Glossary · Protocols and standards

Agent Payments Protocol (AP2)

AP2 is an open protocol for agent-initiated payments. Signed mandates prove what a user authorized, and it can run as an extension of A2A.

The Agent Payments Protocol (AP2) is an open protocol for securing payments that an AI agent makes for a user, using cryptographically signed mandates as evidence of what the user authorized.

Origin and status. Google announced AP2 in September 2025 and developed it with payments and technology companies. In April 2026 Google released version 0.2 on GitHub and announced that it is donating AP2 to the FIDO Alliance.

How it works (v0.2). AP2 defines roles: the shopping agent, the credential provider that supplies payment credentials, the merchant, the merchant payment processor, the network and issuer, and a trusted surface, which is the interface where the user gives consent. It defines two mandate types, each secured as an SD-JWT:

  • Checkout Mandate: proves to the merchant that the agent may buy one specific checkout. It is bound by hash to a checkout JWT that the merchant signs.
  • Payment Mandate: proves to the credential provider, network and payment processor that the agent may pay for that checkout.

In Human Present mode, the user sees and approves the final checkout. In Human Not Present mode, the user approves “open” mandates with constraints, such as a price limit or timing. The agent later signs “closed” mandates that must satisfy those constraints. The merchant returns a checkout receipt and the payment processor returns a signed payment receipt. Mandates and receipts serve as evidence in disputes.

Version note. The September 2025 launch materials described Intent, Cart and Payment Mandates. The v0.2 specification defines Checkout and Payment Mandates with open and closed forms. When you read about AP2, check which version the text describes.

Relation to A2A. The AP2 documentation describes the protocol as an extension for A2A and for the Universal Commerce Protocol (UCP). AP2 does not define catalog or checkout APIs. It works as a security layer inside a commerce protocol. For crypto payments, Google and partners launched an A2A x402 extension alongside AP2.

Neighbouring terms. x402 handles payment at the request level. An A2A extension is the mechanism AP2 uses to plug into A2A agents.

Questions

Does AP2 move money?
No. AP2 defines signed evidence of what a user authorized. Existing payment methods such as cards, bank transfers and stablecoins still move the money, and merchants, credential providers and networks verify the AP2 mandates.
How does AP2 relate to x402?
They work at different levels. AP2 proves what a user authorized an agent to buy. x402 carries a payment request and payment inside an HTTP, MCP or A2A exchange. Google's AP2 launch included an A2A x402 extension for stablecoin payments.

Sources

  1. Google Cloud: Powering AI commerce with the new Agent Payments Protocol (AP2) (16 September 2025) (accessed )
  2. Google: We're donating Agent Payments Protocol to the FIDO Alliance (28 April 2026) (accessed )
  3. AP2 specification v0.2 (accessed )
  4. AP2 documentation: What is AP2? (accessed )