AgentsPay

Explainer

Concur AI and Concur Joule Agents with Concur MCP Spend Controls

SAP Concur is putting Joule agents into the expense report itself this year: one builds the report, one audits receipts before submission, and an AI approval assistant reaches US approvers in Q4 2026. Outside agents connect through Microsoft 365 Copilot or the Concur API. We read every OAuth scope SAP publishes for Concur to see where an agent's dollar limit would live. It is not in the scopes and it is not in the approve call.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Concur AI is SAP's set of Joule agents and machine-learning features inside Concur Expense, Travel and Intelligent Audit. SAP runs no first-party Concur MCP server: on 6 October 2026 mcp.concur.com and mcp.concursolutions.com did not resolve, and the "Concur MCP" servers in search results are third-party connectors built on the Concur API. That API publishes 108 OAuth scopes. 47 grant more than read access, 25 of those touch expenses, receipts, cards, budgets, invoices, payments or travel booking, and none carries an amount, limit or threshold. The approve endpoint takes five fields and no amount, and its short form accepts a company-level token with no named approver. Concur's dollar ceilings live in workflow rules and audit. A per-agent spend limit has to sit outside Concur.

What Concur AI and Concur Joule agents do with money in 2026

Joule is SAP's AI assistant and agent platform, and in 2026 it reached SAP Concur in three waves. At SAP Concur Fusion on 17 March 2026, SAP announced the Expense Automation Agent, which acts as a virtual delegate that creates the expense report, adds card transactions and fills in custom fields from context and the user's history, and the Expense Pre-Submit Audit Agent, which checks receipts and flags discrepancies before the report is submitted. Both sit in SAP's Early Adopter Care program, are sold through Joule Premium for Travel and Expense, and are expected to reach general availability later in 2026. The employee still reviews and submits.

The second wave reaches the approver. At GBTA in August 2026, SAP announced an AI-assisted approval manager that ranks expense reports by risk, highlights unusual patterns and missing context, and gives approvers the evidence for a decision. SAP plans it for US English-speaking customers with both Joule Premium and Concur Expense starting in Q4 2026, and describes it as decision support. The approver still clicks approve.

The third wave is the audit layer that already runs. The Receipt Analysis Agent became generally available in Q4 2025 inside ExpenseIt, and an AI-generated receipt checker in Verify is expanding into Concur Intelligent Audit during 2026. And employees can now create and submit reports, upload receipts and book travel from inside Microsoft 365 Copilot through the Joule integration, without opening Concur.

Is there a Concur MCP server

Not from SAP. On 6 October 2026 we checked the obvious hosts. mcp.concur.com, mcp.concursolutions.com and mcp.sap.com all returned NXDOMAIN, meaning the names do not exist. On the US API gateway, us.api.concursolutions.com, every MCP and OAuth discovery path we tried (/mcp, /.well-known/oauth-protected-resource, /.well-known/oauth-authorization-server, /.well-known/openid-configuration, /.well-known/agent-card.json) returned the same 161-byte 404 as a randomly generated control path. Nothing is listening there.

The servers that rank for "Concur MCP" are third-party connectors. The best known is CData's, whose open-source version describes itself as read-only and points to CData Connect AI for full create, update and delete access. Hobby projects on MCP directories wrap the same Concur REST API. Whichever you pick, the permissions an agent ends up with are the Concur OAuth scopes and user role behind the connector, which is why the scope list is the thing to read.

SAP's own route for outside AI is agent-to-agent. Microsoft 365 Copilot talks to Joule, and Joule acts in Concur. SAP has said A2A support across Joule Studio is arriving through 2026.

How we read the Concur API scopes

SAP publishes the Concur developer documentation as a public GitHub repository, SAP-docs/preview.developer.concur.com. On 6 October 2026 we cloned it at commit bc7d693 (last changed 2 October 2026) and extracted every OAuth scope name the API reference mentions, then removed one false positive from a code sample. Anyone can repeat this in two commands.

The control came first. The same reference documents 946 distinct field names, and 62 of them are about amounts, currencies, limits or budgets: approvedAmount, claimedAmount, amountNotApproved, approverAdjustedAmount, totalApprovedAmount, dailyLimitAmount, cardTransactionAmount. Concur models money in detail, so a search for money in its permission model is not looking in a place that never talks about money.

Then the scopes. There are 108. Concur names them by object and action, so .read is read only, .write is read and write, .writeonly and .delete are what they say. 47 grant more than read access. 25 of those touch money: expense reports, receipts, card accounts and transactions, cash advances, budget items, exchange rates, mileage, invoice payment confirmations, purchase requests, travel requests and travel booking. Not one scope name contains an amount, a limit, a threshold or a currency.

The Concur approve call has no amount in it

The scope that matters most for agents is expense.report.workflowstatus.write. Concur's Workflows v4 reference says it lets an application approve or send back a report with a PATCH to /expensereports/v4/reports/{reportId}/approve.

The request body has five optional fields: comment, expenseRejectedComment, expectedStepCode, expectedStepSequence and statusId, which defaults to approved. None is an amount, a ceiling or an approver identity. The two step fields are a safety check that the report is still on the step you expect, which is a good design for race conditions and says nothing about money.

The access rule is the detail a controller should read twice. The reference says the short approve and send-back URLs, the ones without a user ID or context, support the company-level access token, and tells you to use the short form when the report sits in a system step. The long form takes a user token in the MANAGER context. So an integration holding a company token and this one scope can advance reports through the system steps it is placed on, and an integration acting as a manager can approve whatever that manager can approve. In both cases the ceiling is wherever your workflow puts the step, never a number the agent carries.

Where the dollar limit sits for a Concur agent

Concur is strong on controls for people and reports. Workflow rules can route a report to an extra approver above an amount, expense type limits flag or block entries over policy, cost-object approvers see the approved amount per cost center, and Intelligent Audit and Verify catch receipt problems before reimbursement. Configure all of that before any agent goes near Concur. These are real ceilings on reports.

What none of them gives you is a ceiling on the agent. A Joule agent acting as an employee's delegate builds reports with that employee's authority. An integration acting as a manager approves within that manager's workflow position. A company-level token with the workflow scope advances any report in the system step it is attached to. There is no per-agent monthly total, no lower per-transaction cap for software, and no count of how many reports one integration approved this week.

The larger gap is outside Concur entirely. Concur governs money after it becomes an expense: a card swipe, a receipt, a report. An agent that books travel, renews a subscription or pays for API calls spends first and creates the expense later. SAP's Amex virtual card integration, available to select US customers and planned for all Amex Corporate and Business customers in Q3 2026, gets the card data into Concur faster. It does not stop the purchase.

A rollout checklist for Concur AI agents that touch spend

  1. Grant scopes by object, not by convenience. Concur's scopes are granular, so use that. A reporting agent needs expense.report.read, not expense.report.readwrite, and almost no agent needs expense.report.workflowstatus.write.
  2. Never give a company-level token the workflow scope unless the step is designed for it. If an external validation step exists for an agent, put amount-based routing before it so large reports reach a person first.
  3. Connect user-context agents as low-authority users. An agent acting as a manager inherits that manager's approval position. Create a dedicated approver for the agent with the narrowest scope of reports.
  4. Keep Intelligent Audit and expense type limits strict. They are the controls that still fire when the submitter or approver is software.
  5. Count what each agent approves. Export approvals by actor weekly. Concur gives you the per-report amount, not a running per-agent total.
  6. Put agent purchases behind a payment layer before they become expenses. A wallet or virtual card per agent, a monthly budget, a merchant allowlist and an approval threshold on the amount.

How AgentsPay fits alongside SAP Concur

AgentsPay does not replace Concur. Keep Concur as your system for expense reports, travel policy, audit and reimbursement. AgentsPay governs the agent before money moves: each agent gets its own wallet and identity, a hard per-agent spend limit that totals across the month, a per-transaction ceiling, an approval threshold that pauses for a named person, and scoped virtual cards locked to the merchants you allow. Every decision lands in an audit trail you can match against Concur at close.

The limit is a stored number checked before authorization, and an agent cannot edit its own policy. That is the piece a delegate token and a workflow scope cannot supply.

If you are costing the Concur side, our SAP Concur pricing breakdown covers the per-report plans and what Joule Premium adds. The same measurement for the rest of the SAP estate is in SAP Joule agents, and the closest Concur rivals are covered in Navan AI and Expensify agents and Coupa AI and Coupa MCP.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the Concur and SAP hosts returned on 6 October 2026

Unauthenticated requests with a randomly generated control path on each host. Repeatable by anyone.

Request Response What it proves
mcp.concur.com, mcp.concursolutions.com, mcp.sap.com NXDOMAIN No first-party Concur MCP host exists
us.api.concursolutions.com /mcp 404, 161 bytes Nothing serves MCP on the US API gateway
us.api.concursolutions.com OAuth and OpenID discovery paths 404, 161 bytes No published MCP authorization metadata
us.api.concursolutions.com /.well-known/agent-card.json 404, 161 bytes No A2A agent card on the API host
Random control path on the same host 404, 161 bytes Identical to the paths above, so they are genuinely absent
developer.concur.com, same paths 404 on all, same as control No discovery files on the developer portal either

Original research

The 108 Concur OAuth scopes, read 6 October 2026

From SAP's public Concur developer documentation repository at commit bc7d693.

Measure Count or examples Carries a dollar limit
Distinct OAuth scopes documented 108 No
Scopes granting more than read 47 No
Of those, touching money 25, including expense.report.readwrite, cards.transaction.writeonly, cashadvance.write, budgetitem.write, invoice.paymentconfirmation.write, purchaserequest.write, travel.trips.booking.write No
Approval scope expense.report.workflowstatus.write, approve or send back No
Fields in the approve request 5: comment, expenseRejectedComment, expectedStepCode, expectedStepSequence, statusId No
Control: money fields in the same reference 62 of 946, such as approvedAmount, claimedAmount, dailyLimitAmount Yes, as data, never as a permission

Controls today

What limits a Concur agent, and what it misses

The Concur controls to configure first, and the gap each one leaves when the actor is an agent.

Control What Concur provides What it does not cover for agents
Workflow rules Route reports above an amount to an extra approver An agent in a manager or system step inherits that step's reach
Expense type limits Flag or block entries over policy Per entry, with no per-agent monthly total
Intelligent Audit and Verify AI and auditor review of receipts and reports Runs after the spend has happened
OAuth scopes 108 granular scopes by object and action No amount, limit or threshold in any scope
Joule agents Delegate builds the report, employee submits The delegate carries the employee's authority
Purchases before they are expenses Not in scope for Concur Bookings, renewals and API spend need a payment layer

Across the series

Where each platform puts the dollar limit for agents

From our dated measurements of each vendor's public documents and specifications.

Platform Governs which actions Governs how much money
SAP Concur API (6 Oct 2026) Yes, 108 granular scopes Workflow rules per report, none per agent, no amount in approve
Coupa MCP (5 Oct 2026) Yes, the connecting user's role Approval limits per person, two MCP scopes
Expensify Agents (2 Oct 2026) Yes, prompt and workspace role Approval limit per report, none per agent
Navan MCP (2 Oct 2026) Yes, inherits the user role No amount scope or field
SAP Joule (26 Sep 2026) Yes, SAP roles No limit in the agent layer
AgentsPay Yes Per-agent budget, per-transaction ceiling, approval threshold

Frequently asked

Questions people ask about Concur AI and Concur Joule

Does SAP Concur use AI?

Yes. SAP Concur uses AI in ExpenseIt receipt capture, the Receipt Analysis Agent, Verify and Intelligent Audit, and through Joule agents. The Expense Automation Agent builds reports and the Expense Pre-Submit Audit Agent checks receipts before submission. An AI-assisted approval manager is planned for US customers in Q4 2026.

What is Joule in Concur?

Joule is SAP's AI assistant and agent platform, and in Concur it powers agents that create expense reports, add transactions and audit receipts before submission. It also connects Concur to Microsoft 365 Copilot, so employees can submit reports and book travel without opening Concur. The Concur agents are sold through Joule Premium for Travel and Expense.

Does Concur have an MCP server?

SAP does not run a first-party Concur MCP server. On 6 October 2026 mcp.concur.com and mcp.concursolutions.com did not resolve, and the US API gateway returned 404 on every MCP path. The Concur MCP servers available are third-party connectors, such as CData's, built on the Concur REST API and its OAuth scopes.

What is Concur Intelligent Audit?

Concur Intelligent Audit is SAP's audit service for expense reports, combining machine learning with human auditors to check receipts and policy compliance before reimbursement. SAP is expanding its AI-generated receipt checker into Intelligent Audit during 2026. It is priced on request, not on a public list.

Can Joule approve expense reports in Concur?

Not on its own today. SAP's AI-assisted approval manager, planned for Q4 2026, ranks reports by risk and gives approvers context, but the approver makes the decision. Software can approve through the Concur API using the expense.report.workflowstatus.write scope, either as a manager or in a system step.

Can an API integration approve Concur expense reports?

Yes. The Workflows v4 approve endpoint lets an application holding expense.report.workflowstatus.write approve or send back a report. The short URL accepts a company-level token and is meant for system steps, and the long URL takes a user token in the manager context. The request carries no amount or limit.

How much does Joule cost in Concur?

SAP sells the Concur agents through Joule Premium for Travel and Expense and does not publish its price. In SAP's AI Units catalog the Concur Expense Automation Agent was listed as non-billable in September 2026. Concur itself starts at 7 dollars per report on the Base plan.

Can I connect Microsoft Copilot to Concur?

Yes. SAP integrates Joule with Microsoft 365 Copilot, so employees can create and submit expense reports, upload receipts, check status and book travel from Microsoft applications. Copilot works with the employee's own Concur permissions, so the controls that apply are that user's role and your workflow rules.

How do I limit what an AI agent can approve in Concur?

Limit the scope, the step and the person. Grant only read scopes unless approval is essential, put amount-based workflow routing before any step an agent can act on, and connect user-context agents as a dedicated low-authority approver. For money an agent spends before it becomes an expense, add a payment layer with a per-agent budget.

Is the SAP Concur API read-only?

No. Of the 108 OAuth scopes SAP documents for Concur, 47 grant write, write-only or delete access, including expense reports, card transactions, cash advances, budget items, purchase requests and travel booking. Scopes are granted per application, so an integration can be kept read-only if you choose its scopes carefully.

Keep reading

More explainers

Coupa AI and Navi

Coupa AI and Coupa Navi

Coupa's Navi agents moved from answering questions to running payment batches this year, and since the September 2026 release Microsoft Copilot and custom agents can read and write Coupa data through MCP. We probed the Coupa MCP authorization servers on six live US tenants to see where the dollar limit sits for an outside agent. It is not in the token.

Read

Navan and Expensify

Navan AI and Expensify

Navan and Expensify both opened their travel and expense data to AI assistants this summer, and both are moving from answering questions to acting on reports. Expensify Agents can already submit, approve, reject and route expense reports. Navan says write tools for approving expenses and booking travel are next. We measured where the dollar limit sits for those agents, and in the agent itself it does not sit anywhere.

Read

HubSpot Breeze

HubSpot Breeze

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Read

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy