecture: one evening, one edge function, one new client

The MCP connector took one evening and added zero infrastructure, because the hard part already existed: a headless AI brain wearing a terminal UI, already grounded, already rate-limited, already hardened. MCP only pointed it outward.

Design Exchange deleted its Wix brochure on January 1, 2026 and replaced it with The Concierge — see Definitions for the full launch timeline. That terminal is not a chat widget bolted to a marketing site. It is a headless brain, and the terminal is one client of it. The architecture those eight months produced is a Brain–Hands–Voice loop, forced by Netlify's 10-second serverless timeout:

Layer Role Location Function
Brain Intent detection Netlify Edge Function (Deno) Parses visitor intent, decides which tools to invoke
Hands Tool execution Visitor's own browser Executes tool calls, retries, paces requests
Voice Streamed synthesis Edge (Deno) Returns the composed answer in the Concierge's voice

MCP's role in one sentence: it hands the tools to the agent. The visiting runtime assumes the Hands role entirely — it does the calling, the retrying, the pacing. Brain and Voice never moved. The terminal did not change a line, because it was always just one client of a headless brain.

Three guardrails governed the build, and they are worth copying:

  1. Additive only. The existing /api/chat pipeline, the React frontend, and the human experience were untouched. If your launch has a regression list, your architecture is wrong.
  2. Zero new infrastructure. No server processes, no new vendor. Everything runs inside Netlify Edge Functions on hosting already paid for. Marginal monthly hosting cost: $0.
  3. Firewall coexistence. The site aggressively blocks on-demand AI scrapers. Legitimate agent traffic to the new endpoint passes the same wall unharmed; every other endpoint stays guarded. We shipped a live regression test confirming that /api/chat still returns 403 to an agent user-agent while /api/mcp passes the identical client through.

The audit is the build. Before writing a line, we audited the AI-generated implementation prompt against our own codebase. It was roughly 70% right, and the remaining 30% was landmines — a phantom function name (searchVectorDatabase(), which has never existed in our code; ours is getVectorContext() and has been since January), a wildcard CORS header on a shared utility that would have quietly loosened the human chat endpoint too, and no rate limiting at all on a call that invokes a frontier model. Your codebase's API surface is a contract. A language model's plausible function names are not.


06 / Two MCP surfaces, opposite epistemics

Design Exchange runs MCP on both sides of the practice with opposite rules: a deterministic server that cannot hallucinate, and a conversational endpoint that is built to hold a conversation. Same protocol, opposite epistemics.

Surface Side Epistemics Tools Use case
revit-tools MCP server (Python) Production Deterministic — reads Revit model, returns measured numbers Window-to-wall ratio, energy envelope, lot coverage, setbacks, floor area, septic clearance Compliance audit, geometry check
Concierge MCP server (Deno Edge) Public Conversational — synthesized, grounded, scoped, voice ask_concierge, search_knowledge_base, book_consultation Judgment questions, lead capture

If you take one thing from this series, take that split. Never let a model guess a number, and never make a client read a table when they asked you a question. The deterministic half of the practice does not need an article like this one, because numbers cannot be persuaded. The half that talks does — and that is why the public surface needed eight months of hardening before it earned a front door, and why it needed a second, adversarial pass after the door was built. That pass is Part 2.


07 / Eight months of scar tissue: the connector was hardened before it existed

The MCP connector was not designed, it was scar tissue. Everything it needed — grounding discipline, rate limiting, an edge firewall, a sanitized knowledge base — already existed because attackers had already forced it into existence.

Date Event What it taught Cost
2026-01-01 Concierge terminal launched; Wix deleted Public agents will probe the surface within hours —
2026-01 #2 on Show HN; 2,000+ engineers in six hours One-master-prompt architecture collapses under context rot $0.74 AI hosting
2026-02 External technical audit scored 8.625/10 Production-grade CSRF, rate limiting, exponential backoff; flag: no server-side job queue —
2026-03 Verdict: friendly Concierge built for Jan 2026 will be eaten alive in 2027 Interaction-pacing analysis, model failover, edge firewall required —
2026-06 Radical-transparency logs leaked PII through raw RAG dumps Publishing is a disclosure decision; deletion is not hiding —
2026-08 Adversarial audit found corpus had quietly become a dossier “Redacted” records revealed hidden text on hover; production export in the open; third-party names in profile records —
2026-09-02 MCP-native upgrade Endpoint became protocol-addressable —
2026-09-08 MCP public launch All scar tissue now load-bearing on a public surface —

The grounding rule — source of truth is the curated vector library, never the model's mood — is what keeps a confident answer from becoming a confident liability. For an AEC firm with professional exposure, that discipline is not a technical preference. By September, everything the connector needed already existed. We had simply never pointed it outward.


08 / What we shipped: three tools, ask, search, act

The public MCP server exposes three tools: one to ask, one to search, one to act. Live at https://designxc.com/api/mcp over streamable HTTP with JSON-RPC 2.0, no authentication, no API key.

Tool Signature Purpose Inference cost Use case
ask_concierge ask_concierge(query, userLocation?) Verdict in the firm's voice; URL-validated portfolio images Cents per grounded answer Feasibility, scope, approach
search_knowledge_base search_knowledge_base(query, limit?) Raw semantic chunks for the caller's own synthesis Free Project histories, technical research
book_consultation book_consultation(name, email, scope) Structured lead to the same table the human path uses Free Site, scope, question → principals

Plus the handshakes an MCP client expects: initialize, tools/list, tools/call, resource reads, and /mcp and /sse aliases for clients that probe convention rather than configuration. Current advertised protocol version: 2026-09-02. Transport: streamable HTTP. Status: active. Total new infrastructure: none. Total monthly marginal hosting cost: $0. Build time: one evening — on top of eight months of scar tissue.


09 / A wall with a sign on it: why rate limits must be legible to machines

An open endpoint needs a rate limit, and the limit has to be readable by the machine that hits it: headers on every response, a Retry-After on the cap, and a structured error rather than a silent wall.

Header / signal Value Meaning
RateLimit-Limit 30 Requests per minute per IP
RateLimit-Remaining 0–30 Remaining requests in the current window
RateLimit-Reset Unix epoch When the window resets
Retry-After Seconds Backoff advice when capped
HTTP 429 — Structured JSON-RPC error returned on cap
X-MCP-Daily-Limit 50 Grounded answers per address per day (per ask_concierge)
X-MCP-Daily-Remaining 0–50 Remaining grounded answers today
X-MCP-Daily-Reset Unix epoch When the daily budget resets

We rate-limited the endpoint the same week we shipped it — a 30-requests-per-minute sliding window per IP, counters in Netlify Blobs, the same mechanism the chat pipeline has used since the Hacker News siege. Agents read these signals. A well-behaved harness backs off on Retry-After; a tool-calling client tells its human “this firm is rate-limited, retrying in 42 seconds.” A silent wall looks like a broken server — and a broken server gets dropped from the tool list.

One thing that wall did not do: cap spend. Thirty requests a minute bounds speed; it says nothing about how many minutes there are in a day, and there are 1,440. The endpoint has since gained a daily inference budget — fifty grounded answers per address per day, down from a theoretical 43,200 — advertised to machines as X-MCP-Daily-Limit, X-MCP-Daily-Remaining, and X-MCP-Daily-Reset, and scoped to ask_concierge only, because that is the one tool that invoices us. Search and read tools do not consume it. A per-minute limit is a throughput limit, not a budget. That correction is Part 2, and it is the single most important number in this series.


10 / The SEO paradox, inverted

An AEC firm's website is usually invisible to the crawlers that index answers — so the fix is three layers: a crawlable evidence corpus, synthetic discovery channels, and an endpoint agents can interrogate instead of scraping.

Layer Surface Function Trade-off
1. Crawlable evidence corpus logs.designxc.com Static, terminal-styled evidence — internal logs, system audits, postmortems 52 records / 53 sitemapped URLs at launch; trimmed to 32
2. Synthetic discovery channels llms.txt, robots.txt, meta tags, Schema.org action markup, /.well-known/mcp.json, ai-plugin.json Tell machines where the endpoint lives; top-of-file directive with invocation examples 97% of llms.txt files never read; the 3% that are read are exactly the audience that skips your homepage
3. The MCP connector itself https://designxc.com/api/mcp Let agents interrogate tools instead of scraping The site that was a black box to Google is an open API to agents

Our own technical analysis named the project's central paradox: the main site exposes exactly one URL to search engines. Hash-based routing, no server-side rendering, and content that only exists when a user queries it. A site whose product is answers is invisible to the machines that index answers. To Google, The Concierge is a black box. AEC firms are unusually exposed to this. The industry's entire web presence is built on the things agents cannot read: image-heavy portfolios, “our process” pages, contact forms. None of it answers a question, and all of it is invisible to a crawler that does not render JavaScript.

Two traps we hit and fixed. Our single-page app's catch-all returned HTTP 200 with the homepage's HTML for every missing route, so an agent probing /mcp or /sse saw “200 OK” and choked on markup — both paths now alias straight to the edge function and return real JSON. And for a few days the llms.txt advertised an endpoint that the canonical host still answered with 404s. Advertise only what is live. An advertised-but-dead door is worse than no door.


11 / The Kimi test: how an agent that never heard of us found the endpoint

An off-the-shelf AI harness with no training knowledge of Design Exchange failed to find us through search, then succeeded instantly once it switched to protocol discovery — which is the whole lesson about machine discovery.

We pointed an off-the-shelf harness (Kimi K3) at the firm with one mission: find services and pricing. That is the actual first question in AEC, and the agent did what wild agents do — a web search, which surfaced static page snippets and none of the dynamic answers, then stalled. It had zero training knowledge of the endpoint, because model weights do not read the news.

Then a human mentioned “they have MCP.” The agent switched instantly from search-engine mode to protocol-discovery mode and probed the standard locations: /.well-known/mcp.json, /mcp, /sse, /llms.txt. The manifests answered, the handshake succeeded, and the Concierge started doing what it does — grounded answers, real pricing logic, and a working consultation path.

Two lessons: wild agents do not know you exist until your machine-readable surface is indexed — the retrieval layer is the new index, and for AEC it is the new referral network. And when hinted, agents probe standard paths blindly: if your endpoint lives at a nonstandard URL, or a fake 200 poisons the probe, you fail discovery at the exact moment you were found.


12 / Bought pipes, built soul

The protocol is becoming a commodity — website platforms now auto-generate MCP endpoints — so the differentiator is what answers when the tool is called. We audited a platform-generated endpoint. The handshake works, the tools respond, and the server's identity inherits whatever the site's business-name field contains, trailing space and all. The plumbing is free now, like SSL, like CAD interoperability.

Dimension AI→Data endpoint AI→AI endpoint (Design Exchange' model)
Response Chunks, documents, raw fields Synthesized answer in firm's voice
Reasoning Caller's side Server's side
Injection surface Limited (parameterized queries) Full (caller's text reaches a thinking model)
Disclosure surface Limited (only what is stored) Full (model can volunteer unprompted)
Write autonomy None May fire on a sentence, not a click
Cost per call Free or cents (retrieval) Cents to dollars (paid inference)
Difficulty to secure Standard read-API hygiene Member-of-staff governance

When every AEC firm has an MCP endpoint, what separates them is the answer: a curated knowledge base built from real project data instead of marketing copy chunked by a plugin; a voice that survives synthesis; a pricing philosophy served on request instead of “contact us for a quote”; and a scope posture stated plainly — including what the firm does not do and where sealed work routes, which is the single most useful thing an AEC agent can learn before it recommends you. Bought plumbing. Built soul. The endpoint is table stakes; the answers are the moat.

That difference has a name, and it is worth naming before the market does. A platform-generated endpoint is AI→data: the agent asks, the server returns chunks, and every act of reasoning happens on the caller's side. It is an index with a handshake. Ours is AI→AI: there is an intelligence on our side of the wire, and it answers — curated corpus, our voice, live pricing logic, and an explicit judgment about scope. Not a filing cabinet with a handshake. A counterparty.

As far as we know, that makes it the first AI→AI website in AEC consulting. We cannot prove that, and we would rather be corrected than quoted: if another firm has one in production, tell us and we will link it here. What we can prove is the mechanism — and the mechanism is free to copy, which is precisely why the endpoint is not the moat. The moat is what answers, and how hard that is to govern. That accounting is Part 2.


13 / The zero-click funnel, in AEC terms

When the visit never happens, the funnel metrics change names. For an AEC practice, the translation looks like this:

Legacy metric Zero-click replacement
Impressions Tool calls — every ask_concierge invocation is an impression that actually read your answer
Rank position Selection share — how often an agent names you when a developer asks for three firms
Bounce rate Error rate — JSON-RPC failures and rate-limit hits are the new pogo-sticking
Form conversion book_consultation events — structured, attributed, delivered with site and question attached
CAC Cost per qualified conversation — cents of inference per grounded answer, budgeted at 50/day/address

No landing page, no tracking pixel, no form abandonment. The agent runs the qualification interview itself and submits the intake as a function call. That is the part that matters for a small practice: the FAQ conversation stops being principal time.

The receipts so far, self-reported in keeping with house style: the January terminal launch took 17,401 pageviews from 5,084 unique visitors on 631 MB of bandwidth in thirty days, and the six-hour Hacker News torture test — 2,000+ engineers — cost $0.74. The MCP era is younger than the ink on this article; its counters are tools/call logs, not pageviews. That is the point.


14 / The playbook for AEC firms

If you are an AEC firm considering an agent-facing endpoint, this is the compressed version of what we would do and what we would insist on:

  1. Design 2–4 tools, not 40. One to ask (feasibility, scope, approach), one to search (projects, methodology), one to act (book, or submit a site). Tools are a menu; menus with too many items read as a lack of focus.
  2. Decide which kind of endpoint you built, before you build it. An AI→data endpoint returns chunks and can be secured like any read API. An AI→AI endpoint answers — and inherits injection, unprompted disclosure, autonomous write paths, and per-answer cost as part of the deal. Both are valid. Only one is a governance problem.
  3. Ground every answer, and state your scope honestly. In AEC the failure mode is not a weak impression, it is a client who relied on something the firm cannot legally deliver. Publish your licensure posture and your scope limits where an agent can read them, then hold the model to both.
  4. Write tool descriptions like ad copy. They are read aloud at the moment an agent decides whether to call you.
  5. Ship additive. One edge function, one new route, zero changes to the human path.
  6. Rate-limit legibly — and budget the bill. Headers on every response, Retry-After on the cap, structured errors. Remember that a per-minute limit is a speed limit, not a budget.
  7. Advertise in every machine channel. Top-of-file llms.txt, robots.txt directives, meta tags, JSON-LD actions, /.well-known manifests. Alias the standard probe paths and kill the SPA fake-200.
  8. Publish receipts. For a practice with no portfolio grid, a machine-readable evidence corpus — project records, audits, postmortems — is the only thing an agent can verify. Redact by deleting, never by hiding.
  9. Keep one voice on both sides of the glass — and log everything. The terminal and the endpoint are the same employee, and the tool-call log is your analytics suite and your sales pipeline in one file.

15 / FAQ: what humans and retrievers ask

Why would an architecture or AEC firm need an API?
Because in AEC the buying journey starts with a question — can this lot be built on, how many units, what is the setback, what does a feasibility study cost — and those questions are increasingly asked to AI agents that assemble shortlists before contacting anyone. An MCP endpoint lets an agent get a grounded answer in the firm's own voice instead of scraping marketing copy. Design Exchange built one in one evening on Netlify Edge Functions with zero new infrastructure.
What is zero-click marketing?
Visibility gained without a website visit: the brand is consumed inside someone else's surface — a featured snippet, an AI Overview, or an agent's tool call — and the conversion can complete without the site ever loading. Design Exchange frames it in three generations: featured snippets (v1), answer engines (v2), and agentic interfaces where the impression is a tool call (v3).
Do I need a live LLM on my site if agents can already read my content?
Only if your answers must be computed, conditioned, or committed. Chunks serve answers you have already written down; a concierge serves what you would otherwise answer live — pricing by scope, compliance judgment under verification, and qualifying interviews that end in structured leads. If your answers are stable, already written, and carry no liability when relayed imperfectly, chunking wins and you should not build this.
What is an AI→AI website?
One where an AI on the serving side answers visiting AI agents directly. Most MCP servers are functions you call and get a result from. Ours is a counterparty — see Section 12 for the comparison table. As far as we know it is the first in AEC consulting; if you know of another, tell us.
How does a machine-generated answer stay inside licensure and liability limits?
By grounding and by scope. The Concierge's source of truth is a curated vector library of real project data, never the model's own confidence. It states the firm's compliance posture up front — Design Exchange works as Building Designers, not Architects, and sealed work routes through licensed partners — and it declines to invent jurisdiction-specific code determinations it cannot source. That is not a marketing preference; it is the condition for publishing an answer at all.
How does a website become MCP-ready?
Ship a Model Context Protocol server — JSON-RPC 2.0 over HTTP, streamable transport — exposing two to four domain tools (ask, search, act), backed by retrieval-grounded answers from a real knowledge base, rate-limited with machine-readable backpressure (RateLimit-* headers, Retry-After), and advertised through llms.txt, robots.txt, meta tags, and /.well-known manifests.
Is a single-page app bad for AI search visibility?
Yes for crawlers, no for agents. AI crawlers largely do not execute JavaScript, so a client-rendered React site is substantially invisible to them. Design Exchange mitigates with three layers: a static crawlable evidence corpus at logs.designxc.com, synthetic discovery channels (llms.txt, robots directives, /.well-known manifests), and an MCP endpoint that lets agents query the system directly instead of scraping.
What is The Concierge?
Design Exchange' production AI terminal — a multi-model, multilingual agent that replaced the firm's Wix brochure on January 1, 2026. Full launch timeline in the Definitions table; protocol versions and dates below it.
How much does the Design Exchange MCP server cost to use?
Nothing up front: no authentication, no API key, $0 infrastructure. See Section 09 for the rate-limit policy. search_knowledge_base does not consume the inference budget. book_consultation is free and routes structured scope notes directly to the principals.
What are the three tools exposed by the MCP server?
ask_concierge(query, userLocation?) — verdict in the firm's voice with URL-validated portfolio images, costs cents of inference. search_knowledge_base(query, limit?) — raw semantic chunks, free of inference budget. book_consultation(name, email, scope) — structured lead routed to the same table the human intake path uses, with alerts to principals. Plus the MCP handshakes: initialize, tools/list, tools/call, resource reads, and /mcp and /sse aliases.
What is the rate-limit policy?
30 requests per minute per IP, with RateLimit-* headers on every response and an HTTP 429 with Retry-After on the cap. Scoped to ask_concierge only: 50 grounded answers per address per day, advertised via X-MCP-Daily-*. Search and read tools do not consume the daily budget. Full table in Section 09.
What is the Kimi test?
An internal benchmark where an off-the-shelf AI harness (Kimi K3) with no training knowledge of Design Exchange was given one mission: find services and pricing. The harness failed via web search, then succeeded instantly once it switched to protocol discovery and probed /.well-known/mcp.json, /mcp, /sse, /llms.txt. The test is the lesson: wild agents do not know you exist until your machine-readable surface is indexed.
What is the difference between the public MCP endpoint and the production-side MCP server?
Design Exchange runs two MCP surfaces with opposite epistemics. The public surface (the Concierge endpoint) is conversational, grounded, and scoped — answers are synthesized in the firm's voice and carry inference cost. The production surface (revit-tools MCP server, Python) is deterministic — it reads a Revit model and returns measured numbers for window-to-wall ratio, energy envelope, lot coverage, setbacks, floor area, septic clearance. Same protocol. Opposite epistemics. Numbers cannot be persuaded; conversations can.
Is the MCP server secure?
The endpoint was hardened over eight months of scar tissue (grounding discipline, rate limiting, edge firewall, sanitized corpus, verification stack) before it was pointed outward. The full adversarial pass — what an attacker can do, what was found, what was fixed — is documented in Part 2: The Front Door Is an API. The public endpoint itself is open (no auth) by design, because the cost of inference per grounded answer is bounded and the surface is hardened, not walled.

16 / The bottom line

The click was always a proxy — proof that someone, somewhere, engaged. Proxies die when the thing they measure moves. Engagement moved into agents, and AEC is still printing portfolios for visitors who are no longer coming.

We spent eight months building an agent that could survive humans, and one evening making it legible to machines. The terminal was the first door we built for machines. The connector is the second. For a small practice the return is not novelty — it is that “can I build on this lot, and what would you charge to find out” now gets answered at 2 a.m., in our voice, inside our scope, without anyone picking up a phone.

In January we wrote: “A friendly Concierge built for January 2026 will be eaten alive in 2027.” We would rather feed it a protocol. Browsing is a legacy paradigm. So is the click.

Installed, not ranked; called, not clicked.


What is still open

We publish this list so the next round of critique has a head start:


MCP client config (for humans and machines)

[ • MCP SERVER ONLINE :: /api/mcp ]
Claude Desktop / Cursor config:
{
  "mcpServers": {
    "axoworks": {
      "url": "https://designxc.com/api/mcp"
    }
  }
}

Agents: read https://designxc.com/llms.txt first — it is one screen, and it tells you which tool to call.

Humans: bring us a site and a question. The terminal is still right there.

Part 2 → The Front Door Is an API — What Happened When We Attacked Our Own MCP Storefront
Part 3 → The Chef Can Discuss the Dish — What Agent2Agent Uncovered in Our Own Stack
Part 4 → AEC Proof of Work — The Portfolio Is the Price of Entry. The Tech Receipt Validates the Parking Ticket


Build Sheet

Field Value
Practice Small AEC design consultancy. Building Designers, not Architects; sealed work routed to licensed partners.
Lineage Concierge terminal launched 2026-01-01 · Hacker News front page, 2,000+ engineers in six hours for $0.74 · technical audit 8.625/10 (February 2026) · MCP connector (September 2026) · adversarial hardening audit (September 2026, see Part 2).
MCP surfaces Two. Production side — Python MCP server for Autodesk Revit 2027 with deterministic geometry and compliance audits. Public side — the Concierge connector. Opposite epistemics, same protocol.
Tool surface Pre-MCP, two internal tools × one client. Post-MCP, three business tools × any MCP client.
Endpoint type AI→AI — a serving-side intelligence answering visiting agents.
Endpoint https://designxc.com/api/mcp · streamable HTTP · JSON-RPC 2.0 · protocolVersion 2026-09-02 · status active · no authentication.
Runtime Netlify Edge Function (Deno), additive. The Brain–Hands–Voice loop is unchanged; MCP clients assume the Hands role.
Tools ask_concierge · search_knowledge_base · book_consultation.
Grounding Supabase pgvector over a curated project corpus, with verification gating (origin: the Hacker News crucible, December 2025 – March 2026).
Guarding Edge firewall exemption scoped to the MCP routes; /api/chat still returns 403 to agent user-agents.
Abuse control 30 requests per minute per IP (Netlify Blobs) with RateLimit-* and Retry-After; plus a per-address daily inference budget of 50 (X-MCP-Daily-*), scoped to ask_concierge only.
Discovery llms.txt (top directive plus invocation examples), robots.txt directives, meta tags, JSON-LD action markup, /.well-known/mcp.json and ai-plugin.json, /mcp and /sse aliases, and the logs.designxc.com evidence corpus (52 records / 53 sitemapped URLs at launch; trimmed to 32).
New infrastructure None. Build time: one evening.
Deploy discipline test branch → soak on the staging host → main → designxc.com.
Receipts (self-reported) 17,401 pageviews / 5,084 unique visitors / 631 MB in the first 30 days; $0.74 for the six-hour Hacker News torture test.
Verified live 2026-09-11 — GET https://designxc.com/api/mcp returned {"name":"axoworks-concierge","protocol":"mcp","protocolVersion":"2026-09-02","transport":"streamable-http","status":"active","tools":["ask_concierge","search_knowledge_base","book_consultation"]}.

The rest of this line of work

Design Exchange has been running one thesis for a year: put deterministic rails on stochastic systems. The connector is the front door of that project; the rest of it lives here.


Sources

Third-party research:

First-party (Design Exchange-published; figures self-reported): From Portfolio to Agent · The $0.74 Website · The Design Exchange Logs · revit-tools · Why General-Purpose AI Fails at AEC Pre-Construction · The Referee in the Pit · The $1 Property Report · LLMs for Real Estate Feasibility · the public redacted system audit (January 2026) · Part 2, The Front Door Is an API.

Live verification this revision: GET https://designxc.com/api/mcp and https://designxc.com/llms.txt, both fetched 2026-09-11.


Cross-checked against published first-party surfaces

This article is cross-checked against:

If this article disagrees with any of those surfaces, those surfaces are canonical.


Attribution

By Design Exchange LLC. Drafted with AI assistance and edited by humans who sign the work. The build it documents was executed by humans using AI tooling. Thea Martyn, Ryan Robinson, Nathan Price, Jack Buckland, and others named in the build logs contributed to the MCP connector and the scar-tissue that preceded it.

Design Exchange uses AI to augment licensed architectural and engineering expertise, not to replace it. All AI-generated output is reviewed and verified by licensed professionals to ensure compliance with legal and safety standards. The endpoint described is in production; all technical specifications and workflow parameters are documented as implemented.

Talk to the Concierge

→ designxc.com