🎓 CoursesMarkets & internationalAdvanced⏱ 60 min

Preparing for agentic payments. 6 chapters and a final quiz.

The decision course for product managers and architects who see shopping agents coming. Assess a protocol’s real maturity from public evidence, specify an enforceable mandate and the evidence package behind it, wire agent recognition into your site’s front door, defuse the six failures that break an agentic checkout, negotiate liability with your acquirer, cost out an order, then sort the work into no-regret investments and protocol bets.

Chapter 1. Reading a protocol’s real maturity.

The market won’t crown a winning agentic protocol anytime soon, so the useful question is a different one: which protocol can a team spend a quarter of development on without regret? You answer it with public evidence, never with announcements. In one hour, you can check that a dated specification exists, that a license is named, that a change process is written down, and that geographic availability is declared. A press release substitutes for none of those four proofs.

Six proofs to demand before writing the first line of code

  • A versioned, dated specification you can read without an account or a nondisclosure agreement. A marketing page doesn’t count.
  • An explicit license covering the specification text and the reference implementation.
  • A written change process: who proposes a change, who decides, and how quickly.
  • A runnable reference implementation, with a sandbox where you can reproduce a decline, not just a success.
  • Declared geographic availability from the provider that will bill you. It is the criterion most often overlooked outside the US.
  • A documented production transaction, dated and naming both parties. An announced pilot doesn’t qualify.
ProtocolVerifiable publicationLicense and governanceWhat it standardizesWhat it leaves open
ACP (Agentic Commerce Protocol)Dated versions: 2025-09-29, 2025-12-12, 2026-01-16, 2026-01-30, 2026-04-17 (protocol’s GitHub repository, accessed August 2026)Apache 2.0; founding maintainers OpenAI and Stripe; changes made through written proposalsCheckout, delegated payment, product feed, orders, authenticationBroader governance announced but not yet in place
AP2 (Agent Payments Protocol)Announced September 16, 2025; documentation published on ap2-protocol.org (accessed August 2026)Apache 2.0; repository maintained by Google; standards work handed to FIDO Alliance technical groupsThe mandate, signed as a verifiable credential: Checkout Mandate, Payment MandateThe object model has changed since the initial announcement
UCP (Universal Commerce Protocol)Published in January 2026 by Google and Shopify; listed by Stripe as a seller protocol (Stripe documentation, August 2026)Builds on AP2Catalog and cart shared among agents, merchants, and providersHow it fits with ACP on the seller side is left to the provider
x402Public specification; implementation documented by Stripe (August 2026)x402 Foundation, hosted by the Linux Foundation since April 2026Pay-per-request: HTTP status code 402, settlement in stablecoinsNo dispute mechanism, since on-chain settlement is irreversible
Trusted Agent Protocol (Visa)Announced October 14, 2025; specifications on the Visa Developer Center and GitHub (Visa, 2025)Published by Visa with 12 named partners, including Adyen, Checkout.com, Fiserv, Microsoft, Nuvei, Shopify, Stripe, and WorldpayCryptographic signing of agent requests and declaration of intentThe mandate cap and who bears the financial cost of a dispute
Five agentic protocols checked against the public evidence (as of August 2026)

ACP deserves a closer look, because it sets the benchmark: five dated versions in just over six months, each describing a complete state of the specification. You can read the cadence in the repository, not in a keynote, so a team can pin a version, read it end to end, and know exactly what changed in the next one. That is what you should expect from a standard you plug payment collection into.

⚠️
Object models shift, even at the biggest players
AP2 was announced on September 16, 2025, built around a chain of three mandates: intent, cart, and payment. Its reference documentation now describes only two, Checkout Mandate and Payment Mandate, each with two states, open and then closed (ap2-protocol.org, August 2026). The vocabulary of a version 0.x protocol is not a contract. Isolate it behind your own domain objects, or every revision will cost you a database migration.
5 versions
published and dated by ACP between September 29, 2025, and April 17, 2026
protocol’s GitHub repository, accessed August 2026
12
partners named when Visa published its Trusted Agent Protocol
Visa press release, October 14, 2025
+4 700 %
year-over-year growth in AI-referred traffic to US retail sites, as cited in support of the launch
Visa, October 2025
🔑
The decision rule
Build against a protocol when its public proofs are all in place and the provider that bills you offers it in your market. Otherwise, build against your own internal model and connect the protocol through an adapter. That adapter costs far less than reworking a data schema.
🎯 Quick question
Which element best shows that your team can build on an agentic protocol right now?