AgentsPay

Explainer

Navan AI and Expensify Concierge Agents with Navan MCP and Expensify MCP Spend Controls

Navan and Expensify both opened their travel and expense data to AI assistants this summer, and both are moving from answering questions to acting on reports. Expensify Agents can already submit, approve, reject and route expense reports. Navan says write tools for approving expenses and booking travel are next. We measured where the dollar limit sits for those agents, and in the agent itself it does not sit anywhere.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Navan AI and Expensify Concierge both connect to Claude, ChatGPT and Cursor through MCP servers that are documented as read-only for data. The agents that act are a separate surface. Expensify Agents, in open beta, can approve reports and send them to Ready to Pay, and on 2 October 2026 we read Expensify's open-source client: the four API types that create or configure an agent carry 18 fields and none is an amount. The limit you give an agent is a sentence such as "approve reports under $1,000". Navan's OAuth server publishes 14 scopes, all of them identity. The enforceable dollar ceilings are Expensify's approval limit on the workflow and a payment layer for anything the agent buys.

What Navan AI and Expensify Concierge can do with money in 2026

Navan AI is the AI layer across Navan's travel and expense platform. Its support agent, Ava, handles a large and growing share of traveler conversations (Navan told investors it reached about 60 percent of customer interactions in a recent quarter, including rebooking and refunds). On 2 July 2026 Navan launched an MCP server that lets Claude, ChatGPT, Cursor, Codex and VS Code query spend, bookings, policies, approval flows and card details in plain English. Navan's launch release calls the first version read-only and names the write tools it is building next: approving out-of-pocket expenses, updating travel policies, and booking travel from inside the assistant.

Expensify has two different AI surfaces and they carry different authority. Concierge is the assistant every user talks to. It answers questions, and on request it creates an expense, changes an amount, marks something non-reimbursable or turns on a workspace rule such as requiring receipts above 25 dollars. The Expensify MCP server, launched 8 June 2026, gives outside assistants one Search tool under a single mcp:tools scope, and Expensify's help center is explicit that it cannot create, edit, approve or reimburse anything.

The third surface is the one finance teams should look at before anything else. Expensify Agents (open beta) and Agent rules are AI members of your workspace that act on reports. They can submit a report, approve it, reject single expenses, put expenses on hold, take over a report as approver, route it to a different approver and export it to QuickBooks, Xero, NetSuite or Sage Intacct. A final approval sends the report to the reimbursement queue as Ready to Pay. That is real authority over real money, and it is configured in English.

How we measured the Navan MCP server

On 2 October 2026 we sent unauthenticated requests to Navan's hosted server with no account, so anyone can repeat this in a terminal. Every probe was paired with a randomly generated control path, because some servers answer every URL with 200 and look like they support everything.

A JSON-RPC initialize posted to https://mcp.navan.com/mcp returned 401 with a WWW-Authenticate: Bearer header pointing at the protected-resource document, and the body -32001 Missing Bearer token. A plain GET to the same path returned 405, which matches Navan's docs: HTTP transport only, no SSE. The control paths returned a 400 gateway error rather than a page, so the host is not a catch-all.

The protected-resource document names login.navan.com as the authorization server and lists scopes_supported as an empty array. The authorization server's own discovery document lists 14 scopes, and every one is an identity claim: openid, profile, offline_access, name, given_name, family_name, nickname, email, email_verified, picture, created_at, identities, phone and address. There is no Navan permission scope at all, and dynamic client registration is open.

That is consistent with how Navan describes the design. The developer docs say the assistant "inherits exactly the permissions Navan has already granted you", bound to your role, entity and region. The docs' own role table lists what each role can change: a Manager can approve or reject reports they own and an Approver can approve, reject or request edits. So the only ceiling on what an assistant connected as a manager can approve is the manager's own authority. Nothing in the token narrows it to an amount.

Navan deserves credit for two things most vendors in our series skip. Every tool call is logged with the user, the MCP client name and version, the exact tool and its arguments, and the response size. And the docs state the server cannot bypass approval workflows, policy rules or duplicate detection.

How we read the Expensify agent API

Expensify's endpoint at www.expensify.com/mcp could not be measured from a server. It returned a 403 bot challenge on every path, including our random control path, which tells you about the firewall and nothing about the server, so we do not draw a conclusion from it.

Expensify gives us something better. The New Expensify client is open source on GitHub, and every call the app makes to Expensify's backend is declared as a typed parameter object. On 2 October 2026 we read the main branch and counted 682 API parameter types.

The control first. 56 of those 682 type names are about money, limits or approvals, and they are precise: SetPolicyAutomaticApprovalLimit, SetPolicyExpenseMaxAmount, SetPolicyCategoryMaxAmount, UpdateExpensifyCardLimit, UpdateTravelBillingMonthlyLimit, SetPolicyPreventSelfApproval. Expensify models spend limits for people in real detail, so the method is not blind.

Then the agents. Four types create or configure an agent or an Agent rule: CreateAgent, UpdateAgentPrompt, AddPolicyAgentRule and UpdatePolicyAgentRule. Between them they carry 18 fields. They are IDs, a first name, an avatar, a workspace ID, a personal-agent flag and one field called prompt. None is an amount, a currency, a limit or an approver. Everything an agent is allowed to do lives in that free-text prompt.

Two more facts from Expensify's own help center finish the picture. A new agent is added as a full-access Copilot on the account of the person who created it (the delegate role has two values, full access and submitter, and agents get the first). And the first time an admin creates an Agent rule, Expensify adds RuleBot to the workspace as a Workspace Admin.

The approval limit is a sentence the model reads

Expensify's capability reference tells you how to phrase instructions. To approve, write "Approve reports under $1,000". To escalate, write "Route reports over $5,000 to the finance manager". With the admin role, "Take over reports over $10,000 regardless of who they were submitted to".

Read those as a controller would. The dollar figure is inside an instruction to a language model. It is not stored as a number, it is not checked by a rule engine before the approval posts, and nothing compares it with what the agent approved yesterday. If a report total is ambiguous, if the currency differs, or if a long expense description talks the model into a different reading, the instruction is what gets interpreted. Expensify itself advises that clear, specific instructions "generally produce more predictable results", which is honest, and it is also the definition of a soft limit.

None of this makes the feature reckless. Expensify's structured workspace rules still run underneath every agent: maximum expense amounts, receipt requirements, category limits and holds that block approval and payment until fixed. Those are real limits on expenses. What is missing is a limit on the agent: a hard amount above which this agent cannot approve whatever its prompt says, and a monthly total it cannot exceed.

Where to put a hard dollar limit on an Expensify agent

There is a structured answer inside Expensify, and it is the first thing to configure. Each approver in a workflow can carry an approval limit with an over-limit approver. In Expensify's data model that is the approvalLimit and overLimitForwardsTo pair on the approver's row: if the report total is above the limit, the next approver is the over-limit person instead of the usual one. Because an agent can be selected anywhere a workspace member can, you can put the agent into the workflow as an approver with, say, a 500 dollar approval limit and a named human as the over-limit approver. Reports above 500 dollars then reach a person before they can be paid, whatever the prompt says.

Know the edges of that control. It is per report, so twenty reports at 499 dollars pass cleanly. It does not total what one agent approved this month. And an agent holding the admin role can be instructed to take over or reroute reports, which changes who sits in the workflow, so keep approving agents out of the Workspace Admin role wherever you can, and review RuleBot's admin seat on purpose rather than by default.

The second edge is the bigger one. Expensify governs money that flows through expense reports. An agent that buys things, books travel, renews software or calls a paid API spends money that never becomes an expense report until after it has left your account. Navan's planned booking tools will put agents into exactly that position for travel.

A rollout checklist for Navan and Expensify agents

  1. Connect MCP as a reader first. Both servers are designed for analysis. Connect them with the narrowest real user who needs the answers, not an admin, because the assistant inherits that person's full authority.
  2. Turn MCP on per workspace or company deliberately. Expensify has a workspace MCP toggle and Navan SSO companies enable MCP under Integrations. Decide who may connect before people start pasting the server URL into Claude.
  3. Put every approving agent behind an approval limit. In Expensify, give the agent an approval limit and a human over-limit approver in the workflow. Treat the dollar figure in the prompt as documentation, not enforcement.
  4. Keep agents out of admin roles. Take over and reroute need admin rights. An approver agent does not need them.
  5. Watch the cumulative total yourself. Export what each agent approved each week. Neither platform gives you a per-agent monthly ceiling.
  6. Put a payment layer in front of anything an agent buys. When Navan's booking tools or any other agent can spend, give it a funded wallet or virtual card with a monthly budget, a merchant allowlist and an approval threshold that fires on the amount.

How AgentsPay fits alongside Navan and Expensify

AgentsPay does not replace Navan or Expensify. Keep them as the system for expense reports, travel policy, reimbursement and your accounting sync. AgentsPay sits in front of the money an agent moves on its own: each agent gets its own wallet and scoped virtual card, a budget in dollars that is cumulative across the month rather than per report, spend controls by merchant and category, approval thresholds that hold a payment for a named person above an amount you set, and an audit trail you can reconcile against Navan or Expensify at close.

The difference is where the number lives. In AgentsPay the limit is a stored value checked before the payment is authorized, and the agent's credentials cannot edit their own policy. A prompt can ask for more. It cannot get it.

We have measured the same gap on the corporate card side. Ramp's agents and MCP server and Brex's AI agents both govern cards for people in depth, and our Expensify pricing per user breakdown covers what the Collect and Control plans cost before you add agents to a workspace.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the Navan MCP endpoints returned, probed 2 October 2026

Unauthenticated requests with randomly generated control paths, repeatable by anyone.

Request Response What it proves
POST initialize to mcp.navan.com/mcp 401, Bearer challenge, -32001 Missing Bearer token Live host, spec-correct OAuth challenge
GET mcp.navan.com/mcp 405 Method Not Allowed HTTP transport, POST only, no SSE
/.well-known/oauth-protected-resource 200 JSON, scopes_supported empty No published permission scopes
login.navan.com OIDC discovery 200, 14 scopes, all identity claims No Navan permission scope exists
Random control paths on mcp.navan.com 400 gateway error Not a catch-all server
Random control path on developer.navan.com 200, the same 15,871 byte app shell Catch-all, so only llms.txt and the MCP guide were counted

Original research

Expensify API parameter types, read from the open-source client 2 October 2026

Expensify/App on GitHub, main branch, src/libs/API/parameters.

Measure Count or examples Carries a dollar limit
API parameter types in the client 682 Some
Types about money, limits or approvals (the control) 56, e.g. SetPolicyAutomaticApprovalLimit, UpdateExpensifyCardLimit Yes, for people and workspaces
Types that create or configure an agent or Agent rule 4 No
Fields across those four types 18 No
Where agent permissions live One free-text field, prompt Only as words
www.expensify.com/mcp from a server IP 403 on every path, control included Inconclusive, bot wall

Controls today

What limits an Expensify agent, and what it limits

From Expensify's help center and data model, read 2 October 2026.

Control What Expensify provides What it limits
Approval limit with over-limit approver Workflow setting, per approver row Each report above the amount
Max expense amount and category limits Workspace rules, flag violations Each expense
Hold on an expense Blocks approval and payment until released That expense
Dollar figure in agent instructions Interpreted by the model Nothing enforced
Monthly total one agent may approve None Nothing
Money an agent spends outside reports None Nothing

Across the series

Where each platform puts the dollar limit for agents

From our dated measurements of each vendor's public documents and specifications.

Platform Governs which actions Governs how much money
Expensify Agents (2 Oct 2026) Yes, prompt and workspace role Approval limit per report, none per agent
Navan MCP (2 Oct 2026) Yes, inherits the user role No amount scope or field
HubSpot Breeze (1 Oct 2026) Yes, scopes and TAKE_ACTION review No amount scope or field
Intercom Fin (30 Sep 2026) Yes, procedures and approval steps Only conditions you write per procedure
Ramp and Brex agents Yes, card and policy controls Card limits for people
AgentsPay Yes Per-agent budget, per-transaction ceiling, approval threshold

Frequently asked

Questions people ask about Navan AI and Expensify

What is Navan AI?

Navan AI is the AI layer across Navan's travel and expense platform. It includes Ava, the support agent that handles traveler requests such as rebooking and refunds, AI expense automation, and since July 2026 a hosted MCP server that lets Claude, ChatGPT, Cursor and other assistants query your Navan travel and expense data in plain English.

Does Navan have an MCP server?

Yes. Navan's hosted MCP server runs at https://mcp.navan.com/mcp over HTTP transport, with no SSE and no local install. Users sign in with their Navan login, and SSO companies must have an admin enable MCP under Integrations first. Navan documents setup for Claude Code, Claude Desktop, Cursor, Codex and VS Code.

Is the Navan MCP read-only?

Navan's July 2026 launch release calls the initial deployment read-only and lists approving out-of-pocket expenses, updating travel policies and booking travel as upcoming write tools. The developer docs say the assistant inherits the user's role, and their role table shows managers and approvers can approve or reject reports, so check what your connected user can do.

What is Expensify Concierge?

Concierge is Expensify's built-in AI assistant. It answers questions about your expenses and settings, troubleshoots problems, and takes actions on request, such as creating an expense, updating an amount, marking an expense non-reimbursable or turning on a workspace rule like requiring receipts above 25 dollars. Separate Expensify Agents handle report approvals.

Does Expensify have an MCP server?

Yes. Expensify launched its MCP server on 8 June 2026 at https://www.expensify.com/mcp. It uses OAuth 2.1 with PKCE and a single mcp:tools scope, and it exposes one Search tool. Expensify documents it as read-only: it cannot create, edit or delete data, approve reports or reimburse payments.

Can Expensify AI agents approve expense reports?

Yes. Expensify Agents and Agent rules, enforced by RuleBot, can approve reports, reject individual expenses, hold expenses, route reports to another approver and export them to accounting. A final approval moves the report to Ready to Pay. The amount an agent may approve is written into its natural-language instructions rather than stored as a limit.

How do I stop an Expensify agent from approving large reports?

Use the structured approval limit, not the prompt. Give the agent an approval limit in the workflow and a human over-limit approver, so any report above the amount reaches a person before it can be paid. Keep the agent out of the Workspace Admin role so it cannot reroute reports around that person.

Can Navan AI book travel for employees?

Navan's Ava agent already handles changes such as rebooking and refunds inside Navan's own support flow. Booking travel from an outside assistant through MCP is one of the write tools Navan announced as upcoming, not part of the read-only launch. When it ships, travel policy will govern the booking, and a separate payment layer is what caps an agent's total.

How much does Expensify cost?

Expensify Collect costs 5 dollars per unique member per month on pay-per-use. Control costs 36 dollars per active member per month on pay-per-use, or 18 dollars per member on an annual subscription, falling to as low as 9 dollars with full Expensify Card usage. Our Expensify pricing per user guide covers the details.

Is it safe to connect Claude or ChatGPT to Expensify or Navan?

For reading data, yes, with sensible care. Both servers use OAuth, inherit your existing permissions and are documented as read-only for data. Connect as a user who only needs to read, turn MCP on deliberately at the workspace or company level, and revoke access you no longer use. Be stricter with agents that approve or buy.

Navan vs Expensify for AI agent controls, which is safer?

Today Navan is more conservative, because its MCP server is read-only and its audit log records every tool call with arguments. Expensify goes further on automation, since its agents approve reports, but it also has the stronger structured control in approval limits with over-limit approvers. Neither sets a monthly dollar ceiling per agent.

Keep reading

More explainers

HubSpot Breeze

HubSpot Breeze

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Read

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy