AgentsPay

Explainer

Workato MCP and Workato Genies Spend Controls for Workato Agent Studio Agents

Workato now sells itself as the control and execution plane for enterprise AI agents: Genies built in Agent Studio, more than 80 prebuilt MCP servers, and an MCP Gateway in front of all of them. Several of those servers can refund a Stripe charge, authorize a Xero bill or submit a Coupa requisition. We read Workato's own documentation on 9 October 2026 to find where a dollar limit lives.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Workato MCP is Workato's hosted Model Context Protocol layer: prebuilt and custom MCP servers that let Claude, ChatGPT or a Workato Genie act in business apps, governed by an MCP Gateway. The gateway limits tool calls per hour or month, not dollars. Across 8 prebuilt finance and commerce servers we counted 33 write tools, and only Coupa's runs a budget check before submitting.

What Workato MCP and Workato Genies are in 2026

Workato started as an integration platform, and the recipes that move data between Salesforce, NetSuite and Slack are still the engine. On top of that engine Workato has built three agent products. Agent Studio is where you build a Genie, Workato's name for an AI agent, and give it skills, knowledge bases and a chat interface in Slack, Teams or Workato GO. Workato Genies are the prebuilt ones: the docs list an EDI Genie, IT Support Genie, License Genie, CPQ Genie and Rep Genie. And Workato MCP turns any recipe or skill into a tool that an outside model such as Claude or ChatGPT can call, with a registry, a runtime and a gateway to manage them.

That last part matters for finance. An MCP server is a door from a language model into a system of record. When the system is Stripe, QuickBooks Online, Xero or Coupa, the door opens onto money. So the useful question for a controller is not whether Workato can connect an agent to the ledger. It clearly can. The question is what stops the agent when the amount is wrong.

Integration engineers connecting business apps to AI agents on a large monitor

We counted the write tools in Workato's prebuilt finance MCP servers

Workato publishes its documentation as plain Markdown with an index file, docs.workato.com/llms.txt, that lists 4,340 pages. On 9 October 2026 we pulled the 82 prebuilt MCP server pages from that index and read the eight that touch money: Stripe Billing Operations, QuickBooks Online AP and Expenses, QuickBooks Online Billing and AR, Xero AP and Expenses, Xero Billing and AR, Coupa Approval Operations, Coupa Procurement and Receiving, and Shopify Orders and Fulfillment.

Together they expose 74 tools. We counted a tool as a write when it changes state, meaning anything that is not a get, search, list or resolve. That leaves 33 write tools, including refund_payment, cancel_subscription and accept_dispute on Stripe, create_bill and authorize_bill on Xero, record_payment and create_credit_note on Xero billing, approve_approval on Coupa, and cancel_order on Shopify. Workato's own example prompt for the Stripe server is "Issue a partial refund of $50 for charge ch_987654321."

Then we looked for a ceiling. Seven of the eight servers document no amount limit of any kind. The exception is Coupa Procurement and Receiving, which has a budget_enforcement project property with three settings, block, advisory and off, defaulting to block. It checks a purchase request against Coupa's own budgets before submitting. That is a real control and worth turning on, but it is a Coupa budget, not a limit on the agent, and it does not exist on the Stripe, QuickBooks, Xero or Shopify servers.

The Workato MCP Gateway limits tool calls, not dollars

Workato's answer to "how do we govern all of this" is the MCP Gateway, which enforces authorization, captures audit data and applies rate limits and usage quotas across every server. Two lines in the docs define what it can and cannot do.

First, "No rate limits or usage quotas are enforced on requests to your MCP server by default." You add them per server. Second, the unit is the tool call. Workato's example quota is a monthly limit of 1,000,000 tool calls, after which all requests are blocked until the quota resets. A rate limit throttles calls per hour.

Neither unit knows what a call is worth. A quota of 100 tool calls a day lets an agent issue 100 refunds of 5 dollars or 100 refunds of 5,000 dollars, and both look identical to the gateway. Verified user access is the other strong control here: tools run under the calling user's own identity, so an agent cannot reach further than the person who connected it. That bounds which accounts it can touch. It does not bound the amount. For what each of those tool calls costs in Workato credits, see our Workato pricing breakdown.

What Workato Agent Studio guardrails cover

Agent Studio has a real guardrails panel, in beta, and it is aimed at content and data. Prompt Attack and Harmful Content detection are always on and set to low, medium or high sensitivity. PII detection is optional and comes with credit card numbers, bank account numbers, Social Security numbers, passwords and API keys switched on by default, handled by block, redact, tokenize or log-only. You also get up to 10 custom regex patterns, a custom word filter of up to 100 words and up to 30 denied topics per Genie.

Notice how a card number is treated. Guardrails see it as sensitive data to hide from the model, which is right. Nothing in the panel treats it as a payment instrument with a budget. We ran a word count across Workato's 138 Agent Studio pages (136,448 words) for money vocabulary and found 87 hits, mostly sample invoices and data lookups, and no setting for an amount, a currency or a spending budget on a Genie.

The control worked. The same scan over Workato's own 16 Stripe connector pages, just 3,346 words, found 119 money hits, about 56 times the density. Workato documents money in detail where the subject is money. On the agent side the absence is the design, not a gap in the test.

Where approvals live in Workato Genies

Workato does give you a human in the loop, and it is well built. Business approvals in Agent Studio, also in beta, let a skill write a request to a data table, notify a named approver and wait for an approve or reject inside Slack, Teams or Workato GO before the operation runs. Workato's example is provisioning access to an application. The License Genie goes further, with a user, manager and admin tier and a full audit trail of decisions before it reclaims a seat.

What the business approvals page does not contain is a threshold. We searched it for amount, threshold and limit and found none of the three. Whether a 40 dollar request and a 40,000 dollar request both wait for a person, or neither does, is logic the skill builder writes into each recipe. Ten skills built by ten teams give you ten definitions of "large".

Finance manager approving a request in a chat app on a phone at her desk

What a finance team adds before a Workato Genie can spend

Before a Genie or an MCP client gets a tool that refunds, pays or orders, a controller will ask for controls that sit outside the tool and that the agent cannot rewrite:

  • A per-agent budget per day and per month, cumulative across every server and skill the agent can reach, not per tool.
  • A per-transaction ceiling, so one confused run cannot refund a whole invoice or approve a bill ten times its usual size.
  • One approval threshold that applies the same way in every skill, so amounts over a set number always wait for a person.
  • Counterparty rules for approved vendors, customers and categories, checked before the call rather than reconciled after.
  • An audit record that ties each payment to the agent, the prompt, the rule applied and the approver.

A job description that says "never refund more than 500 dollars" is advice to a model, and a model can be argued out of advice. That is why we treat AI agent governance and spend policy as separate layers, and why the policy has to answer before the tool runs.

How AgentsPay works alongside Workato MCP

Keep Workato as the place you build Genies, host MCP servers and connect your apps. AgentsPay sits where the money leaves. Each Genie or MCP client that can spend gets its own AgentsPay identity, a hard per-agent budget and per-transaction cap, vendor and category rules, and approval thresholds that route larger amounts to a person in Slack or by email. Every decision lands in an exportable audit trail.

The wiring is one step in the skill. Before the action that refunds, pays or submits, call AgentsPay with the agent, amount and counterparty, and continue only on an approval. When the payment is by card, the agent receives a scoped virtual card with the limit built in, so the limit holds even if the prompt is hijacked. The same policy covers agents outside Workato, which matters when your teams also run watsonx Orchestrate, Copilot Studio or a vendor's own QuickBooks MCP server.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

Workato prebuilt MCP servers that move money, read 9 October 2026

From docs.workato.com. A write tool is any tool that is not a get, search, list or resolve.

MCP server Tools Write tools Amount limit documented
Stripe Billing Operations 12 5, incl. refund_payment, cancel_subscription, accept_dispute None
QuickBooks Online AP and Expenses 7 1, record_expense None
QuickBooks Online Billing and AR 8 2, create_invoice, send_invoice None
Xero AP and Expenses 7 4, incl. create_bill, authorize_bill, void_bill None
Xero Billing and AR 14 9, incl. record_payment, create_credit_note, void_invoice None
Coupa Approval Operations 6 4, incl. approve_approval, reject_approval None
Coupa Procurement and Receiving 14 5, incl. create_requisition, submit_requisition budget_enforcement, default block, checks Coupa budgets
Shopify Orders and Fulfillment 6 3, incl. cancel_order, fulfill_order None
Total 74 33 1 of 8 servers

Control test

Money vocabulary in Workato's own documentation

Same regex (amount, currency, budget, spend, price, cost, payment, invoice, purchase, billing, charge, refund) on each set of pages.

Documentation set Pages Words Money hits Hits per 1,000 words
Agent Studio and Genie building 138 136,448 87 0.6
Workato Genies (prebuilt) 17 13,282 11 0.8
MCP platform (gateway, registry, runtime) 26 29,301 6 0.2
Control, Stripe connector 16 3,346 119 35.6

Comparison

What Workato governs and what it leaves to you

Workato controls from its documentation, next to the spend controls a finance team needs.

Control Workato AgentsPay
Which apps and accounts an agent reaches Yes, verified user access and OAuth Uses your existing access
Tool call rate limits and monthly quotas Yes, per MCP server, off by default Not needed
Prompt attack, harmful content and PII guardrails Yes, in beta Not in scope
Human approval step Yes, business approvals in beta, no amount threshold Yes, by amount, per agent
Per-agent daily and monthly dollar budget No Yes
Per-transaction cap No (Coupa budget preflight only) Yes
Scoped virtual card per agent No Yes

Frequently asked

Questions people ask about Workato MCP and Workato Genies

What is Workato MCP?

Workato MCP is Workato's enterprise Model Context Protocol platform. It turns recipes and skills into MCP servers, offers more than 80 prebuilt servers for apps such as Stripe, Xero, Coupa and Salesforce, and runs them through a registry, a hosted runtime and an MCP Gateway that handles authorization, audit data, rate limits and usage quotas.

What are Workato Genies?

Workato Genies are AI agents built in Workato Agent Studio. Workato ships prebuilt Genies for specific jobs, including an EDI Genie, IT Support Genie, License Genie, CPQ Genie and Rep Genie, and you can build custom Genies with your own skills, knowledge bases and chat interfaces in Slack, Microsoft Teams or Workato GO.

What is Workato Agent Studio?

Agent Studio is the part of Workato where you build and manage Genies. You give a Genie a job description, skills built from Workato recipes, knowledge bases and guardrails, then publish it to a chat interface. Skills called by a Genie are included in its Genie action for billing, while skills called over MCP bill as Tasks.

Can I connect Claude or ChatGPT to Workato MCP servers?

Yes. Any MCP-compatible client can connect to a Workato MCP server, and Workato documents OAuth 2.0 so each user authenticates with their own identity. Tools then run with that user's permissions in the underlying app rather than a shared service account. Usage is billed as the underlying asset, for example Tasks for skills.

Does Workato MCP have spending limits?

Not in dollars. The MCP Gateway can limit tool calls per hour and per month, and no limits apply until you add them. Of the 8 prebuilt servers we read that touch money, only Coupa Procurement and Receiving checks a budget, and it checks Coupa's budgets rather than a cap on the agent.

Can a Workato Genie issue a Stripe refund?

Yes, through the Stripe Billing Operations MCP server or a skill built on the Stripe connector. Its refund_payment tool issues a full or partial refund for a captured payment, and Workato's own example prompt is a 50 dollar partial refund. The server documents no maximum amount, so a cap has to come from a policy you add.

Do Workato Genies support human approval?

Yes. Business approvals, in beta, let a skill pause, write the request to a data table and ask a named approver to approve or reject in Slack, Teams or Workato GO. The License Genie adds user, manager and admin tiers. There is no built-in amount threshold, so each skill decides which requests need a person.

Are Workato Agent Studio guardrails enough for payments?

They solve a different problem. Agent Studio guardrails block prompt attacks, filter harmful content, mask PII such as card and bank account numbers, and stop denied topics. They do not hold a budget, a per-transaction cap or an approval threshold, which is what a payment needs before it leaves the company.

How much does Workato MCP cost?

Workato bills MCP as the asset the server invokes, converted into Workato credits. A skill called over MCP bills one Task per action step, and a proxy to a third-party MCP server bills per proxy call. Self-service Workato Pro starts at 75 dollars a month for 2,500 credits; enterprise editions are quoted. See our Workato pricing breakdown for details.

How do I cap what a Workato agent can spend?

Put a policy check in the skill before the action that moves money. Have the skill call a spend control service such as AgentsPay with the agent, amount and counterparty, and continue only on approval. AgentsPay holds the per-agent budget, per-transaction cap, vendor rules and approval threshold where the agent cannot change them.

Keep reading

More explainers

IBM watsonx Orchestrate

IBM watsonx Orchestrate

IBM sells watsonx Orchestrate as the control plane for every AI agent in the enterprise, and its agents now call tools, run flows and talk to other agents over MCP and A2A. We downloaded the developer kit IBM published on 7 October 2026 and read every agent and flow model in it, looking for one thing: where a dollar limit would go.

Read

Amex Agentic Commerce

American Express Agentic Commerce

American Express launched its Agentic Commerce Experiences (ACE) developer kit and Amex Agent Purchase Protection on 14 April 2026. It is the first card network to write "how much can be spent" into the agent's purchase intent and to promise a credit when a registered agent buys the wrong thing. We checked every public Amex host for the specification, an MCP server and discovery files on 7 October 2026. Here is what is actually live, and what a business still has to add before it lets agents spend.

Read

Concur AI and Joule

Concur AI and Concur Joule

SAP Concur is putting Joule agents into the expense report itself this year: one builds the report, one audits receipts before submission, and an AI approval assistant reaches US approvers in Q4 2026. Outside agents connect through Microsoft 365 Copilot or the Concur API. We read every OAuth scope SAP publishes for Concur to see where an agent's dollar limit would live. It is not in the scopes and it is not in the approve call.

Read

Coupa AI and Navi

Coupa AI and Coupa Navi

Coupa's Navi agents moved from answering questions to running payment batches this year, and since the September 2026 release Microsoft Copilot and custom agents can read and write Coupa data through MCP. We probed the Coupa MCP authorization servers on six live US tenants to see where the dollar limit sits for an outside agent. It is not in the token.

Read

Navan and Expensify

Navan AI and Expensify

Navan and Expensify both opened their travel and expense data to AI assistants this summer, and both are moving from answering questions to acting on reports. Expensify Agents can already submit, approve, reject and route expense reports. Navan says write tools for approving expenses and booking travel are next. We measured where the dollar limit sits for those agents, and in the agent itself it does not sit anywhere.

Read

HubSpot Breeze

HubSpot Breeze

HubSpot Breeze agents now resolve tickets, recommend leads and, through agent tools and the HubSpot MCP server, write carts, orders, quotes and line items. HubSpot meters what the agents cost you in HubSpot Credits, with an account cap and per-feature caps. It does not meter what they spend or commit on your behalf, and that gap is what this page measures.

Read

Intercom Fin

Intercom Fin

Intercom Fin no longer just answers questions. Through Fin Procedures and data connectors it looks up a Stripe subscription, cancels it and issues the refund while the customer is still typing. Intercom charges you 99 cents for that outcome. The refund itself can be any amount, and that is the number worth putting a limit on.

Read

Zendesk AI Agents

Zendesk AI agents

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Read

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy