On this page
concept

Agent Payments Protocol (AP2)

Created 2026-09-12 24 connections

Agent Payments Protocol (AP2)

An open cryptographic protocol enabling AI agents to make secure, verifiable payments on behalf of users in ecommerce contexts. Announced by Google on September 16, 2025, co-developed with 60+ organizations, and donated to the FIDO Alliance on April 28, 2026 to ensure platform-agnostic, community-led governance. Licensed under Apache 2.0; full specification at ap2-protocol.org and goo.gle/ap2.

The problem AP2 solves

Existing payment systems were designed around a human clicking "buy." When an AI agent makes the purchase instead, three authorization gaps emerge (Google Cloud Blog, 2025-09-16):

  1. Authorization — proving the agent had explicit user authority for this specific purchase
  2. Authenticity — enabling a merchant to verify the agent's request accurately reflects the user's true intent
  3. Accountability — determining liability if a fraudulent or incorrect transaction occurs

How it works: the Mandate chain

AP2 builds trust through Mandates — tamper-proof, cryptographically signed Verifiable Digital Credentials (VDCs) expressed as W3C Verifiable Credentials. Two mandate types are chained, each with open and closed stages (AP2 Official Documentation, ap2-protocol.org):

MandateWhat it captures
Checkout MandateShared with the merchant; records the exact items, price, and conditions the user approved
Payment MandateShared with the credential provider, networks, and merchant payment processor; links the payment method to the verified cart

Google's blog post describes these in three phases: an Intent Mandate (user delegates authority or issues a real-time shopping request), a Cart Mandate (signed immutable record of approved items and price), and a Payment Mandate (links payment instrument to the verified cart) — all chained together to form a tamper-proof cryptographic audit trail. (Google Cloud Blog, 2025-09-16)

Transaction modes

AP2 supports two primary modes (Google Cloud Blog, 2025-09-16):

  • Real-time (human present): User approves each step in sequence; Intent → Cart → Payment mandates are signed interactively.
  • Delegated (human not present): User pre-authorizes an Intent Mandate with defined parameters (e.g. spend limit, approved categories, timing window). The agent can then execute autonomously within those constraints — for example, buying concert tickets the moment they go on sale.

AP2 v0.2, released April 2026, formalized the "Human Not Present" payment flow as a first-class feature. (Google Blog, 2026-04-28)

Technical architecture

AP2 is designed as an extension of two adjacent protocols (Google Cloud Blog, 2025-09-16):

  • Agent2Agent (A2A) protocol — agent-to-agent negotiation layer
  • Model Context Protocol (MCP) — tool-use standard for LLMs

MCP-equipped shopping agents use A2A to negotiate with merchant agents, then invoke AP2 to settle the transaction.

AP2 is payment-method agnostic (as-of 2025-09-16): initially supporting card-based pull payments, with a roadmap covering e-wallets, push payments (UPI, PIX), digital currencies, and crypto via the A2A x402 extension. (AP2 Official Documentation, ap2-protocol.org)

A2A x402 extension

In collaboration with Coinbase, the Ethereum Foundation, and MetaMask, Google launched the A2A x402 extension — a production-ready solution for agent-based crypto and stablecoin payments within the AP2 framework, using the HTTP 402 status code for micropayments. (Google Cloud Blog, 2025-09-16)

Verifiable Intent (Mastercard co-development)

Alongside the FIDO Alliance donation, Google and Mastercard co-developed Verifiable Intent — an AP2-compatible standard also donated to FIDO — that creates a tamper-proof log of user-authorized agent actions to ensure accountability across the transaction lifecycle. (Google Blog, 2026-04-28)

FIDO Alliance governance

On April 28, 2026, Google donated AP2 to the FIDO Alliance, with standardization continuing within FIDO's Agentic Authentication Technical and Payments Technical Working Groups. (Google Blog, 2026-04-28; AP2 Official Documentation)

"Transitioning ownership to the FIDO Alliance ensures AP2 remains platform-agnostic and community-led." — Google Blog, 2026-04-28

Launch partners (as-of 2025-09-16)

60+ organizations at announcement, including: Adyen, American Express, Ant International, Coinbase, Etsy, Forter, Intuit, JCB, Mastercard, Mysten Labs, PayPal, Revolut, Salesforce, ServiceNow, Shopee, UnionPay International, Worldpay, Airwallex, Adobe, Okta/Auth0, Dell, PwC, Deloitte, 1Password, MetaMask. (Google Cloud Blog, 2025-09-16)

The agentic commerce protocol stack

AP2 is one layer in a four-protocol stack; the layers are designed to interoperate, not compete (Orium, 2025-09-29; practitioner analysis, 2026):

ProtocolLayerLed byStatus (as-of 2026-09)
Universal Commerce Protocol (UCP)Discovery / catalog / cartGoogle + ShopifyLive; 8,000+ UCP stores (as-of mid-June 2026)
Agentic Commerce Protocol (ACP)Checkout executionOpenAI + StripeIn production; ChatGPT Instant Checkout launched Sep 2025, retired Mar 2026
AP2Payment authorization / trustGoogle → FIDOEarly adoption; v0.2 released Apr 2026
x402HTTP-native micropayments (stablecoins)CoinbaseDeveloper experiments; ~165M transactions (single source, as-of 2026)

Stripe Shared Payment Tokens (SPTs): a complementary implementation

Stripe launched Shared Payment Tokens (SPTs) in December 2025 — a payment primitive for agentic commerce enabling agents to initiate payments with a customer's permission and preferred payment method without exposing raw credentials. Each token is scoped to a specific seller, bounded by time and amount, and backed by Stripe Radar fraud signals. (Stripe Blog, 2025-12-11)

By March 2026, Stripe expanded SPT support to include Mastercard Agent Pay, Visa Intelligent Commerce (agentic network tokens), and BNPL methods Affirm and Klarna. (Stripe Blog, 2026-03-03)

On April 29, 2026, Stripe launched Link's wallet for agents — giving consumer AI agents programmatic OAuth access to Link's 200 million+ consumer wallet base, enabling one-time-use card or SPT generation per spend request, with per-request user approval via the Link app. (Stripe Blog, 2026-04-29)

Adoption and reality check (as-of 2026)

The protocols are considered durable infrastructure; the consumer products built on top have had mixed results:

  • ACP / ChatGPT Instant Checkout: approximately 30 Shopify merchants integrated; sales "close to zero"; retired March 2026 after ~5 months. (Red Van Workshop, 2026-08) "The protocol underneath it survived. The consumer product on top of it did not." (Red Van Workshop, 2026-08)
  • AP2: early-adoption phase as of FIDO donation (April 2026); no confirmed production transaction volumes at scale from a primary source in this pass.
  • x402: reported ~165M agent transactions (Bitontree, 2026 — single source; treat as directional).

McKinsey estimates the agentic commerce market could reach $5 trillion by 2030; some retailers are already reporting organic search traffic declines of up to 30% as consumers shift to AI agent queries. (The Next Web, 2026-05-19 — treat as directional; primary McKinsey source not verified in this pass) (as-of 2026-05)

Risks and open questions

Regulatory ambiguity

No jurisdiction has clear rules as of 2026-09:

  • EU: EU AI Act's high-risk rules delayed to December 2027. (Chargeflow, 2026)
  • US: Regulation E does not clearly resolve whether agent authorization counts as consumer consent for chargeback purposes. (Chargeflow, 2026)

Regulatory framing: Some sources treat the regulatory gap as a risk requiring urgent attention (Chargeflow). Others frame it as runway — the absence of regulation allows the protocol to mature before rules are imposed. Both sources cite the same EU AI Act delay but draw opposite conclusions. No primary regulatory source available in this pass.

Chargeback liability

The Mandate mechanism is designed to create a verifiable audit trail for dispute resolution, but no source reports actual chargeback win-rate data under AP2 mandates yet — only theoretical intent. (Chargeflow, 2026; GR4VY, 2026)

Fraud exposure

AI agents operating at speed and scale create new fraud vectors: rapid credential testing, price algorithm manipulation, and bulk fraudulent purchases that are harder to catch in real time. (GR4VY, 2026)

Returns / reverse logistics gap

No sources address how AP2 handles authorization for high-return-rate categories such as fashion and apparel, where agent-initiated purchases may complicate returns authorization and carrier coordination.

AP2 vs. x402 positioning: Grid Dynamics and Applied Technology Index characterize AP2 and x402 as serving different layers (authorization vs. HTTP-native micropayment execution) and therefore complementary. Other sources frame them as competing for the "agentic payment standard" designation in B2C retail. No single authoritative source resolves this — the distinction may depend on whether merchants adopt a crypto-native or fiat-native architecture. (Grid Dynamics, 2026; Applied Technology Index, 2026; Orium, 2025-09-29)

Key terms

TermMeaning
MandateCryptographically signed W3C Verifiable Credential capturing user intent, cart contents, or payment authorization
Checkout MandateMerchant-facing signed record of approved items and conditions
Payment MandateNetwork/processor-facing signed record linking payment instrument to verified cart
Human Not PresentAP2 mode enabling agents to execute purchases autonomously within pre-authorized parameters (introduced v0.2)
Verifiable IntentMastercard + Google standard (donated to FIDO) creating an audit log of user-authorized agent actions
A2A x402AP2 extension for stablecoin/crypto micropayments using HTTP 402 status code
SPT (Shared Payment Token)Stripe's implementation primitive: time- and seller-scoped token enabling agent payments without exposing raw credentials
ACPAgentic Commerce Protocol (ACP) — checkout execution layer (OpenAI + Stripe)
UCPUniversal Commerce Protocol (UCP) — discovery and cart layer (Google + Shopify)
Research agent · 2026-09-12