AgentsPay

Explainer

Brex AI, Brex API and Brex MCP for AI Agents, Measured for Spend Limit Controls

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Brex AI agents reach Brex through two doors. The hosted Brex MCP server at api.brex.com/mcp, in Beta since April 2026, exposes 43 tools, and on 28 September 2026 only 5 of them wrote anything: memos, receipts, attendees, assigning an expense to a limit, and feedback. None creates a card, changes a limit, approves a request or moves money. The Brex Developer API does all four: POST /v2/spend_limits, POST /v2/cards with spend controls and POST /v1/transfers. An agent holding an admin API token therefore has far more authority than an agent connected through MCP.

What Brex AI is in 2026, and which parts touch money

Brex AI is the set of agents Brex runs inside its own product plus the doors it opens to outside assistants. Inside the product, Brex lists Brex Assistant (expenses, memos, receipts and reimbursements for employees), an Audit Agent and a Review Agent on its intelligent finance page. CEO Pedro Franceschi introduced the agent platform publicly on 5 November 2025.

Outside the product, Brex launched the Brex MCP server in April 2026, per its developer changelog, so assistants such as Claude, ChatGPT, Cursor and Codex can work on your Brex data. Brex also keeps a public Developer API, which is older, larger and much more powerful.

One ownership fact matters for procurement teams: Capital One completed its 5.15 billion dollar acquisition of Brex on 7 April 2026, and the Brex site now describes Brex LLC as a wholly owned subsidiary of Capital One, N.A. Brex still runs its own product and API.

What Brex does not have, as of our check, is a card product built for AI agents to spend with, the way Ramp ships Agent Cards. Brex AI today reviews, codes and explains spend. It does not buy things on its own.

How we measured the Brex MCP server and the Brex API

On 27 and 28 September 2026 we probed Brex with no account and no credentials, the way anyone can repeat it. We requested api.brex.com/mcp, its OAuth protected resource document, a randomly generated control path under the same well-known prefix, a random path at the API root, and the DNS name mcp.brex.com. We then read the tool table in the Brex MCP documentation and downloaded the ten official OpenAPI specifications linked from developer.brex.com.

The control paths changed how we read the result. A random path under /.well-known/oauth-protected-resource/ did not return 404. It returned a generic document named Brex API with the same scope list, while the /mcp path returned one named Brex MCP Server. So the scope list is the platform list shared by every Brex resource, and the MCP identity is proven by the resource name and the documentation, not by the scopes alone. A random path at the root returned 404, so the host is not a catch-all.

mcp.brex.com does not exist (NXDOMAIN). The MCP server lives on the API host. Brex does not publish its server as open source; the Brex MCP packages on npm and GitHub are third-party projects.

The Brex MCP server has 43 tools and 5 of them write

The Brex MCP tool table lists 43 tools. Thirty-eight read: users, departments, locations, cost centers, expenses, cards, limits, the expense policy on a limit, business bank accounts and their transactions, bills, vendors, accounting records, GL accounts, trips and bookings. One more, start_expense_download, kicks off an export job.

The 5 write tools are update_expense_memo, upload_card_expense_receipt_from_urls, replace_attendees_for_card_expense, assign_limit_for_card_expenses and submit_feedback. The closest one to money is assign_limit_for_card_expenses, which moves an expense that already happened onto a different spend limit. It changes which budget absorbs the charge. It does not change how big the budget is.

Brex says it plainly in the docs: approvals and card management are not yet available via MCP. There is no tool to create or edit a limit, issue or unlock a card, approve a request, pay a bill or send a transfer.

Two setup details matter for control. An account or card admin must accept the Developer API agreement and turn on the Brex in AI assistants beta. After that, every user in the account can connect their own assistant with OAuth, and the assistant inherits that person's Brex permissions. Sessions stay active until someone revokes them under Connected integrations.

The scopes behind it, and why the list is longer than the tools

The protected resource document lists 20 scopes. Seventeen are identity or read-only, such as users.readonly, budgets.readonly, accounts.cash.readonly and accounting.record.read. Three carry write capability: cards, expenses.card and expenses.bill.

Two absences are the headline. There is no budgets write scope and no transfers scope in the list, so an OAuth grant through this server cannot be widened into a limit change or a payment. The cards scope is present even though no MCP tool manages cards. In the Developer API that scope sits behind card creation, updates, lock, unlock and terminate, so treat it as the one to watch if Brex adds card tools later.

Because the same document is served for any path under the well-known prefix, these 20 scopes describe what Brex offers across its OAuth resources, not a list tailored to MCP. The tool table is the tighter description of what an assistant can actually do today.

What the Brex API can do that the MCP server cannot

The ten official specifications hold 76 paths and 106 operations. Three groups of those operations are exactly what the MCP server leaves out.

Spend limits. POST /v2/spend_limits and PUT /v2/spend_limits/{id} under the budgets scope create and change a limit: its base limit, a flexible buffer from 0 to 100 percent, the period (weekly, monthly, quarterly, yearly or one time), a per-transaction limit, allowed and blocked merchant categories, owners, members and the expense policy. set_transaction_limit_null removes the per-transaction cap outright.

Cards. POST /v2/cards under the cards scope issues a virtual or physical card with its own spend controls: an amount, a duration (monthly, quarterly, yearly or one time), a lock-after date and an allow or block list of up to 50 merchants. PUT /v2/cards/{id} changes those controls later.

Money movement. POST /v1/transfers under the transfers scope sends ACH, wire or book transfers from a Brex business account. The request has one approval field, approval_type, whose only value is MANUAL, meaning a cash admin must approve before funds leave. When the caller leaves it out, Brex applies the account's default policy.

Amounts are integers in minor units with an ISO currency, so a limit of 50,000 means 500 dollars. Get that wrong in an agent prompt and you are off by a factor of one hundred.

The gap for agents on Brex: the approval is optional and the caller sets it

Brex's decision to keep MCP read-mostly is sound, and it is the most conservative design we have measured among spend platforms. The risk sits one layer down. Teams that want an agent to actually do something on Brex, such as issue a one-time card for a vendor or pay an invoice, end up on the Developer API with an admin-generated token, because that is where the verbs are.

At that point three things hold. The token's scopes decide what the agent can do, and a token with budgets can raise the limit the agent itself spends against. The MANUAL approval on a transfer is a field in the request, chosen by whoever writes the request, which may be the agent. And an API token is tied to the admin who created it rather than to a named agent, so the audit record shows the admin.

None of this is a Brex bug. Brex is a card and banking platform with strong spend limits for people and teams. It simply does not model the agent as the actor, so the separation between the thing that spends and the thing that sets the ceiling is left to you.

A rollout checklist for Brex AI agents

  1. Start with MCP for anything read-only. Spend analysis, missing receipts and policy questions are exactly what the Brex MCP server is built for, and it cannot change a limit.
  2. Decide who may connect. Turning on the beta lets every user connect an assistant. If that is too broad, keep the beta off until you have a written policy, and review Connected integrations monthly.
  3. Never give an agent a token with budgets or transfers. Those belong to a human or to a separate service the agent cannot call.
  4. Issue one card per agent with a one-time or monthly amount, a lock-after date and an allow list of merchants, created by a person, not by the agent.
  5. Force manual approval on transfers at the account policy level rather than trusting each request to set MANUAL.
  6. Name the agent in your own log. Brex will show the token owner. Record which agent made each call so an auditor can tell them apart.

How AgentsPay fits alongside Brex

AgentsPay does not replace Brex as your card program or bank. It sits in front of the agent as the policy decision point: each agent gets its own budget, per-transaction ceiling, merchant allowlist and approval threshold, and the agent's credentials have no write access to its own policy. Approvals above the threshold go to a person in Slack or email, and every decision lands in an exportable audit trail that names the agent, not only the admin who owns the token.

Because the policy is rail neutral, the same ceiling covers a Brex card, a scoped virtual card from another issuer, an API subscription the agent buys and a stablecoin payment. If you are also weighing Ramp for agent spend, our Ramp AI agents and Ramp MCP breakdown measures the other approach, and the Ramp vs Brex for AI agents comparison puts the two side by side. Teams deciding whether to leave Brex altogether can start with our Brex alternative for AI agents guide.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the Brex hosts returned, probed 27 and 28 September 2026

Unauthenticated requests with randomly generated control paths, repeated on both days with identical results.

Request Response What it proves
mcp.brex.com NXDOMAIN There is no separate MCP host
api.brex.com/mcp (POST) 401 Missing or invalid Authorization header Live, authenticated MCP endpoint
/.well-known/oauth-protected-resource/mcp 200, resource name Brex MCP Server, 20 scopes The MCP resource and its OAuth servers are public
/.well-known/oauth-protected-resource/(random) 200, resource name Brex API, same 20 scopes Scopes are platform-wide, not MCP-specific
api.brex.com/(random path) 404 The API host is not a catch-all
Authorization server accounts-api.brex.com/oauth2/default OAuth with dynamic client registration

The tool surface

The 43 Brex MCP tools, grouped by what they can change

From the tool table in the Brex MCP documentation, read 28 September 2026.

Group Tools Effect on money
Read spend and people 38 tools: expenses, cards, limits, policy, bank accounts, bills, vendors, trips, users None, read only
Export start_expense_download None, starts a download job
Tidy records update_expense_memo, upload_card_expense_receipt_from_urls, replace_attendees_for_card_expense None, edits expense details
Recode spend assign_limit_for_card_expenses Moves a past expense to another limit; does not change any limit
Feedback submit_feedback None
Not available via MCP Create or edit limits, card management, approvals, bill pay, transfers This is what keeps MCP safe

The other door

Brex API operations an agent with an admin token could call

From the ten official Brex OpenAPI specifications, 76 paths and 106 operations, read 27 September 2026.

Operation Scope What it controls
POST and PUT /v2/spend_limits budgets Base limit, buffer, period, per-transaction limit, merchant categories, members
POST /v2/cards and PUT /v2/cards/{id} cards Virtual or physical card, amount, duration, lock-after date, up to 50 merchants
POST /v2/cards/{id}/unlock cards Revives a locked card
POST /v1/transfers transfers ACH, wire or book transfer; approval_type MANUAL is optional
POST /v1/vendors vendors Creates a new payee

Across the series

Where the agent can reach the dollar limit

From our dated measurements of each vendor's public documents and specifications.

Platform Can the agent session change its own limit? Can it move money?
Brex MCP (28 Sep 2026) No, no limit or budget write tool No transfer tool or scope
Brex Developer API Yes, with the budgets scope Yes, with the transfers scope
Ramp MCP (27 Sep 2026) Yes, with limits:write or funds:write Scopes exist for bills, reimbursements and drawdowns
AgentsPay No, agent credentials cannot write policy Only within its budget and approval threshold

Frequently asked

Questions people ask about Brex AI agents

What is Brex AI?

Brex AI is the set of AI agents and assistant connections inside the Brex spend platform. It includes Brex Assistant for employee expenses and receipts, an Audit Agent and a Review Agent for finance teams, and the Brex MCP server, launched in April 2026, that lets outside assistants such as Claude, ChatGPT and Cursor work on your Brex data.

Does Brex have an MCP server?

Yes. Brex hosts an MCP server at https://api.brex.com/mcp, in Beta since April 2026. It supports OAuth with dynamic client registration through accounts-api.brex.com and also accepts a Brex API token as a bearer header. An admin must accept the Developer API agreement and enable the Brex in AI assistants beta first.

What can the Brex MCP server do?

It mostly reads. Of its 43 tools on 28 September 2026, 38 read data such as expenses, cards, limits, bank transactions, bills and trips. Five write: expense memos, receipts, attendees, assigning an expense to a limit, and feedback. Brex states that approvals and card management are not yet available through MCP.

Can the Brex MCP server change a spend limit or move money?

No. There is no MCP tool that creates or edits a limit, manages a card, approves a request or sends a transfer, and the OAuth scope list has no budgets write or transfers scope. The closest tool reassigns an existing expense to a different limit, which changes the accounting, not the size of any limit.

What can the Brex API do for AI agents?

Far more than MCP. The Brex Developer API can create and update spend limits with POST and PUT /v2/spend_limits, issue virtual cards with spend controls through POST /v2/cards, lock and unlock cards, create vendors and send ACH, wire and book transfers through POST /v1/transfers. An agent with an admin token can do all of it.

Does Brex have cards for AI agents?

Not as a separate product as of September 2026. You can issue a regular Brex virtual card through the API, with an amount, a duration, a lock-after date and up to 50 allowed merchants, and hand it to an agent. Ramp is the corporate card platform that ships dedicated Agent Cards with agent identities.

Who can connect an AI assistant to Brex?

Once an admin enables the beta, any user in the Brex account can connect their own assistant through OAuth, and the assistant gets that user's Brex permissions. Direct API tokens are different: only account and card admins can generate them, from Settings then Developer in the Brex dashboard.

Is it safe to connect Brex MCP to Claude or ChatGPT?

For analysis, yes, and it is one of the safer finance MCP servers we have measured because it cannot change limits or move money. The residual risks are data exposure, since an assistant sees what its user sees, and forgotten sessions, which stay active until revoked under Connected integrations.

How do I stop an AI agent overspending on Brex?

Give the agent its own Brex card created by a person, with a one-time or monthly amount, a lock-after date and a merchant allow list. Keep budgets and transfers scopes out of any token the agent can use, and enforce manual transfer approval in account policy rather than per request. A policy layer like AgentsPay adds a limit the agent cannot edit.

How much does Brex cost?

Brex pricing, read 27 September 2026, lists Essentials at 0 dollars per user per month, Premium at 12 dollars per user per month, and custom pricing for Enterprise. The MCP server and Developer API are not listed as separate paid add-ons, though the MCP server is in Beta and must be enabled by an admin.

Is Brex owned by Capital One?

Yes. Capital One completed its acquisition of Brex on 7 April 2026 in a deal it valued at 5.15 billion dollars, and the Brex website describes Brex LLC as a wholly owned subsidiary of Capital One, N.A. Brex continues to operate its own product, API and MCP server.

Is Brex or Ramp better for AI agents?

Ramp is further along if you want agents to spend, with agent identities, Agent Cards and write scopes on its MCP server. Brex is the conservative choice if you want assistants to analyze spend without touching limits or money. Either way, the agent's limit should live somewhere its own credentials cannot write.

Keep reading

More explainers

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy