Agentic Payments Market Map 2026: Who Builds What in AI Agent Payments

Short answer: The agentic payments market in 2026 has seven layers: open protocols (x402, AP2, ACP, MPP, UCP), card-network agent programs (Visa Trusted Agent Protocol, Mastercard Agent Pay), agent wallets and stablecoin rails, payment MCP servers and agent toolkits from PSPs, spend-control/policy and approval tools, agent identity ("Know Your Agent") systems, and checkout/agentic-commerce platforms. The most established players — measured by whether their own docs describe a live, money-touching product — are Stripe, Coinbase, Circle, Visa, and Mastercard; the protocol layer (x402, AP2, ACP) and the spend-control/policy layer are the two most crowded with early-stage and single-purpose tools.

Last checked: 2026-09-28. This is a point-in-time snapshot of a fast-moving market; every row below links to a primary source we opened ourselves.

The seven layers

Protocols & standards. These define the message format for a payment request, not a product you buy. x402 and MPP standardize an HTTP 402 request/response for machine-to-machine payments; AP2 standardizes cryptographically signed proof that a human authorized what an agent is buying; ACP and UCP standardize agent-to-merchant checkout. See What is agentic payments? and x402 vs AP2 vs ACP.

Card-network agent programs. Visa and Mastercard are extending their own tokenization infrastructure — not adopting a third-party protocol — so that a card issuer or merchant can recognize "this specific agent, with these specific limits, is transacting," rather than treating agent traffic as anonymous bot traffic. See Visa Trusted Agent Protocol and Mastercard Agent Pay.

Agent wallets & stablecoin rails. This layer solves custody: how does an autonomous process hold and move funds without a human typing in a card number each time? Most of these products are crypto/stablecoin-native, using MPC key-splitting, smart-contract delegation, or a policy engine that checks a proposed transaction before it's signed. See What is an AI agent wallet?.

Payment MCP servers & agent toolkits from PSPs. Payment processors are exposing their existing APIs as tools an AI client can call over the Model Context Protocol. MCP itself is not a payments protocol — it's the plumbing an agent uses to discover and call a company's tools, and whether those tools can move money (and under what controls) varies enormously by vendor. See Payments over MCP and Payment MCP servers compared.

Spend control / policy & approval layer. Almost every layer above assumes a budget or approval rule exists somewhere, but few of them enforce one natively across a fleet of agents and tools. This layer is where dedicated products — budget engines, approval gateways, and policy consoles — sit on top of (or in front of) wallets, MCP servers, and protocols. See AI agent spending controls.

Agent identity / "Know Your Agent" (KYA). Before a spending rule can be enforced, a merchant or service needs to know which agent, and on whose behalf, is making a request. This layer verifies agent identity — distinct from authorizing a specific purchase — often so that bot-defense infrastructure doesn't block a legitimate agent. See Know Your Agent (KYA).

Checkout / agentic commerce platforms. This is where a specific merchant-facing purchase actually completes — a buyer approves an order inside a chat interface or an agent flow, and the platform (not the protocol itself) handles capability negotiation, tokenization, and settlement.

The market map

Company Product Layer What it does Status Primary source
Coinbase / x402 Foundation x402 Protocols & standards Lets servers request stablecoin payment via HTTP 402 before returning a resource Live; governed by x402 Foundation (Linux Foundation) docs.x402.org/faq
Google / FIDO Alliance AP2 (Agent Payments Protocol) Protocols & standards Proves via signed mandates that a user authorized an agent's purchase Live; donated to FIDO Alliance Google Cloud
OpenAI + Stripe ACP (Agentic Commerce Protocol) Protocols & standards Standardizes agent-to-merchant checkout inside a chat interface on card rails Live spec; OpenAI and Stripe as Founding Maintainers Stripe
Stripe + Tempo MPP (Machine Payments Protocol) Protocols & standards Standardizes HTTP 402 machine-to-machine payments over stablecoins, cards and BNPL Published March 18, 2026 mpp.dev
Google UCP (Universal Commerce Protocol) Protocols & standards Open-source checkout standard for agentic commerce, compatible with AP2 Announced January 11, 2026 Google Developers Blog
Visa Trusted Agent Protocol (TAP) Card-network agent programs Lets merchants cryptographically verify a request comes from a trusted agent In development and deployment developer.visa.com
Mastercard Agent Pay (Agentic Tokens) Card-network agent programs Issues permissioned, tokenized credentials so agents pay within set limits Announced 2025; "Agent Pay for Machines" launched 2026 investor.mastercard.com
Coinbase AgentKit / Agentic Wallet Agent wallets & stablecoin rails USDC wallet for agents with per-session caps and OFAC screening GA-toned; no beta label found docs.cdp.coinbase.com
Circle Agent Wallets (circlefin/skills) Agent wallets & stablecoin rails Sets time-bound USDC spend limits and address allow/blocklists for agents Not labeled GA/beta github.com/circlefin/skills
Crossmint Agent Wallets & Checkout Agent wallets & stablecoin rails Non-custodial stablecoin wallets with scoped, revocable card allowances for agents Not labeled GA/beta docs.crossmint.com
Fireblocks Agentic Payments Suite Agent wallets & stablecoin rails MPC wallets let agents pay any x402/MPP merchant with an audit trail Early access (request access) fireblocks.com
Privy AI Agent Wallets Agent wallets & stablecoin rails Embedded wallets with a policy engine for agent transfer limits and approvals GA (production volume cited, no beta label) privy.io/ai
Turnkey Agentic Payments (Policy Engine) Agent wallets & stablecoin rails Scopes what each agent wallet can sign by address, contract, spend limit Launched turnkey.com
Catena Labs Catena Agent wallets & stablecoin rails Governance and banking platform giving agents accounts, payments, stablecoin rails GA-toned; pursuing a bank charter catena.com
MetaMask (Consensys) Agentic wallet architecture Agent wallets & stablecoin rails Describes a control layer defining what an agent may do before signing Explainer; multiple custody models cited in production metamask.io
Payman Genie MCP bridge Agent wallets & stablecoin rails Agentic-AI banking; natural-language MCP bridge to a remote Genie server Not labeled GA/beta github.com/paymanai
Stripe Stripe MCP server Payment MCP servers & agent toolkits Exposes the Stripe API to agents; write actions need human confirmation GA (some sub-tools in Preview) docs.stripe.com/mcp
Square (Block) Square MCP Server Payment MCP servers & agent toolkits Gives agents Square API access behind a connecting-client allowlist Beta developer.squareup.com
Mollie Mollie MCP Server Payment MCP servers & agent toolkits Connects AI tools to a Mollie account using natural language Not labeled GA/beta docs.mollie.com
Razorpay Razorpay MCP Server Payment MCP servers & agent toolkits Integrates Razorpay payment APIs with AI tools via MCP Not labeled; READ_ONLY flag available razorpay.com/docs
Airwallex AgentOS MCP Payment MCP servers & agent toolkits Money-out actions disabled by default; write tools need confirmation Beta airwallex.com
Plaid Dashboard MCP server Payment MCP servers & agent toolkits Diagnostics and analytics tools only; does not move money Active development; limited support plaid.com/docs
PinkWallet Pink Agentic AI Payment Spend control / policy & approval layer MCP server plus a console designed to enforce per-agent spending rules Early access (waitlist); no public sandbox yet pinkwallet.com/agentic
Locus Locus Spend control / policy & approval layer Three-layer policy engine checks every agent transaction against a budget GA; Y Combinator-backed paywithlocus.com
PolicyLayer PolicyLayer Spend control / policy & approval layer Checks every agent MCP tool call against policy before it runs Live, self-serve policylayer.com
SpendNod SpendNod Spend control / policy & approval layer Open-source, self-hosted human-in-the-loop authorization gateway for agent transactions Free, MIT-licensed spendnod.com
goodmeta agent-verifier-mcp Spend control / policy & approval layer MCP server enforcing a budget-authority protocol; tracks agent spend across services Open source on GitHub github.com/goodmeta
Skyfire KYA + KYA-Pay tokens Agent identity / KYA Attaches verified identity to agents and funds per-agent spend limits Commercial; self-serve signup docs.skyfire.xyz
Cloudflare Monetization Gateway (pay per crawl) Agent identity / KYA Verifies crawler identity and lets publishers charge AI agents via HTTP 402 Announced July 1, 2026 blog.cloudflare.com
Adyen Agent Platform (ACP + UCP) Checkout / agentic commerce platforms Manages full ACP and UCP checkout flows for Adyen merchants Live docs.adyen.com
PayPal Agent Ready (ACP) Checkout / agentic commerce platforms Lets merchants build a ChatGPT app that accepts payments via ACP Live guide; some payment methods listed "coming soon" developer.paypal.com
Checkout.com ACP support Checkout / agentic commerce platforms Supports the Agentic Commerce Protocol for enterprise merchants Announced November 25, 2025 checkout.com/newsroom
Stripe Agentic commerce (ACP checkout) Checkout / agentic commerce platforms Lets AI agents transact with sellers on a buyer's behalf Seller integrations available; agent-side integration in private preview docs.stripe.com/agentic-commerce

PinkWallet publishes this map and is building a product in it; it is listed once, in the layer it belongs to, and is not scored or ranked against the other companies above.

What changed in 2026

  • January 11, 2026: Google announced UCP (Universal Commerce Protocol), an open-source agentic-checkout standard built with Shopify, Etsy, Wayfair, Target and Walmart, describing it as "compatible with Agent Payments Protocol (AP2)" (Google Developers Blog).
  • March 18, 2026: Stripe and Tempo published MPP (Machine Payments Protocol), described on its own spec site as "the open standard for machine-to-machine payments via HTTP 402" (mpp.dev).
  • April 28, 2026: Google donated AP2 to the FIDO Alliance "to help further scale the technology and promote industry-wide innovation" (Google blog).
  • July 1, 2026: Cloudflare announced its Monetization Gateway, "an engine that will give Cloudflare customers the ability to charge for any asset protected by Cloudflare: web pages, datasets, APIs, or MCP tools" (Cloudflare blog), extending its earlier x402-based "pay per crawl" from web pages to a general-purpose charging layer.
  • July 14, 2026: The x402 Foundation had its operational launch under the Linux Foundation, with premier members including Google, Stripe, Visa, Mastercard, AWS and Coinbase (Linux Foundation).
  • October 31, 2026 (upcoming): Stripe's MCP server stops accepting full-access secret keys or non-Agent-tagged restricted keys, per Stripe's own documentation: "Beginning October 31, 2026, Stripe MCP no longer accepts full-access secret keys or restricted API keys without the Agent tag" (docs.stripe.com/mcp).

How to read this map — and where it's thin

This map counts products, not maturity. A row appearing here means a company's own site, docs, or GitHub describes something real — it does not mean the product is generally available, widely adopted, or safe to wire up without your own review.

Two layers are genuinely thin, and it's worth saying so plainly:

  • Spend control / policy is the least-institutionalized layer. PinkWallet's own Agentic Payments Readiness Report audited 13 payment providers across seven dimensions and found: "Guardrail specifics (spend limits, human confirmation, compliance screening) are the least-documented dimension across the sample. If spend control is a requirement for your deployment, expect to verify D5 directly with each vendor rather than relying on marketing language like 'enterprise-grade security.'" Consistent with that finding, most of the named products in this layer here are small, single-purpose tools (Locus, PolicyLayer, SpendNod, an open-source GitHub project) rather than offerings from the large payment processors — none of the PSP MCP documentation we reviewed describes a dedicated, cross-agent budget console; the controls it describes are narrower (a human-confirmation gate, a read-only flag, a client allowlist).
  • Pricing for agent-specific usage is essentially undisclosed. The same report found "Eleven of thirteen vendors show 'pricing: not found' on D7.2 for an agent-specific rate; the other two (Circle, Stripe) explicitly reuse their general processing/product pricing rather than publishing an agent-specific rate card." If you're budgeting a deployment, expect a sales conversation before you see a number.
  • "Has an MCP server" and "can move money without limits" are two different claims. Our companion piece, Payment MCP servers compared, found that among 16 companies checked, "money-out-by-default is the norm, not the exception" — most vendors ship live write tools (refunds, orders, payment links) with no purpose-built spend cap, relying instead on the underlying account's ordinary API-key or dashboard-role permissions.
  • Adoption of the newer protocols is concentrated, not universal. In the same Readiness Report sample, x402 and ACP each have four self-described adopters (Circle, Coinbase, Crossmint, Stripe for x402; Stripe, Adyen, PayPal, Checkout.com for ACP); no vendor in that 13-company sample self-describes an AP2 integration in its own docs as of 2026-09-28.

Methodology

We built this map by combining PinkWallet's prior, source-verified research — the Agentic Payments Readiness Report 2026 (13 payment providers, 7 dimensions) and Payment MCP servers compared (16 companies) — with new verification for protocols, card-network programs, agent wallets, and the spend-control layer. For every row in the table above, we opened the company's own domain, documentation, or official GitHub repository directly (never a search-engine summary or a third-party directory listing) and recorded a verbatim quote supporting the "what it does" and "status" cells, kept in a companion sources file. Several candidate companies found in MCP directories and funding coverage during research — including Nekuda and Natural — are not included in the table because we could not confirm the specific payment-product claims on a company-owned primary page at the time of writing; see the companion sources file for details on what we checked and why they were left out.

This is a snapshot, not a permanent ranking. Company inclusion reflects what we could verify as of 2026-09-28, not funding, market share, or endorsement. Corrections welcome via pinkwallet.com/agentic.

FAQ

Who are the key companies building agentic AI payment infrastructure? There is no single leader across every layer. Among the 13 providers in PinkWallet's Readiness Report, Circle and Skyfire have the most fully documented agent guardrails (spend limits, approvals), and Stripe and Airwallex are the two whose MCP docs explicitly describe a money-movement permission boundary; Visa and Mastercard are extending their card networks with their own agent-identity and tokenization programs; Google, Coinbase, and OpenAI/Stripe each publish a foundational protocol (AP2, x402, ACP).

What are the layers of the agentic payments market map? Seven: protocols & standards, card-network agent programs, agent wallets & stablecoin rails, payment MCP servers & agent toolkits from PSPs, spend control/policy & approval, agent identity (KYA), and checkout/agentic commerce platforms. See "The seven layers" above.

Which fintech startups let AI agents hold and spend money? Coinbase (Agentic Wallet, USDC), Circle (Agent Wallets, time-bound spend limits), Crossmint (non-custodial stablecoin wallets), Fireblocks (Agentic Payments Suite, MPC custody), Privy and Turnkey (embedded/policy-scoped wallets), and Catena Labs (an AI-native banking platform pursuing a bank charter) each publish a wallet-style product an agent can hold funds in and spend from, per their own sites.

Which companies offer spending governance or policy controls for AI agent payments? Dedicated policy/approval products in this map include Locus, PolicyLayer, SpendNod, and the open-source agent-verifier-mcp project, plus PinkWallet's Pink Agentic AI Payment (early access; waitlist; no public sandbox yet). Several wallet and MCP products also ship narrower, built-in controls — Circle's time-bound spend limits, Coinbase's per-session caps, Stripe's human-confirmation gate, and Airwallex's default-deny on money-out.

Where is the agentic payments market thinnest? In spend control. Across the 13 providers in PinkWallet's Readiness Report, guardrail specifics (spend limits, human confirmation, compliance screening) were the least-documented dimension. Most dedicated policy and approval products in this map are small, single-purpose tools rather than offerings from large payment processors. See AI agent spending controls.

Is MCP itself a payment protocol? No. The Model Context Protocol is a general-purpose way for an AI client to discover and call a company's tools; whether those tools can move money — and under what limits — is defined by each company's own server, not by MCP itself. See Payments over MCP.

Related