Agentspay

Explainer

AI Agent Payment Platforms: Agentic Payments Platforms and Agent Wallets Compared

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Agent Payments Console

Pick an agent

Payment intent

intent:

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

Agentspay

single-use

Wallet budget

spent of

Audit trail

In short

An AI agent payment platform gives a software agent a way to pay under rules a human set. The market splits into five categories: card issuers that mint scoped virtual cards (Stripe Issuing, Lithic, Ramp Agent Cards), agent wallets that hold funds and hand the agent a scoped key (Stripe Link for agents, Coinbase Agentic Wallets, Crossmint), checkout protocols that standardize the buy step (ACP, AP2, Visa Intelligent Commerce, Mastercard Agent Pay), crypto rails that meter machine-to-machine spend (x402, Skyfire, Nevermined), and control planes that sit above all of them and enforce budget, approval, and audit. Most teams need one rail plus a control plane, not two rails.

What an AI agent payment platform actually does

Strip away the branding and every agentic payments platform answers four questions. Who is this agent and who authorized it? Where does the money come from? What is this specific agent allowed to buy, from whom, and up to what amount? And what record survives afterward, so finance can tie a charge to the agent, the prompt, and the human who owns it. A platform that answers all four is rare. Most products answer one or two well and quietly leave the rest to your engineering team. That is the single most useful lens when you compare vendors: not the feature list, but which of those four questions the product actually takes responsibility for.

The five categories of AI agent payment platform

Card issuers mint a real card number your agent can use at any merchant that takes cards. Stripe Issuing exposes single-use card creation through its Issuing API, with controls for allowed merchants, MCC blocklists, daily and monthly caps, and country restrictions. Lithic (which started life as Privacy.com) is the other large issuing platform shipping agent-targeted features, and Ramp announced Agent Cards in April 2026, generating virtual cards tied to SaaS vendors where finance sets the monthly limit and the merchant whitelist. Agent wallets hold funds or keys and hand the agent a scoped subkey rather than the underlying credential. Stripe said at Sessions 2026 that Link, with over 250 million users, now lets agents pay on behalf of users with a one-time-use card issued per task; Coinbase Agentic Wallets and Crossmint play the same role on the onchain side. Checkout protocols standardize the handshake between an agent and a merchant rather than holding money at all: the Agentic Commerce Protocol, Google AP2, Visa Intelligent Commerce, and Mastercard Agent Pay all live here. Crypto and metering rails such as x402, Skyfire, and Nevermined charge per request in stablecoins, which suits machine-to-machine API buying. Control planes, the category Agentspay sits in, do not compete with any of those. They sit above the rail and enforce the budget, the approval, and the audit trail.

Which AI agent payment platform enforces a real spend limit

This is where buyer research usually goes wrong, because almost every vendor uses the word "limit" and they do not mean the same thing. A card-level cap is enforced by the issuer at authorization: exceed it and the transaction declines. That is a hard limit and it is genuinely useful. A wallet balance is a soft limit; the agent can burn the whole balance in one call and nothing declines until it is empty. A protocol mandate is an authorization artifact, not a budget: it proves a human approved this purchase shape, but nothing tracks the fifteenth purchase of the day against a weekly cap. And a metering rail counts usage after the fact. If your risk is a runaway loop rather than a stolen card, you want a per-agent budget evaluated before every authorization, plus a human approval step above a threshold. Only a handful of products do that, which is why the honest answer to "which platform stops overspend" is usually "the rail plus something above it".

Fiat cards or stablecoins, and why most US teams pick cards

Stablecoin rails settle in seconds, cost cents, and are ideal for an agent paying a fraction of a cent per API call. They are also a poor fit for the majority of what US business agents actually buy: SaaS renewals, ad spend, cloud, travel, supplier invoices. Those merchants take cards, not USDC, and your controller wants the charge to land in the same expense workflow as everything else. The practical split we see is that agents buying from other machines use x402 or a metering rail, and agents buying from real merchants use scoped virtual cards. Choosing a platform locked to one of those rails is fine until the second use case shows up, which is the argument for keeping the governance layer separate from the rail. Read the deeper comparison in AP2 vs ACP vs x402.

Agent identity: the piece most platforms leave out

A payment platform that cannot prove which agent is transacting cannot give you an audit trail worth the name. Skyfire built the most developed answer here: its KYA protocol issues signed JSON Web Tokens carrying verified claims about agent authenticity, human authorization, and payment capability, over ordinary OAuth2 and HTTP. In April 2026 Skyfire announced that KYA became the identity layer for Experian's Know Your Agent framework, with Experian contributing a human-to-agent binding service and an agent registry that scores agents over time, and Cloudflare enforcing verification at the network edge. If you are evaluating platforms for anything regulated, ask what identity travels with the transaction and what your auditor will see. Our explainer on Know Your Agent covers what the standard actually requires.

How to run the evaluation in a week

Start from the agent, not the vendor. Write down the three things your agent buys most, the merchants involved, and the largest single purchase you would let it make unattended. That immediately tells you the rail. Then ask each shortlisted vendor to demo the failure case rather than the happy path: have the agent try to exceed its budget, and watch whether the transaction declines, warns, or silently succeeds. Ask to see the record afterward and check whether it names the agent and the human owner or just the card. Finally, price it against real volume, because per-transaction pricing and per-agent pricing diverge sharply once you run hundreds of agents. Teams that run that failure-case demo usually end up with a rail plus a control plane, because no single vendor passed all four tests.

Where Agentspay fits

Agentspay is a control plane, not a rail. Agents get an agent wallet, hard spend limits evaluated before every authorization, human approval on anything above the threshold you set, scoped virtual cards that are merchant-locked and single-use, and an immutable audit trail that ties each dollar to the agent, the intent, and the human who owns it. It works on top of the card and stablecoin rails you already use, so you are not betting the architecture on one protocol winning. If you are comparing us head to head with a specific vendor, we keep honest side-by-side pages for Stripe, Lithic, Skyfire, Crossmint, Payman, and Ramp Agent Cards, including the cases where they are the better pick. If the terminology is still blurry, the split between the rail that moves the money and the control plane that authorizes it is worked through in what an AI agent payment gateway is.

Whatever standard moves the money, Agentspay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Side by side

AI agent payment platforms compared

What each category actually gives you, and what it leaves to your team. Capabilities as documented by each vendor in July 2026; verify pricing directly, it moves fast.

Category Agentspay Card issuers Agent wallets Checkout protocols Crypto and metering rails
Examples Agentspay Stripe Issuing, Lithic, Ramp Agent Cards Stripe Link for agents, Coinbase Agentic Wallets, Crossmint ACP, Google AP2, Visa Intelligent Commerce, Mastercard Agent Pay x402, Skyfire, Nevermined
Holds the money No, sits above your rail No, the issuing bank does Yes, custodial balance or keys No, it is a message standard Yes, onchain balance
Hard spend limit before authorization Yes, per agent and per policy Yes, per card caps and merchant locks Balance only, no per-purchase cap No, a mandate is not a budget Metered after the call
Human approval step Yes, threshold based with escalation Not built in Not built in Only at mandate signing Not built in
Agent identity in the record Yes, agent, intent, and human owner Card level only Wallet or key level Varies by protocol Wallet address, KYA where supported
Works at ordinary US merchants Yes, via scoped cards Yes Yes for card-backed wallets Only where the merchant adopted it Rarely, machine-to-machine mostly
Best for Teams that must prove control over agent spend Teams that need card acceptance everywhere Consumer-facing shopping agents Merchants standardizing agent checkout Agents buying APIs and compute per call

Frequently asked

Questions people ask about AI Agent Payment Platforms

What is the best AI agent payment platform?

There is no single best one, because the category is five different products. If your agent buys from ordinary merchants, a card issuer plus a control plane is the strongest combination. If it buys API calls from other machines, a metering rail like x402 fits better. Pick the rail from what the agent buys, then add governance above it. Our buyers guide to agent payment platforms walks each option in detail.

How much do AI agent payment platforms cost?

Pricing splits three ways in 2026: interchange-based (issuers earn on card spend, so the platform fee is low), per-transaction percentage plus a flat fee, and per-agent or per-seat subscription. Crypto rails charge network fees measured in cents. Model your real volume against all three, because a per-transaction model that looks cheap at ten agents gets expensive at three hundred. Always confirm current rates with the vendor.

Can I just use Stripe Issuing for my AI agents?

Often yes, and for many teams it is the right starting point. Stripe Issuing gives you single-use cards with merchant, MCC, country, and daily or monthly caps through the API. What it does not give you is a per-agent budget across cards, a human approval workflow above a threshold, or a record that names the agent and its human owner. Teams usually add that layer once agents outnumber people.

Do AI agents need their own wallet?

An agent needs a funding source it can use without holding your credentials, which a wallet is one way to provide. A scoped virtual card is another, and it works at more merchants. The real requirement is isolation: whatever the agent holds should be worthless outside the purchase it was authorized to make. See do AI agents need a wallet for the tradeoffs.

What is the difference between an agentic payments platform and a payment gateway?

A payment gateway moves a human-initiated transaction from a checkout page to an acquirer. An agentic payments platform assumes there is no human at the checkout, so it has to carry proof of who authorized the purchase, enforce limits the human set in advance, and record the agent behind the charge. Gateways answer how the money moves; agent platforms answer whether it should have moved at all.

Are AI agent payments safe?

They are as safe as the controls around them, which is why the platform choice matters. The two live risks are a runaway loop that repeats a purchase and a prompt injection that convinces an agent to buy something an attacker chose. Neither is fixed by encryption. Both are contained by a hard per-agent budget, merchant-locked single-use cards, and human approval above a threshold, which is exactly what a control plane adds.

Keep reading

More explainers

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy