Glossary · Commerce and payments

Spend limit

A cap on how much an agent or payment credential may spend per payment, per period or in total, checked before the payment is authorized.

A spend limit is a cap on how much money an agent, card or other payment credential may spend, per payment, per period or in total, enforced before a payment is approved.

Where limits live. For agent payments, a limit can sit in three places, and they can be combined:

  • In the authorization evidence. AP2 v0.2 open Payment Mandates carry constraints the verifier must evaluate. payment.amount_range bounds a single payment and requires the currency to match. payment.budget caps the running total across payments made under the mandate, used together with payment.agent_recurrence, which limits how often and how many times the agent may reuse it.
  • In the credential. The Agentic Commerce Protocol’s delegated payment token carries an allowance: a maximum amount, a currency, one merchant, one checkout session and an expiry time. Stripe Issuing cards take spending_limits, each an amount over an interval, optionally per merchant category. When limits overlap, the most restrictive one applies, and the check runs before any real-time authorization logic. Visa Intelligent Commerce adds controls that compare each authorization with the instruction the user approved.
  • At the business. The receiving business can apply its own caps, such as a maximum refund an automated channel may grant.

Example. AP2 constraints for a monthly subscription agent, adapted from the specification’s examples:

[
  {"type": "payment.agent_recurrence", "frequency": "MONTHLY", "max_occurrences": 12},
  {"type": "payment.budget", "max": 1000.00, "currency": "USD"},
  {"type": "payment.amount_range", "min": 10.00, "max": 100.50, "currency": "USD"}
]

Per-payment and cumulative limits differ. A per-payment cap is stateless: the verifier checks one number. A budget is stateful. AP2 says evaluating it requires tracking the total of earlier payments under the mandate and adding each approved amount afterwards, so whoever verifies needs a reliable counter. AP2 also bars an agent from presenting a further open mandate until it holds a rejection receipt for the previous one, which stops one approval from funding several checkouts.

Emissar. Emissar’s Mandate module is a proposed scoped, revocable credential stating what an agent may do for a person, including limits. Status: Spec in progress.

Neighbouring terms. Least privilege is the security principle behind spend limits. A Payment Mandate is one place to carry them.

Sources

  1. AP2 specification v0.2 (Autonomous mode) (accessed )
  2. AP2 v0.2: Payment Mandate (constraints) (accessed )
  3. Agentic Commerce Protocol: Delegate Payment API, OpenAPI spec version 2026-04-17 (accessed )
  4. Stripe Docs: Issuing spending controls (accessed )
  5. Visa Intelligent Commerce (Visa Developer) (accessed )
  6. Emissar: Mandate module (accessed )