Davies Meyer – home
    Tech3 min read

    Agent Payments Protocol (AP2)

    The Agent Payments Protocol (AP2) describes how AI-agent purchase and payment authority can be linked in a technically verifiable way. Specification v0.2 uses checkout and payment mandates. AP2 is a component within a commerce process; it replaces neither the store nor the payment provider and does not guarantee general legal compliance.

    Agent Payments Protocol (AP2) explained

    The central question is what was actually authorised. A checkout mandate and payment mandate connect authority to the specific transaction. That differs from a loose chat request to get something suitable. An implementation should make permitted products, spending limits and validity understandable and technically enforceable.

    AP2 distinguishes direct confirmation from action within previously approved constraints. The relevant roles must verify mandates; a model response does not perform that verification. A pilot needs participating systems that support the same protocol version and intended flow. Mentioning AP2 in a product description is insufficient.

    Signatures make certain data changes detectable. They do not prove that a product recommendation is suitable or a payment economically sensible. Repeats, expired authority, changed prices and conflicting responses also need clear handling. Contractual, privacy and payment requirements require separate assessment.

    Creative Engineering designs understandable delegation with effective limits. We take responsibility for the concept and quality. Start with a narrow test case and explicitly test rejection of prohibited actions. Then evaluate correctly completed tasks and total review and operating effort rather than treating autonomous transactions as success in themselves.

    Examples

    Hypothetical application

    A test system orders office supplies within an approved scope. If quantity or total price moves outside that scope, the process stops. The team also checks that repeating a request does not produce a second order.

    Key Points

    • Bind purchase and payment authority to the actual transaction.
    • Have the responsible systems verify mandates.
    • Separate technical evidence from a sound decision and legal assessment.

    Practical application

    Clarify the delegation case, participating systems and authority. In a limited environment, test successful transactions as well as limit breaches, repeats and uncertain responses.

    Useful measures

    Correctly bounded actions

    Check that allowed actions succeed and disallowed ones are actually rejected.

    Unambiguous completion

    Reconcile orders, payment status and errors traceably.

    Total effort

    Assess integration, ongoing verification, exceptions and payment fees together.

    Common mistakes

    • Treating a signature as evidence of a good purchase decision.
    • Describing authority only in a prompt without effective enforcement.
    • Inferring security or savings from the protocol name.

    Sources and context

    Frequently Asked Questions about Agent Payments Protocol (AP2)

    No. It describes a protocol component. Processing and other services come from participating systems and payment providers.

    Loading related terms…

    All Terms