Agentic Payments — Master Source Brief (for sub-agent writers)
Last updated: 2026-04-21. Use this as a starting point. Verify everything you cite. Do NOT invent sources or URLs. If unsure, say "as reported by [X]" and link an archived/secondary source. When you cannot verify, omit rather than invent.
A. Verified Industry Protocols & Programs
1. Google — Agent Payments Protocol (AP2)
- Announced: September 16, 2025.
- Spec & code: https://github.com/google-agentic-commerce/AP2
- Spec doc: https://github.com/google-agentic-commerce/AP2/blob/main/docs/specification.md
- Google Cloud announcement: https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol
- Community: https://discuss.google.dev/t/new-agent-payments-protocol-ap2-an-open-and-secure-standard-for-agentic-payments/265614
- Site: https://agentpaymentsprotocol.info/docs/introduction/
- Cloud Security Alliance commentary: https://cloudsecurityalliance.org/blog/2025/10/06/secure-use-of-the-agent-payments-protocol-ap2-a-framework-for-trustworthy-ai-driven-transactions
- DeepWiki spec walkthrough: https://deepwiki.com/google-agentic-commerce/AP2
- Core concepts: Intent Mandate, Cart Mandate, Payment Mandate (W3C Verifiable Credentials). Built atop A2A and MCP.
2. OpenAI + Stripe — Agentic Commerce Protocol (ACP)
- Announced: September 29, 2025 ("Instant Checkout in ChatGPT").
- Spec repo: https://github.com/agentic-commerce-protocol/agentic-commerce-protocol
- Site: https://agenticcommerce.dev/
- OpenAI docs: https://platform.openai.com/docs/agentic-commerce
- Stripe docs: https://docs.stripe.com/agentic-commerce/protocol
- Initial merchants: Etsy, then Shopify sellers, then Walmart (Oct 14, 2025).
- Mechanism: SharedPaymentToken via Stripe; merchant remains Merchant-of-Record.
3. Visa — Trusted Agent Protocol & Visa Intelligent Commerce
- Visa Intelligent Commerce announced: April 30, 2025.
- Trusted Agent Protocol announced: October 14, 2025.
- IR release: https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx
- BusinessWire: https://www.businesswire.com/news/home/20251014974512/en/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce
- GitHub: https://github.com/visa/trusted-agent-protocol
- Built jointly with Cloudflare; partners: Adyen, Checkout.com, Coinbase, Fiserv, Microsoft, Shopify, Stripe, Worldpay, Nekuda. Uses HTTP Message Signatures + Web Bot Auth.
4. Mastercard — Agent Pay
- Announced: April 30, 2025.
- Press: https://paymentexpert.com/2025/04/30/mastercard-microsoft-ai-agent-pay/
- PayPal expansion: https://newsroom.paypal-corp.com/2025-10-27-Mastercard-and-PayPal-Join-Forces-To-Accelerate-Secure-Global-Agentic-Commerce
- Tools: Agentic Tokens (extension of Mastercard Tokenization Service), Agent Pay APIs, Agent Pay Acceptance Framework.
- Issuer pilots: Citi, U.S. Bank.
- Partners: Microsoft (Azure OpenAI + Copilot Studio), IBM (watsonx Orchestrate), Stripe, Braintree, Checkout.com, Ant International (Antom), Crossmint, Lobstercash.
5. American Express — Agentic Commerce program
- Press / blog: https://americanexpress.io/shaping-the-future-of-agentic-commerce/
- Cloudflare collaboration (Oct 21, 2025): https://www.cloudflare.com/press/press-releases/2025/cloudflare-collaborates-with-leading-payments-companies-to-secure-and-enable-agentic-commerce/
- Adopts Web Bot Auth + Trusted Agent Protocol.
6. PayPal — Agent Toolkit + MCP server
- Announced: April 29, 2025 at PayPal Dev Days.
- Press: https://newsroom.paypal-corp.com/2025-04-29-PayPal-Brings-Together-Developers,-AI-Leaders-to-Power-Agentic-Commerce-at-Dev-Days
- Docs: https://paypal.gitbook.com/agent-toolkit-and-mcp-server/agent-toolkit/quickstart
- InfoQ writeup: https://www.infoq.com/news/2025/04/paypal-mcp-ai-toolkit/
- Capabilities: orders, invoices, disputes, catalog, shipment tracking, subscriptions, reporting via MCP server; supported in OpenAI Agent SDK, Vercel AI SDK, LangChain.
7. Coinbase — x402 protocol
- Announced: May 6, 2025.
- Spec/docs: https://docs.x402.org/ ; core concept: https://docs.x402.org/core-concepts/facilitator
- GitHub: https://github.com/coinbase/x402
- DeepWiki: https://deepwiki.com/coinbase/x402
- Cloudflare partnership: https://blog.cloudflare.com/x402/ (x402 Foundation)
- Resurrects HTTP 402; stablecoin (USDC) micropayments via EIP-3009/Permit2; "facilitator" service settles on-chain (Base, Ethereum, Polygon, Arbitrum, Solana). Coinbase CDP facilitator: free on Base for first 1k tx/mo.
8. Skyfire
- Founded 2023 by Amir Sarhangi & Craig DeWitt.
- Seed: $9.5M total (round in Oct 2024 led by Coinbase Ventures + a16z CSX, Neuberger Berman).
- TechCrunch (Aug 21 2024): https://techcrunch.com/2024/08/21/skyfire-lets-ai-agents-spend-your-money/
- Built on Coinbase Base. Issues stablecoin-backed agent identities (KYA = Know-Your-Agent).
9. Nekuda
- $5M seed May 2025, led by Madrona Ventures, with Amex Ventures, Visa Ventures.
- Crowdfund Insider: https://www.crowdfundinsider.com/2025/05/239660-fintech-startup-nekuda-secures-funding-led-by-madrona-ventures-to-enable-agentic-payments/
- Components: Agent Wallets, Agentic Mandates, Visa Intelligent Commerce integration.
10. Catena Labs (Sean Neville, ex-Circle)
- $18M seed May 20, 2025, led by a16z crypto.
- BusinessWire: https://www.businesswire.com/news/home/20250520361792/en/Circle-Co-Founder-Sean-Neville-Takes-Catena-Labs-Out-of-Stealth-with-Plans-to-Build-the-First-AI-Native-Financial-Institution
- Open-source Agent Commerce Kit (ACK).
11. Crossmint
- "Agentic payments" product with stablecoin wallets, virtual cards, MoneyGram payouts.
- Page: https://www.crossmint.com/solutions/agentic-payments
- Circle Ventures investment: https://cryptobriefing.com/circle-ventures-investment-crossmint-stablecoin/
12. Cloudflare — pay-per-crawl + Web Bot Auth + AI Agent Identity
- x402 Foundation co-founder.
- Announcement (Oct 21, 2025): https://www.cloudflare.com/press/press-releases/2025/cloudflare-collaborates-with-leading-payments-companies-to-secure-and-enable-agentic-commerce/
- IETF draft "Web Bot Auth" by Cloudflare: HTTP Message Signatures + agent verification.
13. Walmart × OpenAI Instant Checkout (Oct 14, 2025)
- Walmart corporate: https://corporate.walmart.com/news/2025/10/14/walmart-partners-with-openai-to-create-ai-first-shopping-experiences
- CNBC: https://www.cnbc.com/2025/10/14/walmart-openai-chatgpt-shopping.html
- CBS News: https://www.cbsnews.com/news/walmart-chatgpt-online-shopping-ai-openai-agentic/
14. Universal Commerce Protocol (UCP) — Google + Shopify
- Announced at NRF Big Show Jan 2026.
- Google developers blog: https://developers.googleblog.com/under-the-hood-universal-commerce-protocol-ucp/
- Partners: Walmart, Etsy, Wayfair, Target, Visa, Stripe, Mastercard.
15. Stripe — Agent Toolkit + Issuing for agents
- Stripe Agent Toolkit (Anthropic, OpenAI, LangChain, Vercel SDK).
- Stripe Issuing virtual cards for AI agents.
- Stripe blog: https://stripe.com/newsroom/news/stripe-and-openai (and ACP collaboration).
B. Verified Academic / Standards Papers (as of 2026-04-21)
Citation rule: ONLY cite papers you can find at the exact URL given. If the URL fails, drop it.
- "A Survey of AI Agent Protocols" (Shanghai Jiao Tong U., Apr 2025) — arXiv:2504.16736. https://arxiv.org/abs/2504.16736
- "AI Agents Meet Blockchain: A Survey on Secure and Scalable Multi-Agent Systems" — MDPI Future Internet 17(2):57. https://www.mdpi.com/1999-5903/17/2/57
- "Securing AI Agents Against Prompt Injection Attacks" — arXiv:2511.15759 (Nov 2025). https://arxiv.org/abs/2511.15759
- "Secure Autonomous Agent Payments: Verifying Authenticity and Intent in a Trustless Environment" — arXiv:2511.15712. https://arxiv.org/abs/2511.15712 (verify before citing)
- "AI Agents with Decentralized Identifiers and Verifiable Credentials" — arXiv:2511.02841 (verify before citing).
- "Prompt Injection Attacks in Large Language Models and AI Agent Systems: A Comprehensive Review" — Information 17(1):54 (MDPI, 2026). https://www.mdpi.com/2078-2489/17/1/54
- Simon Willison, "Design Patterns for Securing LLM Agents against Prompt Injections" (Jun 13 2025). https://simonwillison.net/2025/Jun/13/prompt-injection-design-patterns/
- Google Security Blog (Jan 2025): "How we estimate the risk from prompt injection attacks on AI systems". https://security.googleblog.com/2025/01/how-we-estimate-risk-from-prompt.html
- ERC-8004 "Trustless Agents" EIP. https://eips.ethereum.org/EIPS/eip-8004 ; Ethereum Foundation blog https://ai.ethereum.foundation/blog/intro-erc-8004
- W3C Verifiable Credentials Data Model 2.0 (W3C Recommendation). https://www.w3.org/TR/vc-data-model-2.0/
- W3C Decentralized Identifiers (DIDs) v1.0. https://www.w3.org/TR/did-core/
- IETF RFC 9421 "HTTP Message Signatures" (Feb 2024). https://datatracker.ietf.org/doc/rfc9421/
- IETF draft "Web Bot Auth" (Cloudflare). https://datatracker.ietf.org/doc/draft-meunier-web-bot-auth-architecture/
C. Industry Reports & Analyses
- McKinsey, "The agentic commerce opportunity" (2025). https://www.mckinsey.com/capabilities/quantumblack/our-insights/europes-agentic-commerce-moment-decision-influence-is-here-execution-is-coming
- Kearney, "Agentic payments: a new frontier in digital commerce". https://www.kearney.com/industry/financial-services/article/agentic-payments-a-new-frontier-in-digital-commerce
- Linklaters TechInsights, "Agentic payments: legal risks". https://techinsights.linklaters.com/post/102l0hm/agentic-payments-what-are-they-what-are-the-legal-risks-and-whats-next
- Consumer Bankers Association white paper (2025). https://consumerbankers.com/press-release/cba-releases-white-paper-examining-agentic-ai-consumer-payments-and-the-future-of-regulation/
- Chainlink blog, "AI Agent Payments: The Future of Autonomous Commerce". https://chain.link/article/ai-agent-payments
- Orium, "Agentic Payments Explained: ACP, AP2, and x402". https://orium.com/blog/agentic-payments-acp-ap2-x402
- Payments Association, "AI powered payment agents". https://thepaymentsassociation.org/article/ai-powered-payment-agents-the-next-payments-revolution/
- Justt.ai, "Agentic Commerce: Preparing for Chargeback and Fraud Risks". https://justt.ai/blog/agentic-commerce-chargeback-risk-preparation/
D. Definitions to use consistently
- Agentic payment: a payment initiated, executed, and/or authorized by an autonomous software agent (typically LLM-driven) acting on behalf of a principal under delegated authority.
- Mandate (AP2 sense): a verifiable credential signed by a user (and possibly a merchant) that authorizes specific agent behavior.
- Human-Present (HP) vs Human-Not-Present (HNP) flows.
- Merchant of Record (MoR) retention.
- Facilitator (x402): non-custodial settlement intermediary.
- KYA (Know-Your-Agent): extension of KYC to agents — identity, principal, scope.
- MCP: Anthropic's Model Context Protocol (Nov 2024 release). https://modelcontextprotocol.io
- A2A: Google's Agent-to-Agent protocol (Apr 2025).
E. Hard rules for sub-agent writers
- Every claim of fact (date, partner, fund amount, technical detail) must cite a URL from this brief OR be verified via web_search/web_fetch and cited.
- Use Markdown footnote-style references
[^1]with full URL in a Sources section at end of your section. - Do not cite arXiv IDs that you have not personally fetched (use web_fetch on the abstract page).
- If a fact is disputed across sources, present both with citations.
- Cross-reference other sections by their filename, e.g.
(see [Card Networks](04-card-networks.md)). - Word target is a floor not a ceiling — but quality > quantity.
- Use UK or US English consistently within your section; be technically precise.
- Tables, code blocks, and protocol diagrams (mermaid) are encouraged.