The cryptographic record that a human authorised an agent to spend: what, how much, with whom, for how long. Distinct from moving the money, and distinct from proving which agent is calling. Mandates sit above the rail (x402, cards) and beside identity (Agent Identity (KYA)).
Researched 21 July 2026 (, ref).
The standards, and who owns them
| Standard | Origin | Status |
|---|---|---|
| AP2 (Agent Payments Protocol) | Google, Sept 2025 | Donated to the FIDO Alliance 28 Apr 2026, v0.2 released alongside, adding “Human Not Present” autonomous payments against pre-authorised mandates. Governance now sits with FIDO |
| Verifiable Intent | Google + Mastercard, co-donated Apr 2026 | Tamper-proof log of user-authorised agent actions |
| ACP (Agentic Commerce Protocol) | OpenAI + Stripe, Apache 2.0, Sept 2025 | Powers ChatGPT commerce. OpenAI withdrew Instant Checkout 5 Mar 2026 |
| UCP (Universal Commerce Protocol) | Google + Shopify, launched 11 Jan 2026 at NRF | Merchants host JSON profiles at /.well-known/ucp. Checkout, Identity Linking and Order Management live at launch; Cart and Product Discovery added 19 Mar 2026 |
| Visa Trusted Agent Protocol | Visa, Oct 2025 | Layered on EMV tokenisation. Described by a16z as still in pilot in March 2026 |
| Mastercard Agent Pay / AP4M | Mastercard | Agentic Tokens extending MDES. Agent Pay for Machines launched June 2026 |
Two things follow from the table.
The mandate primitive has been made a public good by the party best placed to charge for it. Google built AP2 and gave it to FIDO. That removes the most obvious place a startup would have monetised delegated authority.
Google now runs two overlapping stacks. AP2 handles payment mandates, UCP handles the merchant journey including Identity Linking. UCP versus ACP is the one genuine head-to-head in agentic commerce, and OpenAI pulling Instant Checkout in March 2026 leaves ACP looking weaker than the specification suggests.
What a mandate is technically
The W3C Verifiable Credentials pattern applied to spending authority. The user’s wallet issues a credential delegating a bounded authority to the agent’s decentralised identifier; the agent attaches it to the payment; the merchant or rail verifies the signature chain. AP2 v0.2’s “Human Not Present” mode is the interesting extension, since it permits autonomous spend against a mandate signed earlier, which is what makes revocation and expiry load-bearing rather than cosmetic.
The liability hole
Nobody currently carries the risk when a mandate is honoured wrongly.
Mastercard has closed the gap rather than opened one: agent identity and mandates layer on existing tokenisation, liability follows tokenised-transaction rules, the issuer carries fraud where the token was validly issued, and consumer chargeback rights are intact. x402 has no chargebacks, no dispute resolution and no refunds; escrow and refunds are on the roadmap, unbuilt.
That matters for two reasons. It removes the forcing function that would otherwise make somebody buy a mandate-enforcement product by a date. And it leaves enforcement and audit (who checks the mandate, logs it, and takes liability when it is wrong) as the one part of this layer that is not commoditised, not owned by a foundation, and plausibly a recurring-revenue enterprise product.
Why this page is short on companies
companies_using is empty on purpose. The mandate layer is currently specification rather than product, and the companies adjacent to it are doing credential issuance and wallets, which is a payments business. See Agent Identity (KYA) for the funded set, and Agent Identity Value Capture for why it does not clear the investment gate.