AgentsPay

Explainer

Zendesk AI Agents and Zendesk AI Agents Advanced, Automated Resolutions and Refund Controls Measured

Zendesk AI agents now do more than answer. With AI Agents Advanced they run generative procedures that call your APIs, cancel Shopify orders and issue refunds while the customer is still in the chat. Zendesk bills you per automated resolution. Nobody bills you for the refund, and that is the number worth controlling.

Agent Payments Console

Pick an agent

Payment intent

intent: ▌

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

AgentsPay

single-use

Wallet budget

spent of

Audit trail

In short

Zendesk AI agents can take real actions, including cancelling and refunding Shopify orders, through prebuilt and custom actions inside generative procedures. Zendesk tells teams to mark write actions such as refunds as agent-approved in auto assist, but the customer-facing AI agent documentation describes no refund amount field or threshold. On 29 September 2026 the Zendesk MCP server, hosted per account at /api/mcp, published exactly two OAuth scopes: read and write. The dollar ceiling on an AI refund therefore lives in your procedure text or in the API behind the action, not in Zendesk.

What Zendesk AI agents are in 2026, and which parts can move money

Zendesk sells three AI products that people lump together as "Zendesk AI agents", and they carry very different authority.

AI agents (Essential) are included in every Suite and Support plan. They answer from your help center and hand off to a human. They do not touch money.

AI Agents Advanced is the former Ultimate product Zendesk acquired in 2024. It adds generative procedures, scripted dialogues, authorized actions and API integrations. A procedure is written in plain language, and you can insert actions, API integrations, parameters and links to other procedures into it. That is how an AI agent looks up an order, cancels it and refunds it without a person in the conversation. Zendesk opened a new actions experience to customers who bought AI Agents Advanced on or after 10 March 2026.

Copilot with auto assist sits beside your human agents at 50 dollars per agent per month. It suggests the next step, including actions, and the human clicks accept. The distinction matters: auto assist has a person in the loop by design, and the customer-facing AI agent does not.

For refunds specifically, Zendesk ships prebuilt Shopify actions that look up an order, cancel and refund an entire order, or refund selected items. Anything else, such as a Stripe refund, a store credit in your own billing system or a goodwill payout, is a custom action pointed at an API you choose.

How we measured the Zendesk MCP server

On 29 September 2026 we probed Zendesk with no account and no credentials, the same way anyone can repeat it. Zendesk does not run a shared MCP host. Each account gets its own server at https://<subdomain>.zendesk.com/api/mcp, so we tested three subdomains, including Zendesk's own help center at support.zendesk.com, and one subdomain made of random characters that belongs to nobody.

For each we requested the MCP endpoint itself, sent a real JSON-RPC initialize call, fetched the OAuth protected resource document at /.well-known/oauth-protected-resource/api/mcp, fetched the authorization server metadata, and sent randomly generated control paths under /.well-known/. The control paths are what keep a probe honest: several payment companies we measured earlier run catch-all servers that answer 200 to anything.

The MCP endpoint returned 401 with a JSON error body on every subdomain. The response carried a zendesk-service: zendesk-end-user-mcp header and no WWW-Authenticate header, so a client has to know the protected resource location in advance rather than being pointed to it. The protected resource document returned 200 with scopes_supported set to exactly ["read", "write"]. Random control paths returned 404, so the server is not a catch-all.

One result needs care. The random, unregistered subdomain returned the same protected resource document with its own hostname filled in. The document is generated from the hostname, so its existence proves nothing about whether an account exists. We only report what it says, not who it belongs to.

Two scopes, read and write, and what that means for an AI agent

The Zendesk MCP server publishes two scopes. read covers what an assistant can see. write covers everything it can change. There is no separate scope for updating a ticket versus deleting one, for editing help center articles, or for anything that touches an order. The authorization server supports dynamic client registration, PKCE with S256, the authorization code and refresh token grants, and token_endpoint_auth_methods_supported of none, which means public clients such as Claude Desktop, ChatGPT or Cursor can register themselves.

That is a reasonable design for a helpdesk. The MCP server itself does not issue refunds, because Zendesk does not hold your money: Shopify, Stripe or your billing system does. The practical point is narrower. When a support lead asks "can we give the assistant write access but only for tagging tickets?", the answer at the scope level is no. Write is one switch.

The money risk arrives from the other direction. Zendesk announced an MCP client at Relate in May 2026 and opened early access in June. It lets Zendesk's own AI agents call out to other MCP servers, and Zendesk names Stripe among them. In our measurement of payment MCP servers the Stripe MCP tool surface is one generic stripe_api_write that covers any POST, including refunds. Connect those two and a customer-facing AI agent has a path to your payment processor that no Zendesk setting caps by amount.

Where the refund limit lives in Zendesk AI agents

We read Zendesk's documentation on actions for auto assist and action flows, actions in AI agents, generative procedures, and the Shopify cancel and refund recipe. Here is what governs an AI refund today.

Approval in auto assist. Zendesk says actions that write data, "such as an action that refunds an order, should be marked as agent-approved so that an agent can validate the action before it's executed." Pre-approved actions run with no approval. If the same action appears twice in a procedure with mixed settings, it defaults to agent-approved. This is a real control, and it only exists because a human agent is in the conversation.

No amount field. The Shopify recipe tells the procedure to "cancel the order and calculate refund costs" and to refund shipping on a full cancellation. It contains no dollar threshold. The action settings we read offer pre-approved or agent-approved, not "approved below 100 dollars".

Customer-facing AI agents. The AI agents actions documentation describes adding actions to dialogues and procedures and notes that action flows in AI agents do not consume action credits. It describes no approval step and no amount limit. In practice a ceiling is either a sentence in the procedure ("only refund orders under 150 dollars"), which is an instruction to a language model, or a check you build into the API the custom action calls.

Rate, not value. Custom actions allow bursts of up to 280 executions, then 6 per second. That is a throughput limit on your API, not a refund budget.

The gap is the same one we found at Salesforce Agentforce and AWS AgentCore: the platform governs which actions an agent may take, and leaves how much money those actions move to you.

Zendesk automated resolutions, and the cost Zendesk does not bill

Zendesk bills AI agents per automated resolution: a request the AI agent resolved with no escalation to a human, confirmed by a separate language model check. Zendesk's billing article lists included resolutions of 5 per agent per month on Team plans, 10 on Growth and 15 on Professional and Enterprise. The allocation expires annually. When it runs out you choose between allowing overage, billed monthly, or pausing the AI agent. Zendesk says the overage rate is higher than the committed rate. Its pricing page, read 29 September 2026, lists Suite Team at 55 dollars and Suite Professional at 115 dollars per agent per month billed yearly, but prints no per-resolution rate. Third-party reviews widely report about 1.50 dollars committed and 2.00 dollars pay-as-you-go. We break the math down in our Zendesk AI agent pricing guide.

Notice what the meter counts. A resolution that ends in a 400 dollar refund costs about 2 dollars on the Zendesk invoice. The 400 dollars never appears there. And a refund is the quickest way to close a refund request without a human, which is exactly what the meter rewards. None of that makes Zendesk wrong. It means the resolution fee is the small, capped number, and the refund value is the large, uncapped one. Our AI agent cost breakdown shows the same pattern across vendors.

Zendesk is retiring API tokens, so plan the refund integration on OAuth

Zendesk is removing API tokens as an authentication method. The 30-day inactivity rule started on 28 July 2026. From 27 October 2026 accounts can no longer create new API tokens, and on 30 April 2027 the remaining tokens stop working. Any custom action, middleware or script that an AI refund flow depends on should be built on OAuth from the start.

That change is a good moment to separate duties. The OAuth client your AI agent uses to read tickets should not be the same credential that can move money in Shopify or Stripe. Put the refund behind its own service with its own policy, and let the agent ask that service rather than hold the payment key.

A rollout checklist for Zendesk AI agents that issue refunds

  1. Start refunds in auto assist, not the customer-facing agent. Mark every refund action agent-approved. Watch a month of suggestions before you let anything run unattended.
  2. Write the ceiling into the API, not only the procedure. A procedure sentence is guidance to a model. A check in the service the action calls is a rule.
  3. Set a per-refund cap and a daily total. A per-refund cap alone allows an unlimited number of small refunds, which is how a looping or manipulated agent leaks money.
  4. Refund only to the original payment method and never above the order total. That keeps a refund from turning into a payout to a new destination.
  5. Route anything above your threshold to a person. Tie the number to your average order value, so routine refunds flow and the unusual ones surface.
  6. Keep write scopes narrow. Give MCP write access only to the people and assistants that need it, and do not connect a payment MCP server to a customer-facing agent without a policy layer in between.
  7. Log the decision with the ticket. Record the agent, ticket, order, amount, rule applied and approver, so a refund audit does not start from a processor export.

How AgentsPay fits alongside Zendesk

AgentsPay does not replace Zendesk, Shopify or Stripe. It sits between the AI agent's action and the money. Your Zendesk custom action calls AgentsPay instead of calling the refund API directly, and AgentsPay applies the policy you set for that agent: a per-refund ceiling, a daily and monthly total, a counterparty and order match, and an approval threshold that pauses larger refunds for a one-tap human decision. The agent's credentials cannot change that policy.

Every refund lands in an audit trail tied to the agent and the ticket. The same controls cover goodwill credits and store credit. For the general pattern, see our AI agent refunds use case, and for the approval mechanics, human approvals for agent payments. You keep Zendesk's resolution meter for what it measures well, and add a spend limit for the part it was never built to measure.

Whatever standard moves the money, AgentsPay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Original research

What the Zendesk MCP endpoints returned, probed 29 September 2026

Unauthenticated requests to three account subdomains plus one random, unregistered subdomain, each with randomly generated control paths.

Request Response What it proves
POST <subdomain>.zendesk.com/api/mcp (initialize) 401 JSON error, header zendesk-service: zendesk-end-user-mcp Live MCP server per account, no shared host
WWW-Authenticate on the 401 Absent Clients must find the protected resource document themselves
/.well-known/oauth-protected-resource/api/mcp 200, scopes_supported read and write Two scopes cover every tool
Same document on a random, unregistered subdomain 200, same content with that hostname Generated per hostname, proves nothing about an account
/.well-known/oauth-authorization-server/api/mcp/oauth 200, registration endpoint, PKCE S256, auth method none Public clients can self-register
/.well-known/(random control path) 404 Not a catch-all server

Controls today

What governs an AI refund in Zendesk

From Zendesk help center articles on actions, AI agents and the Shopify refund recipe, read 29 September 2026.

Control Auto assist (Copilot) Customer-facing AI agent (Advanced)
Human approval before a refund Yes, if the action is marked agent-approved No approval step documented
Refund amount threshold None in action settings None in action settings
Where a ceiling can live Procedure text plus the human Procedure text or your own API
Prebuilt refund actions Shopify: cancel and refund order, refund items Same, plus custom API actions
Throughput limit Bursts of 280, then 6 per second Same custom action limit

The two meters

What a refund resolution costs you, and what Zendesk bills

Included resolutions from Zendesk's billing article. Per-resolution rates are third-party reports, since Zendesk prints none on its pricing page.

Item Who bills it Capped by
Automated resolution Zendesk, about 1.50 to 2.00 dollars Allocation, or pausing the AI agent
Included resolutions Zendesk, 5, 10 or 15 per agent per month by plan Expires annually
The refund itself Your processor, full order value Nothing in Zendesk
Goodwill credit or store credit Your billing system Nothing in Zendesk

Across the series

Where each platform puts the dollar limit for agents

From our dated measurements of each vendor's public documents and specifications.

Platform Governs which actions Governs how much money
Zendesk AI agents (29 Sep 2026) Yes, actions and approval flags No amount field
Salesforce Agentforce Yes, topics and actions No spend field
AWS AgentCore Payments Yes One optional per-session USD cap
Microsoft Agent 365 Yes, identity and access No monetary properties
AgentsPay Yes Per-agent budget, per-transaction ceiling, approval threshold

Frequently asked

Questions people ask about Zendesk AI agents

What are Zendesk AI agents?

Zendesk AI agents are the automated agents in Zendesk that answer customers on messaging, email and voice. The Essential version answers from your help center and is included in every Suite and Support plan. AI Agents Advanced adds generative procedures, scripted dialogues and API actions, so the agent can look up, change, cancel or refund orders during the conversation.

What is Zendesk AI Agents Advanced?

AI Agents Advanced is the upgraded tier built from Ultimate, which Zendesk acquired in 2024. It adds goal-oriented generative procedures, scripted dialogues, authorized actions and API integrations with your own systems. It is the tier that lets an AI agent act, for example by refunding a Shopify order, rather than only answering questions.

Can Zendesk AI agents issue refunds?

Yes. Zendesk ships prebuilt Shopify actions to cancel and refund an entire order or refund selected items, and custom actions can call any refund API, such as Stripe or your own billing system. In auto assist Zendesk recommends marking refund actions agent-approved. The documentation describes no dollar threshold for refunds in either product.

How do I limit how much a Zendesk AI agent can refund?

Enforce the limit outside the language model. Point the refund action at a service that checks a per-refund cap, a daily total and the original order amount before calling Shopify or Stripe, and pauses anything larger for a human. A sentence in the procedure helps the model behave, but it is guidance, not a rule.

What is a Zendesk automated resolution?

An automated resolution is the unit Zendesk bills AI agents on: a customer request the AI agent resolved with no escalation to a human, confirmed by a separate language model check. Plans include 5, 10 or 15 per agent per month depending on tier, and the allocation expires annually. Beyond it you allow overage or pause the AI agent.

How much do Zendesk AI agents cost?

Zendesk AI agents are included in every plan and billed per automated resolution beyond the included allocation. Zendesk's pricing page lists Suite Team at 55 dollars and Suite Professional at 115 dollars per agent per month billed yearly, with Copilot at 50 dollars. It prints no per-resolution rate, and third-party reviews report about 1.50 dollars committed and 2.00 dollars pay-as-you-go.

Does Zendesk have an MCP server?

Yes. Each Zendesk account has its own MCP server at https://your-subdomain.zendesk.com/api/mcp, authenticated with OAuth. On 29 September 2026 its protected resource document listed two scopes, read and write, and its authorization server supported dynamic client registration with PKCE, so Claude, ChatGPT and Cursor can connect as public clients.

What is the Zendesk MCP client?

The MCP client is the reverse direction: it lets Zendesk's own AI agents call tools on other MCP servers, such as Asana, Sentry or Stripe. Zendesk announced it at Relate in May 2026 and opened early access in June. Connecting a payment MCP server this way gives a customer-facing agent a path to your processor, so add an amount policy first.

Is it safe to connect Claude or ChatGPT to Zendesk?

For reading and drafting, generally yes, because the assistant inherits the permissions of the user who connects it. The caution is that write is a single scope, so an assistant with write access can change anything that user can change. Keep write access to the people who need it and review what the assistant does in the ticket audit log.

When do Zendesk API tokens stop working?

Zendesk is retiring API tokens in phases. A 30-day inactivity rule started on 28 July 2026, accounts cannot create new API tokens from 27 October 2026, and all remaining API tokens stop working on 30 April 2027. Build refund actions and middleware on OAuth now.

Do Zendesk AI agent actions need human approval?

Only where a human is present. In auto assist you mark each action pre-approved or agent-approved, and Zendesk recommends agent-approved for anything that writes data, such as a refund. Customer-facing AI agents run the actions in their procedures during the conversation, and the documentation describes no separate approval step.

Zendesk AI agents vs Intercom Fin for refunds, which is safer?

Both can issue refunds through integrations, and neither prices the refund value itself. The safer setup is the one where the refund runs through a service with a per-refund cap, a daily total and a human threshold, whichever helpdesk you use. Pick the helpdesk on channels and resolution pricing, and put the money control in a separate layer.

Keep reading

More explainers

Brex AI Agents

Brex AI agents

Brex made the opposite bet to Ramp. Its MCP server lets Claude, ChatGPT or Cursor read almost everything in your Brex account and change almost nothing that matters for money. The Brex API is a different story: the same company publishes endpoints that create spend limits, issue cards and send wires. Which of those two doors your AI agent walks through decides what it can spend.

Read

Ramp AI Agents

Ramp AI agents

Ramp has built the most complete spend model for AI agents of any finance platform we have measured: agent identities, agent roles, agent cards, and funds with real dollar limits. That is exactly why the permission question matters here more than anywhere else. The limits are real, so the question is who can change them, and on Ramp the answer can include the agent.

Read

SAP Joule

SAP Joule

SAP Joule is moving from answering questions to acting inside S/4HANA, Ariba and Concur, which means SAP AI agents now sit one function call away from purchase orders and supplier payments. SAP publishes the developer tooling for Joule Studio on npm, so we downloaded it and asked the question a controller asks before an agent goes live: where does the dollar limit go? The answer is that SAP models money in great detail one layer down, and the Joule layer on top carries none of it.

Read

UiPath Agentic Automation

UiPath Agentic Automation

UiPath ships more agent governance than almost any vendor we have measured. It has a policy engine, four enforcement actions including human approval, and consumption metering accurate to a fraction of a unit. So we downloaded both SDKs UiPath publishes and asked the one question a finance lead asks before an agent goes live: can any of it be given a number in dollars? The answer is specific, and it is not the answer the word "budget" suggests.

Read

Workday AI Agents

Workday AI Agents

Workday now registers AI agents the way it registers employees, in the Agent System of Record, and more than 65 partners are wiring their agents into it. We downloaded the API specification Workday publishes for that registry to answer the question a CFO asks before any agent goes live: where is the spending limit? Workday's documents carry plenty of money controls. The agent record carries none.

Read

Oracle AI Agent Studio

Oracle AI Agent Studio

Oracle AI Agent Studio is included with every Oracle Fusion Cloud subscription, and it now lets a finance team build agents that call any REST API or MCP server. We read the API specification Oracle publishes for those agents to answer the question a controller asks before switching one on: what stops an agent spending money? Inside Fusion, quite a lot. Outside Fusion, nothing in the agent model does.

Read

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

AI procurement agents

AI Procurement Agents

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy