Glossary · Commerce and payments

Checkout Mandate (AP2)

An AP2 v0.2 credential proving to a merchant that an agent may complete one specific checkout. It replaced the Intent and Cart Mandates of AP2 v0.1.

A Checkout Mandate is the AP2 credential that gives a merchant cryptographic proof that a shopping agent is authorized to complete the checkout it has assembled.

How it works (v0.2). The merchant must give the shopping agent a checkout JWT that the merchant signs. The closed Checkout Mandate, with the vct value mandate.checkout.1, contains that checkout_jwt and a checkout_hash of it. The user approves the mandate on a trusted surface, or, in the autonomous mode, the agent signs it under an open mandate the user approved earlier. The merchant verifies the signature, checks that the hash matches the checkout it created, and evaluates any constraints. Whether it accepts or rejects, the merchant must return a Checkout Receipt. When AP2 is used with the Universal Commerce Protocol, the signed payload must be UCP’s Checkout object.

Open mandates. An open Checkout Mandate (mandate.checkout.open.1) states what the user will accept before a checkout exists. v0.2 defines two constraints: allowed merchants and line items. The line-items rule can be checked as a maximum-flow problem, and the specification notes it does not yet support splitting one open mandate across several checkouts. A simplified open mandate, with the cnf key, timestamps and selective-disclosure structure removed:

{
  "vct": "mandate.checkout.open.1",
  "constraints": [
    {
      "type": "checkout.allowed_merchants",
      "allowed": [{"name": "Demo Merchant", "website": "https://demo-merchant.example"}]
    },
    {
      "type": "checkout.line_items",
      "items": [
        {"id": "line_1", "acceptable_items": [{"id": "SKU-1234", "title": "Gold sneaker, size 9"}], "quantity": 1}
      ]
    }
  ]
}

What it replaced. AP2 v0.1 (September 2025) had two credentials for the merchant side. A Cart Mandate, generated by the merchant and signed by the user, covered purchases with the human present. An Intent Mandate, generated by the shopping agent and signed by the user, covered purchases with the human absent and carried shopping intent, a restatement of the user’s prompt and an expiry. v0.2 (April 2026) folds both into the open and closed forms of the Checkout Mandate. Treat Intent and Cart Mandate as superseded terms, and check which version any AP2 material describes.

Neighbouring terms. The Payment Mandate covers the payment for the same checkout and points to it by the same hash.

Sources

  1. AP2 specification v0.2 (accessed )
  2. AP2 v0.2: Checkout Mandate (accessed )
  3. AP2 v0.1.0 specification (16 September 2025) (accessed )
  4. AP2 release v0.2.0 (28 April 2026) (accessed )