Agentspay

Explainer

MCP Payments: How AI Agents Pay Through a Payments MCP Server

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Last updated July 2026

Agent Payments Console

Pick an agent

Payment intent

intent:

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

Agentspay

single-use

Wallet budget

spent of

Audit trail

In short

MCP payments are payments an AI agent makes by calling a payment tool exposed over the Model Context Protocol. MCP itself is not a payment protocol; it is the tool discovery and invocation layer. The agent lists tools, calls a payment tool, and a settlement protocol such as x402, ACP or a card token authorizes and settles underneath. Production MCP payment servers include Stripe at mcp.stripe.com, Coinbase x402 and Payments MCP, PayPal and Shopify. None of them enforce a per-agent budget or require human approval, so overspend control is left to you.

What MCP payments are

MCP payments are payments an AI agent makes by calling a payment tool that a server exposes over the Model Context Protocol. It helps to be precise about what MCP is and is not. MCP is the standard Anthropic introduced in 2024 for connecting a model to tools and data. It is a discovery and invocation layer, not a payment rail. As the practitioners building on it put it, MCP carries discovery and invocation while the payment protocols carry settlement, authorization and identity. So when someone searches for a payment MCP server, what they actually want is a server that publishes payment actions (charge a card, send a stablecoin, issue a refund) as MCP tools an agent can call, with a real settlement protocol doing the money movement behind the tool.

How do AI agents pay through MCP

The flow is the same across every MCP payment server, and it is worth knowing because it shows exactly where control is missing. First, discovery: the agent calls tools/list on the MCP server to see the payment tools available. Second, invocation: the agent calls tools/call with the tool name and arguments, for example a charge amount and a customer. Third, authorization: the settlement protocol takes over, whether that is an EIP-3009 signature for a stablecoin transfer, a scoped card token, or a user-signed mandate. Fourth, settlement: the money moves on the designated rail, on-chain or over card networks, and the tool returns a result. The important thing to notice is that steps one through four verify that a call is well-formed and a credential is valid. Not one of them checks whether this agent, at this moment, was allowed to spend this much.

The production MCP payment servers

Several payment companies now run official MCP servers. Stripe operates a remote MCP server at mcp.stripe.com, which we walk through end to end in our Stripe MCP server guide. Its own docs list 14 MCP tools, including create_refund, get_stripe_account_info, get_balance_summary and documentation search, plus generic stripe_api_read and stripe_api_write tools that reach 60-plus supported API methods across customers, charges, payment intents, invoices, subscriptions, disputes, payouts, Issuing and Treasury. Coinbase ships an x402 MCP example that paywalls a tool by returning HTTP 402: the agent wallet signs a stablecoin authorization and retries the call, and settlement confirms on-chain before the tool result comes back. Coinbase also publishes a Payments MCP installer and an AgentKit MCP extension that turn on-chain actions like USDC transfers and swaps into discoverable tools. PayPal and Shopify both publish official servers as well, with Shopify spanning storefront, admin and agent surfaces. There is also a provider-agnostic open-source layer, PayMCP, for adding a per-call price or a subscription gate to any MCP tool, now with a native x402 mode. The point of listing them is not to recommend one; it is that each one answers how an agent pays, and none answers how much an agent should be trusted to pay.

How payment protocols compose on top of MCP

Because MCP only carries the tool call, a settlement protocol has to ride on top. Four patterns dominate in 2026. With x402, the server returns a 402 inside the tool call and the agent wallet signs a stablecoin transfer to unlock the result, which suits high-frequency machine payments for APIs and compute (a natural fit for metered API access, and the model behind paying per tool call). x402 is no longer a single-vendor experiment either: it now sits under the Linux Foundation, with Coinbase, Cloudflare, Stripe, AWS, Google, Shopify, Visa and Mastercard behind the x402 Foundation. With the Agentic Commerce Protocol, a shared payment token is passed as a tool argument and a card processor authorizes it. With the Universal Commerce Protocol, MCP discovers a capability profile and the checkout journey happens separately. With AP2, a user-signed mandate is attached to the tool arguments for non-repudiation. Stripe and Tempo also shipped the Machine Payments Protocol, whose session model lets an agent pre-authorize a spending limit and stream micropayments. These are complements to MCP, not replacements for it.

The spend-control gap MCP payments leave open

Here is the gap every published MCP payments guide skips. None of them meaningfully address spend limits, approval workflows, per-agent budgets, velocity caps or what happens when a wallet or key is compromised. The best current advice is to hand agents a restricted API key rather than a full one, and that advice is correct. Stripe says as much in its own MCP docs: use restricted API keys to limit an agent to exactly the functionality it requires, keep those keys in a secrets vault rather than in code, and enable human confirmation of tools, because chaining several MCP servers together opens the door to prompt injection. A restricted key does limit which tools an agent can call and which resources it can touch. But scope is not a budget. A restricted key that can create charges can create a charge for one dollar or ten thousand dollars, and can do it once or five hundred times in a loop. The MCP server will faithfully execute every well-formed call. So a protocol-compliant, correctly authorized MCP payment can still be a purchase you never wanted, made by an agent that retried a failed call, misread a quantity, or was steered by prompt injection.

How Agentspay governs MCP agent spend

Agentspay is the rail-neutral control plane that sits in front of whichever MCP payment server and settlement protocol moves the money. Instead of handing an agent a restricted key that can spend without a ceiling, you give each agent its own funded wallet with hard limits. Every intended payment is checked against policy before a credential exists: per-transaction ceiling, budget over a window, merchant or counterparty allowlist, velocity rules. Spend above your threshold pauses for a human approval instead of going through. What the agent receives is a scoped virtual card or delegated credential valid for that one purchase, and every call lands in an immutable audit trail tied to the agent, its human owner, the intent and the policy that allowed it. Keep Stripe, x402 or a card token for settlement, and add one place that never lets a tool call move money without policy.

Whatever standard moves the money, Agentspay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Side by side

Production MCP payment servers in 2026

What each server exposes to an agent, and how the payment is authorized underneath.

MCP server What it exposes to agents How the payment authorizes
Stripe MCP (mcp.stripe.com) 14 MCP tools plus stripe_api_read and stripe_api_write across 60-plus API methods: refunds, payment intents, invoices, subscriptions, customers. OAuth for interactive use, or a restricted API key as a bearer token for agents.
Coinbase x402 MCP Tools paywalled behind an HTTP 402 response. Agent wallet signs an EIP-3009 stablecoin authorization, settles on-chain.
Coinbase Payments MCP and AgentKit On-chain actions such as USDC transfers and swaps, as discoverable tools. Wallet-signed on-chain transactions.
PayPal and Shopify Official servers; Shopify spans storefront, admin and agent surfaces. Card and account authorization via the provider.
PayMCP (open source) A provider-agnostic per-call price or subscription gate on any MCP tool, with an x402 mode. Delegated to the configured payment provider.
Buy-side spend limits None of the above enforce a per-agent budget. Left to you: a control plane must gate the call.

Frequently asked

Questions people ask about MCP Payments

What are MCP payments?

MCP payments are payments an AI agent makes by calling a payment tool exposed over the Model Context Protocol. MCP handles tool discovery and invocation, while a settlement protocol such as x402, the Agentic Commerce Protocol or a card token authorizes and moves the money underneath. The agent lists tools, calls a payment tool, and the settlement layer completes the charge.

Is MCP a payment protocol?

No. MCP, the Model Context Protocol, is a standard for connecting a model to tools and data; it is a discovery and invocation layer, not a payment rail. Payment protocols like x402, ACP, AP2 and the Machine Payments Protocol compose on top of MCP to handle authorization and settlement. MCP carries the tool call; the payment protocol carries the money.

How do AI agents pay through MCP?

An agent calls tools/list to discover a payment tool, then tools/call to invoke it with arguments like an amount. A settlement protocol then authorizes the payment through a signature, a scoped token or a signed mandate, and the money settles on-chain or over card rails before the tool returns a result. MCP standardizes the call, not the spending decision.

What is the Stripe MCP server?

The Stripe MCP server is a remote Model Context Protocol server at mcp.stripe.com that exposes 14 MCP tools to AI agents, plus generic read and write tools reaching 60-plus Stripe API methods across refunds, payment intents, invoices, subscriptions and customers. Agents authenticate with OAuth for interactive use, or with a restricted API key as a bearer token for autonomous use.

Can an MCP server process payments?

Yes, indirectly. An MCP server exposes payment actions as tools, but the actual charge is authorized and settled by a payment protocol or processor behind the tool, such as Stripe, an x402 stablecoin transfer or a card token. The MCP layer executes any well-formed call it receives, which is why a spend-control layer is needed to decide which calls should run.

How do you control how much an MCP agent can spend?

A restricted API key limits which tools an agent can call, but not the amount or frequency, so it is not a budget. To control spend you need a policy layer in front of the payment tool that enforces a per-transaction ceiling, a budget over a time window, a counterparty allowlist and velocity caps, and that pauses for human approval above a threshold before any credential is issued.

Keep reading

More explainers

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy