Agentspay

Explainer

Agentforce Spend Controls: What Salesforce Agentforce Pricing and Flex Credits Do Not Cap

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Agent Payments Console

Pick an agent

Payment intent

intent:

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

Agentspay

single-use

Wallet budget

spent of

Audit trail

In short

Salesforce Agentforce is the agent platform built into the Salesforce Platform, now branded Agentforce 360, and it is billed by consumption: 500 US dollars per 100,000 Flex Credits, with a standard agent action costing 20 credits (0.10 dollars) and a voice action 30 credits (0.15 dollars). Agentforce governs what an agent may do through permission sets, topics and actions, and Digital Wallet reports credit consumption and sends threshold alerts. Neither is a spending limit. We searched the published Salesforce Object Reference for Winter 27 on 16 September 2026 and found 178 standard objects that carry money vocabulary and 41 that carry agent vocabulary, with an intersection of exactly zero. No documented standard object gives an agent a budget, a counterparty rule or an approval threshold, so the spend policy for Agentforce agents is a separate layer you have to add.

The three places Agentforce costs you money, and only two are on the invoice

Agentforce is the agent layer Salesforce built into its own platform, and since the October 2025 rebrand the whole stack is sold as Agentforce 360: the Agentforce Platform itself, Data 360, the Customer 360 applications and Slack, held together by Salesforce metadata, MuleSoft and Data Cloud. For a US enterprise that already runs Sales Cloud or Service Cloud, this is the path of least resistance into production agents, which is exactly why the finance question arrives late.

Money leaves through three doors and they behave very differently. The first is seats, the familiar per-user line that a procurement team already knows how to model. The second is consumption, the Flex Credit meter that runs every time an agent takes an action, and that one is genuinely new: it is not bounded by headcount, it is bounded by agent activity, and agent activity is the thing you are trying to increase. The third door is the one nobody puts in the business case. An Agentforce agent that calls out through a Flow, an Apex callout or a MuleSoft connector can cause a purchase: renew a subscription, top up a balance, release a payment, place an order. That money never appears on a Salesforce invoice at all, because Salesforce is not the one charging you for it.

The first two doors have meters. The third has nothing, and the first two have meters rather than valves. That distinction is the whole subject of this page.

What Agentforce pricing actually looks like in 2026

Salesforce publishes its Agentforce rates openly, which makes this part easy to get right. The figures in the table below were read from the Salesforce Agentforce pricing page on 16 September 2026 and are US list prices. Two models run side by side. The older one charges 2 dollars per conversation, which is simple but punishes a chatty agent that resolves nothing. The newer one charges Flex Credits at 500 dollars per 100,000 credits, which works out to half a cent per credit, and then prices work in credits: a standard Agentforce action is 20 credits, so 10 cents, and an Agentforce Voice action is 30 credits, so 15 cents.

Ten cents an action sounds harmless, and at pilot scale it is. The arithmetic only gets interesting when you multiply by the volume an agent program is supposed to produce. A single agent handling 2,000 interactions a day, at a modest four actions each, is 8,000 actions, which is 160,000 credits a day and 800 dollars a day at list. Run it across a month and you are past 24,000 dollars on one agent. None of that is a criticism of the pricing, which is fair and arguably fairer than per seat. It is an observation about shape: a per-action meter turns a fixed cost into a variable one, and variable costs need ceilings rather than forecasts.

How we measured what Salesforce can express about agent spending

Opinion is cheap here and vendor marketing is worse, so we did what we do on every vendor page: we went to the published schema. Salesforce documents every standard object in the Object Reference, and that document is available as machine-readable JSON in one request. The version we pulled on 16 September 2026 is Winter 27, API version 68.0, document version 264.0, and its table of contents enumerates 1,757 documented standard objects.

The object model is the right place to look, and it is worth saying why. In Salesforce, policy is data. A permission, a limit, a threshold, an approval step, an entitlement: every one of those is a record on an object somewhere, because that is how the platform is built. If no object exists to hold a value, no admin screen, roadmap slide or consultant can make the platform store it. So the question becomes narrow and answerable: does Salesforce document any standard object where the agent vocabulary and the money vocabulary meet.

We ran two vocabulary passes over the full list of 1,757 object names. The agent pass matched GenAi, Agent, Bot, Einstein, Copilot and Robot. The money pass matched Payment, Invoice, CreditMemo, Amount, Currency, Price, Cost, Budget, Spend, Billing, Order, Quote, Refund, Revenue, Fee, Discount, Ledger, Payout, Purchase, Expense, Transaction, Cart, Checkout, Wallet, Card and Tax.

Then, because a regex that finds nothing is usually a broken regex, we ran a control. The control matched neutral Salesforce platform vocabulary, the suffixes and siblings that every mature object family in the platform carries: Definition, Share, History, Feed, Event, Log, Setting and Config. If the agent family were a thin, half-finished corner of the schema, the control would come back nearly empty there and the real finding would be uninteresting.

The result: 178 money objects, 41 agent objects, zero overlap

The money pass matched 178 of the 1,757 objects. Salesforce models money in enormous detail, as you would expect from a company that sells Revenue Cloud: AlternativePaymentMethod, CardPaymentMethod, CreditMemo and CreditMemoLine, Invoice and InvoiceLine, CartItemPriceAdjustment, CartTax, BillingSchedule, BillingPolicy, BillingTreatment, Expense and ExpenseReportEntry, and 160-odd more.

The agent pass matched 41 objects: the GenAi family that actually is Agentforce (GenAiPlannerDefinition, GenAiPluginDefinition, GenAiFunctionDefinition, GenAiPlannerFunctionDef, GenAIConversationSummary), the older BotDefinition and BotVersion, the AgentWork routing family, the ProspectingAgent research family, the RpaRobot family and a handful of others.

The intersection is zero. Not small, not one or two edge cases: no documented standard object name carries both vocabularies. And the control behaved exactly as a working control should. Neutral platform vocabulary matched 11 of the 41 agent objects and 16 of the 178 money objects, so both families are ordinary, fully modelled Salesforce object families with the usual Definition, Share, History and Log siblings. The agent family is not a stub that Salesforce has yet to flesh out. It is a mature family that has no money object in it, which is a design decision rather than an oversight.

Read plainly, that is the finding: Salesforce has 178 ways to describe money and 41 ways to describe an agent, and no way to describe an agent budget.

Digital Wallet tells you. It does not stop you.

The obvious objection is Digital Wallet, and it deserves a straight answer because Salesforce genuinely did build a consumption tool and it is a good one. Digital Wallet shows credit balances and burn rate across consumption products, projects when capacity runs out, and sends threshold alerts by email, commonly configured at 50, 75 and 90 percent, with additional alerting possible through Flow.

Every one of those verbs is a reporting verb. Digital Wallet observes consumption and tells a human about it. It does not hold an action pending, refuse one, or switch an agent off, and Salesforce practitioners have made the same point publicly: there is no kill switch that freezes agents or agent actions when a threshold is hit. So the honest description is a smoke alarm, not a sprinkler. It is genuinely useful, it will save somebody a nasty quarter, and it is not a limit, because a limit is a thing that refuses. An alert that fires at 90 percent on a Friday evening while an agent is looping is a record of the overspend, not a prevention of it.

This is the same pattern we found at every other vendor. The payment MCP servers expose write access to live payment APIs and none enforces a ceiling. The accounting and ERP MCP servers govern which tools a model may call against your books, never the amount. Microsoft Agent 365 governs agent identity and access and expresses no monetary amount anywhere in Graph. Google went furthest of all and shipped a cap that genuinely refuses work, and even there the Gemini Enterprise spend limit is a Cloud Billing budget scoped to a project, with no dimension that can identify which agent spent the money. AWS went furthest and shipped an actual number, and even there AgentCore gives you one optional per-session amount with no daily or monthly total behind it.

What Agentforce permissions genuinely do control

It would be unfair and inaccurate to suggest Agentforce is ungoverned. It is one of the better-governed agent platforms on the market, and the controls are real, so it is worth being precise about what they cover.

An Agentforce agent is scoped by a running user, and that user carries a profile, permission sets and sharing rules, so the agent inherits an object and field level security model that Salesforce has spent twenty years hardening. Topics bound what subjects an agent will engage with. Actions are an explicit allow list: an agent can only invoke the Flows, prompt templates, Apex methods and standard actions you have attached to it. Agent Script constrains behaviour deterministically rather than leaving it to the model. There is built-in observability, and the Einstein Trust Layer handles data masking and grounding.

Every one of those answers the question what may this agent do. None of them answers how much may this agent commit. You can grant an agent an action that releases a payment, and the permission model will faithfully check that the running user is allowed to release payments. It has no opinion about whether this is the fortieth payment in an hour, whether the counterparty is new, or whether the total has passed a number that should require a human. Those are finance questions, and the object model shows there is nowhere in the platform to put the answer.

The second money gap: what the agent buys

The Flex Credit meter is the gap people notice, because it lands on a Salesforce invoice and somebody has to sign it. The larger exposure is usually the one that does not.

Agentforce agents are wired into the rest of the business on purpose. That is the pitch and it is a good one. An agent with a Flow, an Apex callout or a MuleSoft connector can reach a supplier portal, a payables system, an ads platform, a SaaS billing API, a Commerce Cloud order or a metered vendor API. Every one of those is a way to move real dollars, and none of them is measured in credits. If an agent renews an annual contract, tops up an ad account or releases a batch of supplier payments, the Salesforce bill is a few cents of actions and the actual cost is somewhere else entirely.

So the two exposures scale differently and want different controls. Consumption is many tiny charges that add up, and it wants a hard ceiling and a rate limit. Purchasing is a small number of large charges, and it wants a per-transaction cap, a counterparty allow list and a human above a threshold. Digital Wallet is aimed at the first and, being an alerting tool, only partly reaches it. Nothing in Salesforce is aimed at the second, because there is no object for it.

Where a spend policy layer fits on top of Agentforce

None of this argues against Agentforce, and there is no overlap to argue about. Salesforce owns the agent runtime, the data grounding, the permission model and the enterprise context, and no startup is going to do that better. The layer the object model shows is empty is the one in front of the money: the decision about whether a particular payment, at this amount, to this counterparty, at this point in the month, is allowed to proceed.

That is what agent spend controls are for. You keep Agentforce as the platform, keep the permission sets and topics doing what they already do well, and put a policy between your agents and your bank: a budget that actually aggregates across a day, a week and a month rather than resetting per session, a merchant-locked virtual card so an agent authorised to renew one vendor cannot pay a different one, an approval threshold that holds a payment for a named human above an amount you choose, a velocity rule for the looping-agent case, and an audit trail that reconciles to your books in dollars. Because the policy layer is rail neutral it does not care whether the agent pays by card, through an ACP checkout, under an AP2 mandate or over x402.

The practical test for whether you need one is short. If your Agentforce agents only read records, draft replies and update fields, you do not: the credit meter plus Digital Wallet alerting is proportionate and you should stop here. If any agent can cause money to move outside Salesforce, you are relying on a permission check that was designed to answer a different question.

How Agentforce compares with the other agent control planes

Four vendors, four schemas, one pattern. We have now measured the published models of the biggest agent control planes shipped in 2026, using the same method each time, and they converge on the same boundary. Microsoft Agent 365 is agent-aware down to the conditional access vocabulary and expresses no monetary amount at all. AWS AgentCore shipped a real ceiling, one optional per-session USD amount on a session capped at eight hours, with no cumulative total anywhere in the model. Salesforce models money in 178 objects and agents in 41 and keeps them apart. The payment MCP servers hand a model write access to live payment APIs with no ceiling of any kind.

That consistency is the useful part. Four independent engineering organisations, with different architectures and different commercial incentives, drew the same line: the platform governs identity, access and capability, and declines to govern the amount. It is a defensible line, because a finance policy sits badly inside an identity system and even worse inside a CRM permission set. It is also a line, which means something has to sit on the other side of it. For the wider category, AI agent governance covers the control frameworks in general and AI agent payment platforms compares the vendors who do this specific job.

Whatever standard moves the money, Agentspay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Pricing

Agentforce pricing, US list, read from the Salesforce pricing page on 16 September 2026

Two billing models run alongside each other. Flex Credits are the consumption model and the one that behaves like a meter.

Line US list price Unit What triggers the charge
Flex Credits 500 dollars per 100,000 credits Prepaid pack, half a cent per credit
Agentforce action 20 credits, about 0.10 dollars per action Each action an agent performs
Agentforce Voice action 30 credits, about 0.15 dollars per action Each voice action an agent performs
Conversations 2 dollars per conversation Older model, charged per conversation not per action
Agentforce User License 5 dollars per user per month Requires Flex Credits alongside it
Agentforce add-on 125 dollars per user per month Seat-based add-on
Agentforce Industries add-on 150 dollars per user per month Seat-based add-on
Agentforce 1 editions from 550 dollars per user per month Includes the add-on and 2.5M Flex Credits annually

Measured

Salesforce Object Reference, Winter 27, API version 68.0, measured 16 September 2026

Two vocabulary passes over all 1,757 documented standard objects, plus a control pass that proves the method is not blind.

Vocabulary pass Objects matched Examples Reading
Money 178 of 1,757 CardPaymentMethod, CreditMemoLine, InvoiceLine, BillingSchedule, CartItemPriceAdjustment, ExpenseReportEntry Salesforce models money in depth
Agent 41 of 1,757 GenAiPlannerDefinition, GenAiPluginDefinition, GenAiFunctionDefinition, BotDefinition, AgentWork, RpaRobotDefinition Salesforce models agents in depth
Both at once 0 None No standard object joins an agent to an amount
Control: neutral platform vocabulary 11 of 41 agent objects, 16 of 178 money objects Definition, Share, History, Feed, Event, Log, Setting, Config Both families are mature, so the zero is a decision

Side by side

What Agentforce governs and what a spend policy layer adds

An honest split. Agentforce owns the agent, the data and the permission model, and we do not compete on any of that.

Control Agentforce A spend policy layer
Which actions an agent may invoke Yes, explicit action allow list Not our layer, we do not compete here
Object and field level security Yes, profiles, permission sets, sharing Not our layer
Credit consumption visibility Yes, Digital Wallet reporting and forecasting Complements it with dollar-level spend
Alert when consumption passes a threshold Yes, Digital Wallet email alerts Yes
Hard stop when a limit is reached No, alerts do not halt actions Yes, the payment is refused
Budget that aggregates over a day, week or month No standard object exists Yes, per agent, team and cost center
Counterparty or merchant allow list No standard object exists Yes
Human approval above a dollar threshold Approval processes exist for records, not for agent spend Yes, payment held pending a named approver
Velocity rule on repeated charges No standard object exists Yes
Control over money the agent spends outside Salesforce No visibility Yes, this is the point of the layer
Agent runtime, grounding and enterprise context Yes, this is what it is for Not our layer, we do not compete here

Frequently asked

Questions people ask about Salesforce Agentforce

What is Agentforce?

Agentforce is the AI agent platform built into the Salesforce Platform, sold since October 2025 as part of Agentforce 360 alongside Data 360, the Customer 360 applications and Slack. Agents are configured from topics and actions, run as a Salesforce user with that user permissions, ground their answers in your Salesforce data and metadata, and are billed by consumption through Flex Credits rather than purely by seat.

How much does Agentforce cost?

Flex Credits are 500 US dollars per 100,000 credits, which is half a cent per credit. A standard Agentforce action costs 20 credits, about 10 cents, and an Agentforce Voice action costs 30 credits, about 15 cents. The older per-conversation model is 2 dollars per conversation. Seat lines run from a 5 dollar per user per month Agentforce User License, which still requires Flex Credits, up to Agentforce 1 editions from 550 dollars per user per month. Read from the Salesforce pricing page on 16 September 2026.

What are Agentforce Flex Credits?

Flex Credits are Salesforce consumption currency for Agentforce. You buy them in prepaid packs of 100,000 for 500 dollars and agents draw them down as they work, at 20 credits per standard action and 30 per voice action. The model charges for work performed rather than for conversations started or seats owned, which is fairer per unit but turns a fixed cost into a variable one that scales with agent activity.

Can you set a spending limit on Agentforce?

Not as an enforced ceiling. Digital Wallet lets you monitor credit consumption and configure threshold alerts, and permission sets control which actions an agent may invoke, but neither refuses work when an amount is reached. We searched all 1,757 documented standard objects in the Winter 27 Object Reference on 16 September 2026 and found no object that joins an agent to a budget, a cap or a counterparty rule.

Does Digital Wallet stop Agentforce from using credits?

No. Digital Wallet is a monitoring and forecasting tool. It shows balances and burn rate across consumption products and emails threshold alerts, commonly at 50, 75 and 90 percent, with more alerting possible through Flow. It does not hold, refuse or halt an agent action when a threshold is crossed, and Salesforce practitioners have noted publicly that there is no kill switch. It is a smoke alarm rather than a sprinkler.

How many Flex Credits does an Agentforce action use?

A standard Agentforce action uses 20 Flex Credits and an Agentforce Voice action uses 30. At the published pack rate of 500 dollars per 100,000 credits, each credit is half a cent, so a standard action costs about 10 cents and a voice action about 15 cents. Multiple actions usually fire within one user interaction, so model actions rather than conversations when you forecast.

What is the difference between Agentforce per-conversation and Flex Credit pricing?

Per-conversation pricing charges a flat 2 dollars each time a conversation starts, regardless of whether the agent does anything useful. Flex Credits charge per action performed, at 20 credits or about 10 cents each. Flex Credits reward an agent that resolves things efficiently and penalise one that takes many steps, while per-conversation pricing is easier to forecast but pays the same for a resolution and a dead end.

Can an Agentforce agent spend real money?

Yes, indirectly, and this is the exposure that is usually missed. An Agentforce action can call a Flow, an Apex method or a MuleSoft connector, and any of those can reach a payables system, a supplier portal, a billing API, an ads platform or a Commerce Cloud order. Money moved that way never appears on a Salesforce invoice, so credit monitoring will not show it and Digital Wallet cannot see it.

Does Agentforce have a budget per agent?

No. There is no documented standard object that assigns a monetary budget to an agent, a topic or an action. Our pass over the Winter 27 Object Reference on 16 September 2026 matched 178 objects on money vocabulary and 41 on agent vocabulary with an intersection of zero. Because policy in Salesforce is stored as records on objects, an absence in the object model means the value has nowhere to live.

What is Agentforce 360?

Agentforce 360 is the platform branding Salesforce adopted in October 2025 for what was previously called the Salesforce Platform. It bundles the Agentforce Platform, Data 360, the Customer 360 applications and Slack on shared metadata, with MuleSoft and Data Cloud underneath. The 360 release added the Agentforce Builder, Agent Script, Agentforce Voice and Intelligent Context.

Do Agentforce permission sets limit spending?

They limit capability, not amount. An agent runs as a Salesforce user and inherits that user profile, permission sets and sharing rules, so the platform will faithfully check whether the agent is allowed to perform an action. It has no opinion about whether this is the fortieth payment this hour, whether the counterparty is new, or whether a cumulative total has passed a point where a human should sign off.

Is there an Agentforce kill switch?

Not as a consumption control. You can deactivate an agent or revoke its permissions manually, but there is no automatic mechanism that freezes agents or agent actions when a credit threshold is reached, and Salesforce practitioners have flagged this gap publicly. In practice the first hard stop on a runaway agent is a human noticing an alert and intervening, which is why a separate enforcement layer matters.

Do I still need a spend policy layer if I use Agentforce?

It depends on what your agents touch. If they only read records, draft replies and update fields, the Flex Credit meter plus Digital Wallet alerting is proportionate and you do not need anything else. If any agent can cause money to move outside Salesforce, through a Flow, an Apex callout or a MuleSoft connector, then you need a budget that aggregates, a counterparty rule and an approval threshold, and the object model shows Salesforce has nowhere to store any of those.

Keep reading

More explainers

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy