Guide · agentic commerce
Agent payment protocols explained
Four efforts shape how AI agents check out and pay: the Agentic Commerce Protocol (ACP), the Agent Payments Protocol (AP2), Visa Intelligent Commerce with its Trusted Agent Protocol, and Mastercard Agent Pay. They answer different questions — how an agent talks to a merchant’s checkout, how a person’s authority is proven, and how a card network recognises an agent. Each summary below is drawn from the publisher’s own pages, linked at the end.
Agentic Commerce Protocol (ACP)
ACP describes itself as an open standard for programmatic commerce flows between buyers, AI agents and businesses. It was developed by Stripe and OpenAI and is published under the Apache 2.0 licence. It lets an agent start a checkout on a merchant’s platform while the merchant keeps control of product presentation and fulfilment, and it handles payment credentials in a way intended to keep card data out of the agent.
- Question it answers: how does an agent place an order with a merchant?
- Where it lives: the ACP site, its GitHub specification and Stripe’s agentic commerce documentation.
Agent Payments Protocol (AP2)
AP2 was released by Google as an open protocol for agent payments and is described as an extension for the Agent2Agent (A2A) protocol. Its core idea is the mandate: signed credentials recording what a person allowed. The current documentation describes checkout mandates, shared with the merchant, and payment mandates, shared with credential providers, networks and processors — each first “open” (the person’s constraints, such as a budget) and then “closed” (a specific, finalised checkout or amount). Standardisation work continues through FIDO Alliance working groups.
- Question it answers: how does everyone in the chain prove the person authorised this purchase?
- Where it lives: ap2-protocol.org, the AP2 GitHub repository and Google Cloud’s announcement.
Visa Intelligent Commerce and the Trusted Agent Protocol
Visa Intelligent Commerce is Visa’s programme for agent-initiated payments. Within it, the Trusted Agent Protocol gives merchants a cryptographic way to recognise approved AI agents and tell them apart from bots and crawlers during a transaction. Visa publishes its specification and getting-started material on the Visa Developer Center.
- Question it answers: is the agent at my checkout a legitimate one?
Mastercard Agent Pay
Mastercard Agent Pay is built on agentic tokens: tokenised credentials issued for an agent, carrying the permissions and limits the cardholder set, so each transaction is tied to a specific authorised agent interaction. Mastercard documents it for developers as a use case of its checkout solutions.
- Question it answers: how does a card network know which agent paid, and under what limits?
What none of them does for you
These protocols carry and authenticate the transaction. They do not decide what your own agents are allowed to buy, from whom, or above what amount a person must step in — and they do not keep your record of why each purchase was allowed. That policy and evidence layer stays with the business running the agent. Agent Trust Cloud is independent of these protocols and is not a member, partner or certified implementation of any of them.
Sources
- Agentic Commerce Protocol (agenticcommerce.dev)
- Agentic Commerce Protocol specification on GitHub
- Stripe documentation: agentic commerce
- Agent Payments Protocol (ap2-protocol.org)
- AP2 specification on GitHub
- Google Cloud: announcing the Agent Payments Protocol
- Visa Developer: Visa Intelligent Commerce
- Visa Developer: Trusted Agent Protocol
- Mastercard: Agent Pay
- Mastercard Developers: Agent Pay