Payment Mandates

last updated 2026-07-21
Agentic PaymentsAgentic PaymentsAgent Identity (KYA)Agent Identity (KYA)x402x402StablecoinsStablecoinsPayment M…

The cryptographic record that a human authorised an agent to spend: what, how much, with whom, for how long. Distinct from moving the money, and distinct from proving which agent is calling. Mandates sit above the rail (x402, cards) and beside identity (Agent Identity (KYA)).

Researched 21 July 2026 (, ref).

The standards, and who owns them

StandardOriginStatus
AP2 (Agent Payments Protocol)Google, Sept 2025Donated to the FIDO Alliance 28 Apr 2026, v0.2 released alongside, adding “Human Not Present” autonomous payments against pre-authorised mandates. Governance now sits with FIDO
Verifiable IntentGoogle + Mastercard, co-donated Apr 2026Tamper-proof log of user-authorised agent actions
ACP (Agentic Commerce Protocol)OpenAI + Stripe, Apache 2.0, Sept 2025Powers ChatGPT commerce. OpenAI withdrew Instant Checkout 5 Mar 2026
UCP (Universal Commerce Protocol)Google + Shopify, launched 11 Jan 2026 at NRFMerchants host JSON profiles at /.well-known/ucp. Checkout, Identity Linking and Order Management live at launch; Cart and Product Discovery added 19 Mar 2026
Visa Trusted Agent ProtocolVisa, Oct 2025Layered on EMV tokenisation. Described by a16z as still in pilot in March 2026
Mastercard Agent Pay / AP4MMastercardAgentic Tokens extending MDES. Agent Pay for Machines launched June 2026

Two things follow from the table.

The mandate primitive has been made a public good by the party best placed to charge for it. Google built AP2 and gave it to FIDO. That removes the most obvious place a startup would have monetised delegated authority.

Google now runs two overlapping stacks. AP2 handles payment mandates, UCP handles the merchant journey including Identity Linking. UCP versus ACP is the one genuine head-to-head in agentic commerce, and OpenAI pulling Instant Checkout in March 2026 leaves ACP looking weaker than the specification suggests.

What a mandate is technically

The W3C Verifiable Credentials pattern applied to spending authority. The user’s wallet issues a credential delegating a bounded authority to the agent’s decentralised identifier; the agent attaches it to the payment; the merchant or rail verifies the signature chain. AP2 v0.2’s “Human Not Present” mode is the interesting extension, since it permits autonomous spend against a mandate signed earlier, which is what makes revocation and expiry load-bearing rather than cosmetic.

The liability hole

Nobody currently carries the risk when a mandate is honoured wrongly.

Mastercard has closed the gap rather than opened one: agent identity and mandates layer on existing tokenisation, liability follows tokenised-transaction rules, the issuer carries fraud where the token was validly issued, and consumer chargeback rights are intact. x402 has no chargebacks, no dispute resolution and no refunds; escrow and refunds are on the roadmap, unbuilt.

That matters for two reasons. It removes the forcing function that would otherwise make somebody buy a mandate-enforcement product by a date. And it leaves enforcement and audit (who checks the mandate, logs it, and takes liability when it is wrong) as the one part of this layer that is not commoditised, not owned by a foundation, and plausibly a recurring-revenue enterprise product.

Why this page is short on companies

companies_using is empty on purpose. The mandate layer is currently specification rather than product, and the companies adjacent to it are doing credential issuance and wallets, which is a payments business. See Agent Identity (KYA) for the funded set, and Agent Identity Value Capture for why it does not clear the investment gate.

Recent mentions

Related concepts

Frontier questions