AgentsPay

Explainer

American Express Agentic Commerce and Amex Agentic Commerce Spend Controls

American Express launched its Agentic Commerce Experiences (ACE) developer kit and Amex Agent Purchase Protection on 14 April 2026. It is the first card network to write "how much can be spent" into the agent's purchase intent and to promise a credit when a registered agent buys the wrong thing. We checked every public Amex host for the specification, an MCP server and discovery files on 7 October 2026. Here is what is actually live, and what a business still has to add before it lets agents spend.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

American Express agentic commerce runs through the ACE developer kit: agent registration, account enablement, intent intelligence, scoped payment credentials and optional cart context. Each purchase intent records what to buy, where, how much can be spent and when extra approval is needed, and the credential is short-lived and bound to that intent. Agent Purchase Protection credits Card Members when a registered agent errs. On 7 October 2026 the ACE specification was invite-only and not public, and no Amex MCP host resolved. ACE bounds one intent on one Amex card. A monthly budget per agent across every card and rail still has to sit outside the network.

What American Express shipped for agentic commerce in 2026

On 14 April 2026 American Express announced two things at once. The first is the Agentic Commerce Experiences (ACE) developer kit, a set of technical specifications for bringing Amex cards into purchases an AI agent makes for a Card Member. The second is Amex Agent Purchase Protection, which Amex calls an industry first: a commitment to back Card Member purchases made by AI agents that developers have registered with American Express.

ACE has five services. Agent registration gives each developer's agent an identity Amex recognizes. Account enablement lets a Card Member link their card to that agent, through the Amex app. Intent intelligence captures what the Card Member actually asked for. Payment credentials hands a verified agent a tokenized credential to pay with. Cart context lets the merchant share the assembled cart, which Amex says helps with disputes, and it is optional.

Amex lined up a long partner list for the launch, including Adyen, Cloudflare, Crossmint, Delta, Expedia, Fiserv, Forter, Global Payments, Google, Hilton, Microsoft, Nekuda, OpenAI, PayPal, Stripe and VGS. It also sits in Google's Agent Payments Protocol (AP2) and is a premier member of the x402 Foundation, so ACE is pitched as working alongside the open protocols rather than replacing them. Amex's own executives are candid about the stage of the market. Luke Gebb, an Amex executive vice president, told Fortune there have "probably been as many press releases as transactions" so far.

How the Amex purchase intent carries a spending amount

The detail that sets ACE apart is in the engineering write-up American Express published on 22 April 2026. An ACE intent is not a vague permission. Amex says it captures what should be purchased, where it could be purchased from, how much can be spent, and when additional approvals are required. The payment credential the agent receives is scoped, short-lived and tied to that intent, each step is validated with signed artifacts bound to the intent, and the credential has replay protection. Calls use OAuth and mutual TLS.

That is a real control, and it is more than most of the agent payment stack offers. In our earlier measurements, AWS AgentCore's whole spend policy is one optional per-session amount, and Microsoft Graph's agent types carry no money fields at all. Amex puts the amount in the authorization itself. Amex also says plainly that without a directive there is no authorization to purchase.

Notice the unit, though. The amount belongs to one intent. Amex's public materials describe nothing that totals intents across a month, compares one agent's spend against a department budget, or applies the same rule when the same agent pays with a Visa card, a Mastercard or a stablecoin wallet. A Card Member who certifies twenty intents of 400 dollars has certified 8,000 dollars, each one correctly bounded.

Is the Amex ACE developer kit public

Not yet. On 7 October 2026 we went looking for it the way an engineer would. The Amex developer portal at developer.americanexpress.com is a single-page app, and its public JavaScript bundle lists "Amex Agentic Commerce Experiences" under Payment Services, describing it as agentic commerce "powered by verified agents, real-time intent and risk signals, and robust authentication", with an overview route at /products/nextgen-agentic-payments/overview and a dedicated invite request address. The portal's product categories include an Invite-Only group.

The portal loads product pages from a public content store. The control worked. That store returned the overview for Amex's Open Banking Account and Transaction API (HTTP 200, 6,650 bytes of JSON). For the ACE product, both the overview file and the specification file returned 404, exactly what a made-up product name returned. So the ACE specification is not published where Amex publishes its other API documentation. You get it by invitation.

One trap for anyone repeating this: the developer portal answers HTTP 200 on any path, including a random one, because it is a single-page app. Requests for /mcp or /.well-known/oauth-protected-resource there look like hits and are not. That is why every probe we publish includes a nonsense control path.

Does Amex have an MCP server for agents

Not one you can reach today. The obvious names, mcp.americanexpress.com, mcp.amex.com, ace.americanexpress.com and agents.americanexpress.com, all returned NXDOMAIN on 7 October 2026, meaning they do not exist in DNS. The Amex API gateway, api.americanexpress.com, answered every MCP and OAuth discovery path with a small JSON 404, the same as our control path.

That matches what Amex wrote. Its engineering post lists SDKs, Agent Skills, an MCP server and reference implementations as tools the platform will provide. Compare Robinhood, which shipped a banking MCP server with its agentic credit card in May 2026, and Stripe, PayPal, Square and Checkout.com, which run hosted MCP servers we probed in September.

The public-facing files tell the same story. www.americanexpress.com/llms.txt exists, was last updated 18 September 2026, and contains three pieces of company trivia (the 1962 launch of a 500 dollar travelers cheque, the names of 1940s staff bowling teams, and a 1960s tuition refund program). It does not mention agents, ACE or any API. And Amex's robots.txt names exactly one crawler, AhrefsBot, and no AI crawler at all.

What Amex Agent Purchase Protection covers

The coverage rests on three conditions in the launch materials: the agent is registered with American Express, the Card Member has enrolled with that agent, and there is a certified intent for the purchase. When those hold and the agent makes a mistake, such as buying the wrong item or completing a duplicate transaction, Amex backs the Card Member. The example Amex used was an agent buying red shoes when the Card Member asked for green.

Two limits matter for a business buyer. First, the protection is for agent errors, not for errors by the Card Member or the merchant. A purchase that faithfully matches a certified intent is not an error, even if finance would never have approved it. The control is the intent you certify, so certifying broad intents is the risk. Second, the announcement materials we read publish no per-claim dollar cap, no business card terms and no claim procedure. Read the benefit terms on your own card before relying on it.

It is still a meaningful difference from the consumer competition. Robinhood's agentic credit card terms say you are solely responsible for transactions your agent makes under your instructions, which means agent purchases are treated as authorized, not as fraud.

What a finance team still has to add before agents spend on Amex

ACE answers the network's question: is this a known agent, acting for a real Card Member, inside what that person asked for. A controller has different questions, and they cut across cards.

  • How much has this agent spent this month? ACE bounds each intent. Nothing in the public material totals them per agent.
  • Does the same rule apply off Amex? Most companies run agents that also pay with a Visa or Mastercard virtual card, a Stripe balance or a USDC wallet for API calls. ACE governs the Amex leg only.
  • Who approves above a threshold? ACE can flag that an intent needs extra approval. Routing that to a named finance approver, with an expiry, is yours to build.
  • Which merchants are allowed at all? The intent says where something could be bought. A standing company allowlist across every agent is a policy, not an intent.
  • What goes in the audit file at close? You need agent, amount, merchant, rule and approver in one export, matched to the card statement.

None of this is a criticism of Amex. A card network is built to authorize one transaction at a time, and ACE does that better than anyone so far. A per-agent budget is a company policy, so it lives in the company's own control plane.

How AgentsPay works alongside American Express

Keep your Amex cards, your Amex rewards and, once you have access, ACE. AgentsPay governs the agent before any card is charged. Each agent gets its own identity and wallet, a hard per-agent spend limit that totals across the month, a per-transaction ceiling, an approval threshold that pauses for a named person, and scoped virtual cards locked to the merchants you allow. Every decision lands in an audit trail you can match against your Amex statement.

The same policy applies whichever rail pays, so an agent that buys on Amex, pays an API on x402 and renews a subscription on a Visa card hits one budget, not three. The limit is a stored number checked before authorization, and the agent cannot edit its own policy.

For the other networks, see Visa Intelligent Commerce and Mastercard Agent Pay, compared side by side in Visa vs Mastercard for agents. If you are weighing a card for an agent to hold, our agentic credit card comparison covers Robinhood, Amex and business virtual cards.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the American Express hosts returned on 7 October 2026

Unauthenticated requests, each host also sent a randomly generated control path. Repeatable by anyone.

Request Response What it proves
mcp.americanexpress.com, mcp.amex.com, ace.americanexpress.com, agents.americanexpress.com NXDOMAIN No Amex MCP or ACE host exists yet
api.americanexpress.com /mcp and OAuth, OpenID, agent card and llms.txt paths JSON 404, 162 to 208 bytes Nothing agent-facing on the API gateway
api.americanexpress.com random control path JSON 404, 174 bytes The 404s above are genuine
developer.americanexpress.com, any path including the control 200, same 1,863-byte app shell A catch-all, so a 200 there proves nothing
Portal content store, Open Banking API overview 200, 6,650 bytes of JSON The store is public for published products
Portal content store, ACE overview and specification 404, same as a made-up product The ACE specification is not published
www.americanexpress.com/llms.txt 200, three trivia facts, updated 18 Sep 2026 No agent or API guidance for AI systems

ACE at a glance

The five ACE services and the control each one gives you

From the American Express launch materials of 14 April and its engineering post of 22 April 2026.

ACE service What it does What it does not do
Agent registration Gives the developer's agent an identity Amex recognizes Say what the agent may spend in total
Account enablement Card Member links a card to an agent in the Amex app Separate one agent's spend from another's budget
Intent intelligence Records what, where, how much and when to ask for approval Total intents across a week or month
Payment credentials Short-lived, scoped credential bound to one intent Cover non-Amex cards or wallets
Cart context Merchant shares the cart, helps settle disputes Required, it is optional for merchants

Comparison

Where the dollar limit lives for an agent paying by card

Card network and card programs for agents, from public materials as of October 2026.

Option Where the amount is set Who carries an agent mistake Public specification
Amex ACE Inside each certified intent Amex, under Agent Purchase Protection, for registered agents No, invite-only
Visa Intelligent Commerce The consumer mandate and issuer controls Standard card dispute rules Trusted Agent Protocol on GitHub
Mastercard Agent Pay Issuer and consumer controls on the agentic token Standard card dispute rules Developer guides on the Mastercard portal
Robinhood agentic credit card Monthly limit or approve every purchase The cardholder, per Robinhood's terms Banking MCP server, consumer only
AgentsPay Per-agent monthly budget, per-transaction cap, approval threshold Policy blocks it before authorization Documented API

Frequently asked

Questions people ask about American Express Agentic Commerce

What is Amex ACE?

Amex ACE, short for Agentic Commerce Experiences, is the American Express developer kit for AI agent purchases, launched on 14 April 2026. It has five services: agent registration, account enablement, intent intelligence, payment credentials and cart context. It lets a registered agent pay with an Amex card inside an intent the Card Member certified.

Does American Express support agentic commerce?

Yes. American Express supports agentic commerce through the ACE developer kit and Amex Agent Purchase Protection, both announced in April 2026. It also takes part in Google's AP2 and is a premier member of the x402 Foundation. Access to the ACE specification was invite-only when we checked on 7 October 2026.

What is Amex Agent Purchase Protection?

Amex Agent Purchase Protection is a commitment to credit Card Members when an AI agent they enrolled makes a mistake, such as buying the wrong item or a duplicate. It applies when the agent is registered with American Express and the purchase has a certified intent. It covers agent errors, not Card Member or merchant errors.

How do developers get access to the Amex ACE developer kit?

By invitation. The American Express developer portal lists Amex Agentic Commerce Experiences under Payment Services with an invite request address, and on 7 October 2026 its specification files were not in the portal's public content store. Developers register on developer.americanexpress.com and request access for the product.

Does Amex have an MCP server?

Not yet. On 7 October 2026 mcp.americanexpress.com and mcp.amex.com did not exist in DNS, and the Amex API gateway returned 404 on every MCP path. American Express has said an MCP server, SDKs and Agent Skills are tools the ACE platform will provide.

Can an AI agent use my Amex card?

Yes, through an agent that is registered with American Express and that you enroll from the Amex app. The agent then receives a short-lived credential tied to each purchase intent rather than your card number. Giving an unregistered agent your raw card details is possible but falls outside Agent Purchase Protection.

How do I set a spending limit for an AI agent on an Amex card?

Within ACE, the amount is set per purchase intent, which includes how much can be spent and when extra approval is required. For a running monthly limit per agent, or one limit across Amex and other cards, put the agent behind a spend control layer that checks a stored budget before any card is charged.

Which protocols does Amex ACE work with?

American Express describes ACE as interoperable with existing and emerging protocols. Amex joined Google's Agent Payments Protocol (AP2) announcement and is a premier member of the x402 Foundation, and its launch partners include OpenAI, Google, Microsoft, Stripe, PayPal and Adyen. The integration details sit in the invite-only specification.

Is Amex Agent Purchase Protection available on business cards?

The April 2026 announcement describes the protection for Card Members using registered agents and does not publish separate terms for corporate or business cards, a per-claim cap or a claim process. Check the benefit terms for your specific card program before relying on it for company purchases.

How is Amex ACE different from Visa Intelligent Commerce and Mastercard Agent Pay?

All three register agents and give them tokenized credentials. Amex is the only one to back registered agent mistakes with a named purchase protection, and it runs a closed-loop network, so it sees both the Card Member and the merchant. Visa has published its Trusted Agent Protocol openly, while the ACE specification is invite-only.

Keep reading

More explainers

Concur AI and Joule

Concur AI and Concur Joule

SAP Concur is putting Joule agents into the expense report itself this year: one builds the report, one audits receipts before submission, and an AI approval assistant reaches US approvers in Q4 2026. Outside agents connect through Microsoft 365 Copilot or the Concur API. We read every OAuth scope SAP publishes for Concur to see where an agent's dollar limit would live. It is not in the scopes and it is not in the approve call.

Read

Coupa AI and Navi

Coupa AI and Coupa Navi

Coupa's Navi agents moved from answering questions to running payment batches this year, and since the September 2026 release Microsoft Copilot and custom agents can read and write Coupa data through MCP. We probed the Coupa MCP authorization servers on six live US tenants to see where the dollar limit sits for an outside agent. It is not in the token.

Read

Navan and Expensify

Navan AI and Expensify

Navan and Expensify both opened their travel and expense data to AI assistants this summer, and both are moving from answering questions to acting on reports. Expensify Agents can already submit, approve, reject and route expense reports. Navan says write tools for approving expenses and booking travel are next. We measured where the dollar limit sits for those agents, and in the agent itself it does not sit anywhere.

Read

HubSpot Breeze

HubSpot Breeze

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Read

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy