AgentsPay

Explainer

Coupa AI Agents and Coupa Navi with Coupa MCP Spend Controls

Coupa's Navi agents moved from answering questions to running payment batches this year, and since the September 2026 release Microsoft Copilot and custom agents can read and write Coupa data through MCP. We probed the Coupa MCP authorization servers on six live US tenants to see where the dollar limit sits for an outside agent. It is not in the token.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Coupa AI is the Navi agent layer across Coupa's spend platform, plus Navi Connect, an MCP integration with more than 30 tools that Coupa describes as auditable, read-write and inheriting each user's permissions. On 5 October 2026 we read the MCP authorization server on six US tenants. It offers exactly two scopes, t:read and t:write, and grants both by default. So an assistant connected through Coupa MCP can do whatever the connecting person can do, up to that person's approval authority, with no separate budget, ceiling or threshold for the agent itself. Coupa's approval chains are strong controls for people. A per-agent dollar limit has to be added outside the token.

What Coupa AI and Coupa Navi agents can do with money in 2026

Coupa Navi is the brand for Coupa's AI agents. Coupa released its first Navi agents in May 2025, and by its 20 August 2026 release it said more than 450 customers ran Coupa agents in production, with over 50 specialized agents across early access, limited availability and general availability. The September release made three more agents generally available, including an Invoice Attachment Validation Agent that automates approve and reject decisions on invoices.

The agent that matters most for a controller is the Navi Payment Batch Creation Agent. Coupa reports that in five weeks in production it autonomously ran 14 payment batches covering 2,395 payments worth 20.1 million dollars, at roughly 27 dollars in AI credits. That is a real result, and it is also the clearest statement in the industry that agents now sit inside the payment run, not beside it.

Customers build their own agents too. Navi Agent Studio went generally available in May 2026 as a no-code builder with role-based access to agents, and Coupa says more than 400 custom agents were built in its first months, making it the most used AI feature on the platform.

Coupa MCP and Navi Connect for outside agents

The Coupa MCP integration ships as part of Navi Connect. Coupa announced it at Inspire in May 2026 with third-party integration, MCP and agent-to-agent support expected in September, and the 20 August release confirmed it: external AI including Microsoft Copilot and custom-built agents can use more than 30 out-of-the-box tools across procurement, invoicing, contracts and expenses. Coupa's own wording is that access is auditable and read-write and inherits each user's existing permissions and security controls.

That sentence is the whole governance model, so we checked what it means at the protocol level. Read-write is the default, not an upgrade, and the permission boundary is the human who signs in. There is no per-agent identity with its own limits in the token.

How we measured the Coupa MCP authorization server

Coupa runs a separate instance for every customer at <tenant>.coupahost.com. There is no central MCP host: mcp.coupa.com does not resolve. So on 5 October 2026 we took six US enterprise and university tenants whose Coupa addresses are printed in their own public supplier guides and sent each one the same unauthenticated requests. We do not name the customers here. Anyone can repeat the test against their own tenant.

For every tenant we fetched the OpenID configuration, the MCP protected-resource document, the MCP authorization-server document, and sent a JSON-RPC initialize to /mcp. As a control we requested a randomly generated path on each host and a random suffix under the protected-resource path. Every control returned 404 on all six, so nothing below is a catch-all server answering 200 to anything.

Five tenants had MCP live. Each returned a protected-resource document naming /mcp as the resource and /mcp-auth as its authorization server, and answered the initialize call with 401 and a spec-correct WWW-Authenticate: Bearer challenge pointing back at that document. The sixth returned 404 on every MCP path, which tells you MCP is switched on per tenant rather than everywhere at once.

Two MCP scopes against 314 API scopes

The MCP authorization server on all five live tenants publishes exactly two scopes, t:read and t:write, and its metadata sets default_scopes to both. It supports only the authorization-code grant with PKCE S256, accepts public clients with no client secret, and advertises a dynamic client registration endpoint. We did not register a client on anyone's tenant. The metadata alone settles the question.

Compare that with the main Coupa OAuth server on the same hosts. It publishes 314 scopes, identical on all six tenants, and they are precise: core.approval.write approves, rejects and holds approvals, core.invoice.approval.write adds and removes invoice approvers and restarts approvals, core.budget.write creates and adjusts budget lines, and there is a scope literally named core.invoice.approval.bypass. 155 of the 314 grant more than read access, and 57 of those touch invoices, payables, payments, cards, budgets, approvals or treasury.

An integration built on the core API can be given three of those scopes. An assistant connected through Coupa MCP is offered read and write. The granularity Coupa built for integrations does not reach the MCP consent screen, so the only thing that narrows an MCP agent is the role of the person who connected it.

Where the dollar limit sits for a Coupa agent

Coupa deserves credit here. It is the strongest platform in our series on structured approvals. Approval chains can route by amount, approvers can carry approval limits, budgets can block or warn, and invoice tolerances catch price and quantity drift. Those are real ceilings, and you should configure them before any agent goes live.

They are ceilings on people and documents. Not one of the 314 scope names, and neither of the two MCP scopes, carries an amount, limit or threshold. When a controller with a 250,000 dollar approval limit connects Copilot through MCP, the assistant inherits that 250,000 dollar authority. It has no budget of its own, no lower per-transaction cap, and no monthly total that stops it. The audit log records what happened, which is valuable after the fact and does nothing to stop the next approval.

Payments need a precise reading too. Through the core API, core.pay.payments.write only marks payments as exported. It cannot originate a payment. Coupa's own agents are a different case: the Payment Batch Creation Agent builds the batches itself, inside Coupa, governed by whatever approval and payment controls the customer configured for the payment run.

A rollout checklist for Coupa AI agents that touch spend

  1. Connect Coupa MCP as a dedicated, low-authority user. The token will be read and write whatever you do, so the role is your only lever. Never connect as a controller, AP manager or anyone with treasury access.
  2. Set approval limits on that user in the approval chain. Treat the agent as an approver with the smallest limit that still lets it do its job, and send everything above it to a named person.
  3. Keep invoice tolerances and budget checks strict. They are the controls that still fire when the actor is an agent.
  4. Audit the integrations holding core.approval.write, core.budget.write or core.invoice.approval.bypass. These are the scopes that let software change who approves and how much is available.
  5. Put agent purchases that leave Coupa behind a payment layer with a per-agent budget. Cards, API spend and checkout purchases an agent makes outside your procure-to-pay flow are not covered by a Coupa approval chain at all.

How AgentsPay fits alongside Coupa

AgentsPay does not replace Coupa. Keep Coupa as the system of record for requisitions, purchase orders, invoices and payment runs. AgentsPay governs the agent: each agent gets its own wallet and identity, a hard per-agent spend limit, a per-transaction ceiling, an approval threshold that pauses for a human, and scoped virtual cards for anything it buys outside the procure-to-pay flow. Every decision lands in an audit trail you can reconcile against Coupa.

If you are pricing the Coupa side of that stack, our Coupa pricing breakdown covers what Coupa publishes and how Navi AI is billed. For the wider procurement picture see AI procurement software and agentic procurement and our procurement agents use case. The same measurement on SAP is in SAP Joule agents

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the Coupa MCP endpoints returned, probed 5 October 2026

Six live US tenants, unauthenticated requests, randomly generated control paths. Repeatable by anyone against their own tenant.

Request Response What it proves
mcp.coupa.com Does not resolve There is no central Coupa MCP host. MCP lives on each customer tenant
GET /.well-known/oauth-protected-resource/mcp 200 JSON on 5 of 6 tenants Resource is <tenant>/mcp, authorization server is <tenant>/mcp-auth, bearer tokens in the header
POST /mcp with JSON-RPC initialize 401 with WWW-Authenticate Bearer and resource_metadata on 5 of 6 A live, spec-correct MCP endpoint that requires OAuth
GET /.well-known/oauth-authorization-server/mcp-auth 200 JSON on 5 of 6 Scopes t:read and t:write, both granted by default, PKCE S256, public clients, dynamic registration advertised
All MCP paths on the sixth tenant 404 MCP is enabled per tenant, not platform-wide
GET /.well-known/openid-configuration 200 JSON on 6 of 6 314 OAuth scopes, an identical list on every tenant
Random path and random protected-resource suffix (control) 404 on 6 of 6 No catch-all server, so every 200 above is a real document

Original research

The 314 Coupa OAuth scopes, read 5 October 2026

From the OpenID configuration each tenant publishes, compared with the two scopes offered to MCP clients.

Measure Count or examples Carries a dollar limit
Scopes on the core OAuth server 314, identical on six tenants No
Scopes granting more than read 155 No
Of those, touching money 57, across invoices, payables, payments, cards, budgets, approvals and treasury No
Approval scopes core.approval.write, core.approval.configuration.write, core.invoice.approval.write, core.invoice.approval.bypass, core.v2.approval.invoice.manage No
Agent and MCP scopes core.mcp.access, core.navi_agent_list.write, core.sourcing.ai_agent.write and three ai_agent read scopes No
Scopes offered to an MCP client 2, t:read and t:write, both by default No

Controls today

What limits a Coupa agent, and what it limits

Coupa controls you should configure first, and the gap each one leaves for an agent.

Control What Coupa provides What it does not cover for agents
Approval chains and approval limits Amount-based routing and per-approver limits An MCP agent inherits the connecting user's limit instead of having its own
Budgets Budget lines that block or warn on documents No per-agent budget, and a token with core.budget.write can adjust budget lines
Invoice tolerances Price and quantity variance checks Do not cap how many invoices an agent approves in a day
MCP consent OAuth with PKCE, user sign-in, audit log Two scopes only, read and write, with write granted by default
Navi Agent Studio Role-based access to custom agents No amount field on an agent, roles decide what it can touch
Purchases outside procure-to-pay Not in scope for Coupa Cards, API spend and checkout purchases an agent makes need a separate payment layer

Across the series

Where each platform puts the dollar limit for agents

From our dated measurements of each vendor's public documents and specifications.

Platform Governs which actions Governs how much money
Coupa MCP (5 Oct 2026) Yes, the connecting user's role Approval limits per person, none per agent, two MCP scopes
Expensify Agents (2 Oct 2026) Yes, prompt and workspace role Approval limit per report, none per agent
Navan MCP (2 Oct 2026) Yes, inherits the user role No amount scope or field
HubSpot Breeze (1 Oct 2026) Yes, scopes and TAKE_ACTION review No amount scope or field
SAP Joule (26 Sep 2026) Yes, SAP roles No limit in the agent layer, 0 of 480 property names
AgentsPay Yes Per-agent budget, per-transaction ceiling, approval threshold

Frequently asked

Questions people ask about Coupa AI and Coupa Navi

What is Coupa Navi?

Coupa Navi is the name of Coupa's AI agents across its spend management platform. Coupa released the first Navi agents in May 2025 and now lists more than 50 across sourcing, procurement, invoicing, payments and expenses. Navi Agent Studio lets customers build their own agents without code, and Navi Connect links outside AI to Coupa through MCP.

Does Coupa have an MCP server?

Yes. Coupa's MCP integration ships as part of Navi Connect and runs on each customer tenant at https://.coupahost.com/mcp, not on a central host. Coupa says it offers more than 30 tools across procurement, invoicing, contracts and expenses. On 5 October 2026 we found it live on five of six US tenants we probed.

Is the Coupa MCP server read-only?

No. Coupa describes MCP access as auditable and read-write, inheriting each user's existing permissions. Its MCP authorization server offers two scopes, t:read and t:write, and grants both by default. The practical limit on what an assistant can do is the Coupa role of the person who connected it.

What are Coupa AI agents?

Coupa AI agents are the Navi agents that carry out work inside Coupa, such as creating sourcing events, validating invoice attachments, capturing early payment discounts and building payment batches. Coupa reports that its Payment Batch Creation Agent ran 14 batches with 2,395 payments worth 20.1 million dollars in five weeks.

Can Coupa AI agents approve invoices?

Yes, within limits you set. Coupa's Invoice Attachment Validation Agent automates approve and reject decisions, and an outside assistant connected through MCP can act with the connecting user's permissions. Approval chains and approval limits still apply, so configure a low limit for any user an agent acts as.

How much does Coupa AI cost?

Coupa does not publish a price for Navi agents. For new customers and upgrades it moved to an outcome-based model with AI compute included at a flat rate, according to analyst coverage of Inspire 2026. Coupa's own example put a five-week payment batch run at about 27 dollars in AI credits. See our Coupa pricing guide for the full breakdown.

Is it safe to connect Microsoft Copilot to Coupa?

It can be, if you connect as the right user. Coupa MCP uses OAuth with PKCE and an audit log, which is sound. But the token is read and write, so connect Copilot as a dedicated user with read access needs and a small approval limit, never as a controller or AP manager whose authority the assistant would inherit.

How do I limit what a Coupa MCP connection can do?

Limit the person, because the token cannot be narrowed below read and write. Create a dedicated Coupa user for the agent, give it the smallest role and approval limit that still works, keep budget checks and invoice tolerances strict, and route any agent purchase made outside Coupa through a payment layer with its own per-agent budget.

What is Navi Agent Studio?

Navi Agent Studio is Coupa's no-code builder for custom agents, generally available since May 2026. You describe the agent in natural language, configure it, monitor its activity and control access by role. Coupa says customers built more than 400 agents with it within months. Agents do not carry their own dollar limit.

Can a Coupa agent pay suppliers on its own?

Coupa's own Payment Batch Creation Agent builds payment batches inside Coupa under the payment controls you configure. An outside agent using the core API cannot originate a payment through core.pay.payments.write, which only marks payments as exported. Purchases an agent makes outside Coupa need their own controls.

Keep reading

More explainers

Navan and Expensify

Navan AI and Expensify

Navan and Expensify both opened their travel and expense data to AI assistants this summer, and both are moving from answering questions to acting on reports. Expensify Agents can already submit, approve, reject and route expense reports. Navan says write tools for approving expenses and booking travel are next. We measured where the dollar limit sits for those agents, and in the agent itself it does not sit anywhere.

Read

HubSpot Breeze

HubSpot Breeze

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Read

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy