AgentsPay

Explainer

HubSpot Breeze AI Agents, Customer Agent and Prospecting Agent Spend Controls for the HubSpot MCP Server

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

HubSpot Breeze agents can create and change commerce records such as quotes, orders, carts and line items through the HubSpot MCP server and custom agent tools, and HubSpot asks for human review of TAKE_ACTION tools by default. We read all 157 OAuth scopes HubSpot publishes on 1 October 2026: 29 relate to commerce or billing and none expresses a spend limit, budget or approval threshold. HubSpot Credits caps the AI bill, not the money the agent moves, so a dollar ceiling has to sit in the payment layer.

What HubSpot Breeze is in 2026, and which parts can touch money

"HubSpot Breeze" covers three different things, and they carry very different authority. Breeze Assistant is the in-app helper that drafts, summarizes and searches the CRM for the person using it. Breeze agents are the paid, autonomous workers: Customer Agent for support, Prospecting Agent for outbound, plus Data, Content and Knowledge Base agents. Breeze Intelligence is the enrichment layer. In July 2026 HubSpot moved the agents into a new home called Agent Hub and renamed Breeze Studio to Agent Builder, so you will see both names in the product and in older guides.

Most of what Breeze does never touches money. Answering a ticket, writing an email or filling a property is a content risk, not a financial one. The financial surface is narrower and easy to miss. HubSpot says Customer Agent can take action when a question needs it, such as order status through Shopify or changes in the CRM, within the rules you set. Agent Builder lets you give any agent agent tools, which are custom workflow actions that POST to a URL you control. And the HubSpot MCP server lets Claude, ChatGPT or your own agent read and write CRM commerce objects from outside HubSpot entirely.

That is where a buyer's money shows up: a quote with the wrong discount, an order line at the wrong price, a cart pushed to checkout, or an agent tool that calls your refund or purchasing API. We went looking for the control that limits the amount, and measured what HubSpot publishes.

How we measured the HubSpot MCP server

On 1 October 2026 we sent unauthenticated requests to mcp.hubspot.com with no account and no credentials, so anyone can repeat this in a terminal. Every probe was paired with a randomly generated control path, because some servers answer 200 to anything and look like they support every endpoint.

The root of mcp.hubspot.com answered a JSON-RPC initialize POST with 401 and a WWW-Authenticate: Bearer resource_metadata header pointing at /.well-known/oauth-protected-resource. That is the behavior the current MCP authorization spec asks for, and fewer hosts in our series get it right than you would expect. The protected-resource document returned 200 and named mcp.hubspot.com as its own authorization server. The authorization-server document returned 200 with authorization code, refresh token and client credentials grants, PKCE S256, and a token introspection endpoint.

Two details stand out. Both documents publish scopes_supported as an empty list, so an MCP client cannot see in advance what it is asking for. And api.hubapi.com/.well-known/oauth-authorization-server returns the same MCP issuer, so HubSpot has pointed its main API host's discovery document at the MCP authorization server. The random control paths on the root and under /.well-known/ returned 404, and so did /mcp, so the server is not a catch-all.

157 HubSpot OAuth scopes, 29 about commerce, and not one about a limit

Because the MCP server does not list its scopes, we read the source of truth instead: HubSpot's public scopes reference for apps, last modified 15 September 2026. Its scope table lists 157 scopes. 64 grant write access. 29 relate to commerce, billing, currency or tax.

The commerce writes are concrete. An app or agent holding them can create and change carts, line_items, orders and quotes, move orders through pipelines with crm.pipelines.orders.write, and change the schemas of invoices and subscriptions. settings.billing.write lets it manage and assign paid seats. settings.currencies.write lets it change exchange rates.

We then searched all 157 names for limit, budget, spend, approv, amount, threshold and cap. Zero matches. HubSpot models money in detail, with commerce payments, invoices, subscriptions and tax rates, and it scopes access by object and by sensitivity tier. It does not scope by amount. A token that can write a quote can write a quote for any total.

One honest qualification. HubSpot's commerce payments API is read-only for live processing: its documentation says it cannot be used to create payments intended for payment processing, only to record payments made elsewhere. So a HubSpot token cannot charge a card on its own. What it can do is set the prices, discounts and quantities that a human or an automated checkout then charges, and mark invoices as paid. The MCP documentation also lists invoices and subscriptions among read-and-write objects, while the scope table offers only read scopes on those two object types, which is worth checking against your own install.

Agent tools and the TAKE_ACTION review step

HubSpot deserves credit for one control most platforms in our series lack. Every custom agent tool declares a toolType of GET_DATA, GENERATE or TAKE_ACTION, and for TAKE_ACTION the developer reference says that by default, this type of action requires users to review the output before approving the tool execution. A tool can also return an execution state of BLOCK with an expiry duration, which halts the workflow.

The limits of that control matter for anyone approving a rollout. The review is a per-execution yes or no, not a threshold, so it cannot say "approve automatically under 200 dollars and ask above that." It is a default, which means it can be relaxed as volume grows and the reviews become a bottleneck. The tool schema itself has no amount, budget or rate field; actionUrl, inputFields, outputFields and the LLM description are what HubSpot sees. And the feature is still marked beta. So the first time a team turns off review to let Customer Agent issue credits overnight, there is no dollar ceiling left anywhere in HubSpot.

That is also the architectural opening. Because an agent tool is a POST to a URL you control, the URL can be a policy service that checks the amount, the running total and the counterparty before it calls the system that moves the money, and returns BLOCK when the answer is no.

HubSpot Credits caps the AI bill, not the money agents move

HubSpot does have spending controls, and they are good ones. They govern a different bill. HubSpot Credits cost 0.01 dollars each, sold in capacity packs of 1,000 for 10 dollars, or as pay-as-you-go overage at 0.010 dollars per credit invoiced in increments of 10. Seat-based Smart CRM and Hub subscriptions include 500 credits a month on Starter, 3,000 on Professional and 5,000 on Enterprise. Customer Agent uses 50 credits (0.50 dollars) per resolved conversation, Prospecting Agent 100 credits (1 dollar) per lead it recommends for outreach, and Data Agent 10 credits per prompt per record.

Once you have bought additional credits, HubSpot lets you set a maximum monthly credit limit for the account, and feature-level limits for individual agents. Per HubSpot's knowledge base, updated 9 September 2026, when usage reaches the account limit any feature requiring credits will be paused until the next monthly cycle. Watch one default: once you have purchased additional credits, going over the limit auto-upgrades you to a higher credit pack for the rest of your term unless you switch overage to pay-as-you-go.

None of that touches the quote, the order or the refund. A Customer Agent that resolves 2,000 conversations costs 1,000 dollars in credits whether each conversation ended with a password reset or a 400 dollar goodwill credit. The credit limit stops the agent from running up HubSpot's invoice. It cannot see yours.

A rollout checklist for HubSpot agents that touch commerce

  1. List every agent and integration holding a commerce write scope. Carts, line items, orders, quotes and order pipelines are the ones that change what a customer is charged. Remove them from any app that only needs to read.
  2. Keep TAKE_ACTION review on for every agent tool that creates a credit, refund, discount or purchase, and read a few weeks of decisions before you relax it for any band.
  3. Point money-moving agent tools at a policy service, not straight at Stripe, Shopify or your purchasing API, so the amount is checked outside the language model.
  4. Set a per-action ceiling and a daily and monthly total per agent, not just per tool, so two tools cannot add up past your budget.
  5. Set HubSpot's account credit limit and switch overage to pay-as-you-go if you do not want an automatic pack upgrade.
  6. Reconcile monthly per agent. Put the credit bill and the money each agent moved side by side so cost per outcome includes both.

How AgentsPay fits alongside HubSpot Breeze

AgentsPay does not replace HubSpot, HubSpot Payments or your processor. It sits between the agent tool and the money. Your TAKE_ACTION tool posts to AgentsPay instead of calling the refund, credit or purchase endpoint directly, and AgentsPay applies the policy you set for that agent: a per-transaction ceiling, a daily and monthly budget, a merchant or counterparty allowlist, and an approval threshold that sends anything above it to a named person for a one-tap decision. Below the threshold it goes through without a human in the loop, which is exactly the threshold HubSpot's review step cannot express. The agent's credentials cannot change that policy.

Every decision lands in an audit trail tied to the agent and the HubSpot record, and when an agent needs to buy something itself it can be issued a scoped virtual card on your own issuer. See how AI agent spend controls and approval thresholds work, or compare the same measurement for Salesforce Agentforce, Zendesk AI agents and Intercom Fin. If you are costing the agents first, our HubSpot Customer Agent pricing breakdown works the numbers.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the HubSpot MCP endpoints returned, probed 1 October 2026

Unauthenticated requests with randomly generated control paths, repeatable by anyone.

Request Response What it proves
POST initialize to mcp.hubspot.com/ 401, WWW-Authenticate Bearer resource_metadata Live host, spec-correct OAuth challenge
/.well-known/oauth-protected-resource 200 JSON, scopes_supported empty Self-issued authorization, no published scope list
/.well-known/oauth-authorization-server 200 JSON, PKCE S256, client credentials grant, introspection Standard OAuth server, scopes_supported empty
api.hubapi.com/.well-known/oauth-authorization-server 200, same MCP issuer Main API discovery points at the MCP server
/mcp and random control paths 404 Not a catch-all server

Scope surface

HubSpot OAuth scopes by what they can change

From HubSpot's public scopes reference, last modified 15 September 2026, counted 1 October 2026.

Group Count or examples Sets a dollar limit
All scopes in the reference table 157 No
Write-level scopes 64 No
Commerce, billing, currency and tax 29 No
Commerce object writes carts, line_items, orders, quotes, order pipelines No
Billing and currency writes settings.billing.write, settings.currencies.write No
Names containing limit, budget, spend, approval, amount, threshold or cap 0 Not applicable

Controls today

What limits a HubSpot agent, and what it limits

From HubSpot developer docs and knowledge base articles, read 1 October 2026.

Control What HubSpot provides What it limits
Account credit limit Monthly maximum, pauses credit features when reached The HubSpot AI bill
Feature credit limit Monthly maximum per agent or feature The HubSpot AI bill
TAKE_ACTION review Human review before tool execution, on by default, beta Each execution, yes or no
Tool BLOCK state Halts the workflow with an expiry Whatever your endpoint decides
Per-action dollar ceiling None Nothing
Daily or monthly money total per agent None Nothing

Across the series

Where each platform puts the dollar limit for agents

From our dated measurements of each vendor's public documents and specifications.

Platform Governs which actions Governs how much money
HubSpot Breeze (1 Oct 2026) Yes, scopes and TAKE_ACTION review No amount scope or field
Intercom Fin (30 Sep 2026) Yes, procedures and approval steps Only conditions you write per procedure
Zendesk AI agents (29 Sep 2026) Yes, actions and approval flags No amount field
Salesforce Agentforce Yes, topics and actions No spend field
AgentsPay Yes Per-agent budget, per-transaction ceiling, approval threshold

Frequently asked

Questions people ask about HubSpot Breeze

What is HubSpot Breeze?

HubSpot Breeze is HubSpot's AI layer. It includes Breeze Assistant, the in-app helper, Breeze agents such as Customer Agent and Prospecting Agent that complete jobs on their own, and Breeze Intelligence for data enrichment. Since July 2026 the agents live in Agent Hub, and Breeze Studio is now called Agent Builder.

What are HubSpot Breeze agents?

They are autonomous AI agents inside HubSpot. Customer Agent answers and resolves support conversations, Prospecting Agent researches accounts and drafts outreach, Data Agent answers questions about records, and Content and Knowledge Base agents write marketing and help content. They require a Professional or Enterprise subscription and bill in HubSpot Credits.

How much do HubSpot AI agents cost?

HubSpot Credits cost 0.01 dollars each. Customer Agent uses 50 credits, or 0.50 dollars, per resolved conversation, Prospecting Agent uses 100 credits, or 1 dollar, per lead recommended for outreach, and Data Agent uses 10 credits per prompt per record. Professional plans include 3,000 credits a month and Enterprise 5,000.

Does HubSpot have an MCP server?

Yes. The remote HubSpot MCP server runs at mcp.hubspot.com and uses OAuth with PKCE. HubSpot documents read and write access to contacts, companies, deals, tickets, carts, products, orders, line items, invoices, quotes and subscriptions, and read-only access to users, teams, campaigns and content. Unauthenticated requests get a spec-correct 401 challenge.

Can HubSpot AI agents create quotes and orders?

Yes, if the app or agent holds the write scopes. HubSpot publishes write scopes for carts, line items, orders, quotes and order pipelines, and the MCP server lists them as read and write objects. None of those scopes limits the total, so a token that can write a quote can write one for any amount.

Can HubSpot Breeze agents make payments?

Not directly through HubSpot's API. HubSpot's commerce payments API records payments made elsewhere and cannot create payments for processing. Agents can still affect money by setting prices and discounts on quotes and orders, marking invoices paid, or calling an external refund or purchasing API through a custom agent tool.

Do HubSpot agent tools require approval?

TAKE_ACTION agent tools require a user to review the output before execution by default, according to HubSpot's developer reference. It is a yes or no review on each execution, it has no amount threshold, and the agent tools feature is still in beta. GET_DATA and GENERATE tools run without that review.

How do I set a HubSpot credit limit?

After buying additional credits, a Super Admin can set a maximum monthly credit limit for the account and feature-level limits for individual agents in the HubSpot Credits settings. When the account limit is reached, credit features pause until the next cycle. Switch overage to pay-as-you-go if you do not want an automatic pack upgrade.

How do I limit how much a HubSpot agent can spend?

Put the limit outside HubSpot and outside the model. Route money-moving agent tools to a policy service that checks a per-action ceiling, a daily and monthly total and the counterparty before calling the payment system, and returns BLOCK or asks a person above your threshold. HubSpot's credit limits only cap the AI bill.

Is it safe to connect Claude or ChatGPT to HubSpot?

For reading CRM data it is a reasonable setup, since the MCP server uses OAuth and blocks sensitive data properties. Be careful with commerce write access. Grant quote, order, cart and line item writes only to agents that need them, and keep a separate dollar ceiling, because no HubSpot scope limits the amount.

What is the difference between HubSpot Credits limits and spend controls?

HubSpot Credits limits cap how many credits your agents consume, which is the price of the AI work. Spend controls cap the money an agent commits on your behalf, such as refunds, credits, discounts and purchases. A Customer Agent costs the same 0.50 dollars per resolution whether it gave a 5 dollar or a 500 dollar credit.

HubSpot Breeze vs Salesforce Agentforce for spend control, which is safer?

HubSpot has the more protective default, because TAKE_ACTION tools ask for review before running. Agentforce governs topics and actions but has no spend field either. Neither sets a dollar ceiling or a monthly money total per agent, so whichever CRM you run, the amount limit belongs in the payment layer.

Keep reading

More explainers

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy