Google announced the Agent Payments Protocol (AP2) on September 16, 2025, as an open protocol for letting AI agents make purchases while preserving evidence of what the user authorized, what the merchant presented and what payment was completed. On April 28, 2026, Google transferred AP2 to the FIDO Alliance, and AP2 version 0.2 added “Human Not Present” transactions based on instructions approved in advance.
AP2 is not a new card network, wallet or settlement system. It is a security and evidence layer intended to work with existing cards, bank transfers, stablecoins and other payment methods. As of August 18, 2026, its public specifications, samples and partner announcements describe an evolving standards effort—not universal consumer availability at every merchant.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Square Reader for contactless and chip (2nd Generation) | $48.99 | Buy on Amazon |
| 2 |
|
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS | $298.99 | Buy on Amazon |
| 3 |
|
Square Reader for magstripe (with Lightning connector) | $9.88 | Buy on Amazon |
Why AI-agent payments need a different checkout model
Conventional online checkout assumes a person is looking at a merchant’s page, reviewing the final total and clicking a payment button. An autonomous agent breaks that assumption. It may search several stores, select a substitute, encounter a changed price and submit payment without the user seeing the final cart.
That creates three questions that ordinary checkout evidence may not answer:
#1 Best Overall
- Use the, easy-to-use, and customizable POS to get started.
- Accept contactless payments, chip cards, Apple Pay, and Google Pay from anywhere, with improved connectivity, extended battery life, and enhanced security. Pay one low rate for every tap or dip.
- No long-term commitments or contracts, no monthly fees- and with offline payments, keep taking payments for up to 24 hours.
- Safely and securely accepts payments anywhere. Plus, get data security, 24/7 fraud prevention, and payment-dispute management at no extra cost.
- Use the, easy-to-use, and customizable POS to get started.
- Authorization: Did the user give the agent permission to make this purchase?
- Authenticity: Does the request accurately represent the user’s instructions and the final cart?
- Accountability: What evidence exists if the transaction is fraudulent, mistaken or disputed?
Google designed AP2 to connect those facts across the agent, merchant, wallet or payment provider and the completed transaction. The protocol specification describes mandates and receipts that can serve as dispute evidence. AP2 does not, however, guarantee that an AI model understood a natural-language instruction correctly or that a purchase is financially wise.
For example, “buy a laptop under $1,000” leaves unresolved questions about taxes, shipping, refurbished products, substitutions, warranty terms and whether the limit applies before or after discounts. A payment protocol can record the decision; it cannot make an ambiguous instruction precise by itself.
How an AP2 transaction is evidenced
AP2 links a user’s authorization to the cart and then to the payment authorization. The core records are signed so participating systems can check whether the data was altered and retain a transaction trail.
- User authorization: The user permits an agent to act, either for a specific purchase or within stated limits.
- Agent selection: The shopping agent searches products or services and chooses an offer.
- Merchant checkout details: The merchant supplies the cart, price, currency, shipping, taxes and other checkout information.
- Checkout Mandate: Evidence binds the authorized shopping request to the relevant cart or products.
- Payment Mandate: The payment provider or wallet records how that authorized purchase is to be funded.
- Receipt: The completed transaction produces evidence of what was presented, approved and paid.
The AP2 specification explains these flows at ap2-protocol.org. A valid signature demonstrates cryptographic integrity and an authorization record; it does not establish that the agent selected the right item, resisted malicious instructions or complied with consumer-protection law.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Human-present and “Human Not Present” payments
The initial AP2 work focused on agent-assisted purchases in which a person could still review or authorize the transaction. Version 0.2 adds a “Human Not Present” mode for an agent to act after the user has issued sufficiently specific instructions.
A practical example is a ticket agent told to buy up to two seats for a named event, from approved sellers, below a maximum price, during a defined sales window. The user need not be watching the checkout at the instant inventory appears, but the purchase is still based on prior authorization.
Implementations must define the limits that make such a mandate meaningful:
- Maximum amount, currency and quantity.
- Approved merchants, products, geography and timing.
- Rules for substitutions, shipping, taxes and changed prices.
- Expiration, revocation and prevention of replay or duplicate use.
- Responsibility when an agent follows an authorized instruction but the result is unwanted.
Google’s and FIDO’s public announcements establish the feature, but they do not settle every operational or liability question. Merchants, wallets, processors and agent operators will need their own policies and controls.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
AP2 compared with MCP, A2A, UCP and x402
These projects address different layers of an agentic system. Treating them as interchangeable can lead a business or consumer to expect capabilities a protocol does not provide.
Rank #2
- With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
- Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
- Process chip cards in just two seconds.
- Get your money as soon as the next business day.
- Use it cordlessly with the built-in battery, designed to last all day.
| Protocol or system | Primary role |
|---|---|
| MCP | Connects models or agents to tools and external data. |
| A2A | Coordinates communication and tasks between agents. |
| UCP | Covers the wider commerce journey, including discovery, product information, checkout and post-purchase interactions. |
| AP2 | Provides authorization, payment evidence and accountability for agent-led payment flows. |
| x402 | Web-native payment mechanism, particularly relevant to automated machine payments and crypto or stablecoin transfers. |
Google’s Universal Commerce Protocol (UCP) documentation describes AP2 as compatible with the broader commerce workflow: UCP handles more of the shopping journey while AP2 concentrates on trusted payment authorization and evidence. See Google’s UCP overview.
AP2 is payment-agnostic by design. Google describes potential use with credit and debit cards, real-time bank transfers, stablecoins and other methods through compatible providers. Card networks, banks, wallets and processors still perform the actual authorization, movement and settlement of funds. AP2 does not require cryptocurrency. Coinbase’s AP2 and x402 material illustrates one possible stablecoin and machine-payment integration at Coinbase Developer Platform.
What changed when AP2 moved to the FIDO Alliance
On April 28, 2026, Google announced that it was donating AP2 to the FIDO Alliance. Mastercard contributed compatible Verifiable Intent work, and FIDO said it would develop interoperable standards for trusted AI-agent authentication and commerce. The announcement is available from FIDO Alliance.
Recommended Free Tools
The governance change could make AP2 more platform-neutral and credible to merchants, payment companies and identity providers than a standard controlled by one technology vendor. It could also make development slower as more participants negotiate common rules. Businesses should monitor FIDO specifications rather than assuming that an early AP2 integration guarantees compatibility with the eventual standard.
AP2 is part of a crowded field that also includes Mastercard Agent Pay and Verifiable Intent, Visa agentic-commerce initiatives, OpenAI and Stripe’s Agentic Commerce Protocol, x402 and proprietary wallet or processor implementations. The FIDO transfer may encourage convergence, but it does not guarantee that these efforts will become one standard.
Who is involved—and what participation means
For the 2025 launch, Google said more than 60 organizations were participating, naming Mastercard, American Express, PayPal, Coinbase, Adyen, Etsy, Intuit, JCB, Revolut, Salesforce, ServiceNow, UnionPay International, Worldpay, Forter and Ant International among others. The launch announcement is at Google Cloud.
“Participation” can mean specification work, a demonstration, a planned integration, payment-rail support or public endorsement. A logo or quote does not prove that a company offers a generally available AP2 checkout for consumers in a particular country. The public materials do not establish universal merchant acceptance.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What developers can test today
The public repository contains specifications, flow descriptions, demonstrations and code samples. It says its examples use Google’s Agent Development Kit and a Gemini model, although AP2 itself is not limited to those technologies. The repository is at github.com/google-agentic-commerce/AP2.
A responsible evaluation path is:
- Read the AP2 v0.2 specification and identify the mandate and receipt flows relevant to your use case.
- Clone the repository and inspect its dependencies, sample credentials and model assumptions.
- If a sample requires Google Cloud, create the appropriate test project and set the repository’s documented variable, such as
export GOOGLE_CLOUD_PROJECT='your-project-id'. - Install the repository’s sample package using its documented command, currently shown as
uv pip install git+https://github.com/google-agentic-commerce/AP2.git@main. - Run demonstrations only with test data or sandbox payment instruments.
- Before production, add identity verification, secret and token management, idempotency, fraud controls, logging, refund handling, compliance review and a documented liability model.
Those commands are repository-specific examples and may change. Public code demonstrates protocol concepts; it is not a universal merchant activation switch or a guarantee of production readiness.
Rank #3
- Pay one transparent rate per swipe for Visa, Mastercard, Discover and American Express.
- Works in conjunction with most downloadable Square point-of-sale apps on your device. Customers can pay, tip and sign directly on your device. Track payments in cash, gift cards and more. Also lets you send receipts via e-mail or text message, makes it easy to apply discounts, keeps a data and sales history log and more.
- Accepts magstripe credit card payments, including those from Visa, Mastercard, Discover and American Express (fees apply).
- App sends deposits to your bank account within 1 to 2 business days, or enjoy instant deposits (fees apply).
What AP2 could mean for merchants and businesses
The strongest near-term use cases are business infrastructure rather than a consumer app: shopping agents, procurement, automatic software-license scaling, travel and event reservations, replenishment orders, price-triggered purchases, digital-service micropayments and machine-to-machine services.
A merchant evaluating AP2 should verify that it can:
- Expose structured catalog, inventory, pricing, checkout, order-status and refund interfaces.
- Validate agent identity, signatures and mandate constraints.
- Bind authorization to merchant, cart, amount, currency and time where appropriate.
- Handle taxes, shipping, promotions, substitutions and price changes deterministically.
- Prevent duplicate submissions and safely recover from uncertain payment responses.
- Retain evidence while limiting exposure of payment and personal data.
- Connect agent transactions to existing processor, fraud, customer-support and chargeback systems.
For consumers, the practical question is not whether an agent can technically send a payment request. It is whether the agent, merchant and payment provider clearly state spending limits, substitutions, approvals, cancellation rights and dispute procedures.
Risks AP2 does not remove
Prompt injection and wrong interpretation
A signed mandate can show that a request came from an authorized party, but a malicious product description, webpage, tool response or prompt can still manipulate an agent. A 2026 analysis of AP2-style architectures discusses these prompt-injection risks at arXiv. Cryptographic integrity, semantic correctness and operational safety are separate problems.
Replay, retries and concurrency
Implementations can submit a valid mandate twice, retry after an uncertain response, run competing agent sessions or mishandle an expired authorization. Another 2026 analysis examines runtime problems involving retries, concurrency and orchestration at arXiv. Idempotency keys, state tracking and explicit expiration rules remain necessary.
Changing prices and inventory
Evidence does not eliminate disputes when a promotion expires, a product is substituted, shipping appears late, taxes change the total or inventory disappears. Agent and merchant policies must specify whether the mandate covers the changed cart or requires renewed approval.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsFraud, liability and privacy
AP2 may improve the evidence available in a dispute, but it does not automatically decide who bears a loss. Card-network chargeback rules, consumer-protection law, wallet terms and contracts among the agent operator, merchant and processor still matter. Agents may also handle addresses, shopping history, preferences and payment tokens, creating data-minimization and credential-security requirements.
Current status and the practical verdict
AP2 is best understood as an open, evolving trust and evidence protocol for agentic commerce. Google announced it in 2025; version 0.2 and the FIDO Alliance governance transfer materially updated the project in 2026. The public specification and repository make experimentation possible, while commercial deployment still requires compatible merchant, identity, payment, fraud and fulfillment systems.
For a developer or enterprise, AP2 is worth evaluating when an agent must prove what it was authorized to do and connect that proof to a payment. For a consumer, it is not yet a universal wallet or a promise that an AI agent can safely buy from any store. The protocol can strengthen authorization and accountability, but spending limits, model safety, dispute rules and ordinary payment-network protections remain essential.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →




