Agentic Payments Market Map 2026: Who Builds What in AI Agent Payments
Short answer: The agentic payments market in 2026 has seven layers: open protocols (x402, AP2, ACP, MPP, UCP), card-network agent programs (Visa Trusted Agent Protocol, Mastercard Agent Pay), agent wallets and stablecoin rails, payment MCP servers and agent toolkits from PSPs, spend-control/policy and approval tools, agent identity ("Know Your Agent") systems, and checkout/agentic-commerce platforms. The most established players — measured by whether their own docs describe a live, money-touching product — are Stripe, Coinbase, Circle, Visa, and Mastercard; the protocol layer (x402, AP2, ACP) and the spend-control/policy layer are the two most crowded with early-stage and single-purpose tools.
Last checked: 2026-09-28. This is a point-in-time snapshot of a fast-moving market; every row below links to a primary source we opened ourselves.
The seven layers
Protocols & standards. These define the message format for a payment request, not a product you buy. x402 and MPP standardize an HTTP 402 request/response for machine-to-machine payments; AP2 standardizes cryptographically signed proof that a human authorized what an agent is buying; ACP and UCP standardize agent-to-merchant checkout. See What is agentic payments? and x402 vs AP2 vs ACP.
Card-network agent programs. Visa and Mastercard are extending their own tokenization infrastructure — not adopting a third-party protocol — so that a card issuer or merchant can recognize "this specific agent, with these specific limits, is transacting," rather than treating agent traffic as anonymous bot traffic. See Visa Trusted Agent Protocol and Mastercard Agent Pay.
Agent wallets & stablecoin rails. This layer solves custody: how does an autonomous process hold and move funds without a human typing in a card number each time? Most of these products are crypto/stablecoin-native, using MPC key-splitting, smart-contract delegation, or a policy engine that checks a proposed transaction before it's signed. See What is an AI agent wallet?.
Payment MCP servers & agent toolkits from PSPs. Payment processors are exposing their existing APIs as tools an AI client can call over the Model Context Protocol. MCP itself is not a payments protocol — it's the plumbing an agent uses to discover and call a company's tools, and whether those tools can move money (and under what controls) varies enormously by vendor. See Payments over MCP and Payment MCP servers compared.
Spend control / policy & approval layer. Almost every layer above assumes a budget or approval rule exists somewhere, but few of them enforce one natively across a fleet of agents and tools. This layer is where dedicated products — budget engines, approval gateways, and policy consoles — sit on top of (or in front of) wallets, MCP servers, and protocols. See AI agent spending controls.
Agent identity / "Know Your Agent" (KYA). Before a spending rule can be enforced, a merchant or service needs to know which agent, and on whose behalf, is making a request. This layer verifies agent identity — distinct from authorizing a specific purchase — often so that bot-defense infrastructure doesn't block a legitimate agent. See Know Your Agent (KYA).
Checkout / agentic commerce platforms. This is where a specific merchant-facing purchase actually completes — a buyer approves an order inside a chat interface or an agent flow, and the platform (not the protocol itself) handles capability negotiation, tokenization, and settlement.
The market map
| Company | Product | Layer | What it does | Status | Primary source |
|---|---|---|---|---|---|
| Coinbase / x402 Foundation | x402 | Protocols & standards | Lets servers request stablecoin payment via HTTP 402 before returning a resource | Live; governed by x402 Foundation (Linux Foundation) | docs.x402.org/faq |
| Google / FIDO Alliance | AP2 (Agent Payments Protocol) | Protocols & standards | Proves via signed mandates that a user authorized an agent's purchase | Live; donated to FIDO Alliance | Google Cloud |
| OpenAI + Stripe | ACP (Agentic Commerce Protocol) | Protocols & standards | Standardizes agent-to-merchant checkout inside a chat interface on card rails | Live spec; OpenAI and Stripe as Founding Maintainers | Stripe |
| Stripe + Tempo | MPP (Machine Payments Protocol) | Protocols & standards | Standardizes HTTP 402 machine-to-machine payments over stablecoins, cards and BNPL | Published March 18, 2026 | mpp.dev |
| UCP (Universal Commerce Protocol) | Protocols & standards | Open-source checkout standard for agentic commerce, compatible with AP2 | Announced January 11, 2026 | Google Developers Blog | |
| Visa | Trusted Agent Protocol (TAP) | Card-network agent programs | Lets merchants cryptographically verify a request comes from a trusted agent | In development and deployment | developer.visa.com |
| Mastercard | Agent Pay (Agentic Tokens) | Card-network agent programs | Issues permissioned, tokenized credentials so agents pay within set limits | Announced 2025; "Agent Pay for Machines" launched 2026 | investor.mastercard.com |
| Coinbase | AgentKit / Agentic Wallet | Agent wallets & stablecoin rails | USDC wallet for agents with per-session caps and OFAC screening | GA-toned; no beta label found | docs.cdp.coinbase.com |
| Circle | Agent Wallets (circlefin/skills) |
Agent wallets & stablecoin rails | Sets time-bound USDC spend limits and address allow/blocklists for agents | Not labeled GA/beta | github.com/circlefin/skills |
| Crossmint | Agent Wallets & Checkout | Agent wallets & stablecoin rails | Non-custodial stablecoin wallets with scoped, revocable card allowances for agents | Not labeled GA/beta | docs.crossmint.com |
| Fireblocks | Agentic Payments Suite | Agent wallets & stablecoin rails | MPC wallets let agents pay any x402/MPP merchant with an audit trail | Early access (request access) | fireblocks.com |
| Privy | AI Agent Wallets | Agent wallets & stablecoin rails | Embedded wallets with a policy engine for agent transfer limits and approvals | GA (production volume cited, no beta label) | privy.io/ai |
| Turnkey | Agentic Payments (Policy Engine) | Agent wallets & stablecoin rails | Scopes what each agent wallet can sign by address, contract, spend limit | Launched | turnkey.com |
| Catena Labs | Catena | Agent wallets & stablecoin rails | Governance and banking platform giving agents accounts, payments, stablecoin rails | GA-toned; pursuing a bank charter | catena.com |
| MetaMask (Consensys) | Agentic wallet architecture | Agent wallets & stablecoin rails | Describes a control layer defining what an agent may do before signing | Explainer; multiple custody models cited in production | metamask.io |
| Payman | Genie MCP bridge | Agent wallets & stablecoin rails | Agentic-AI banking; natural-language MCP bridge to a remote Genie server | Not labeled GA/beta | github.com/paymanai |
| Stripe | Stripe MCP server | Payment MCP servers & agent toolkits | Exposes the Stripe API to agents; write actions need human confirmation | GA (some sub-tools in Preview) | docs.stripe.com/mcp |
| Square (Block) | Square MCP Server | Payment MCP servers & agent toolkits | Gives agents Square API access behind a connecting-client allowlist | Beta | developer.squareup.com |
| Mollie | Mollie MCP Server | Payment MCP servers & agent toolkits | Connects AI tools to a Mollie account using natural language | Not labeled GA/beta | docs.mollie.com |
| Razorpay | Razorpay MCP Server | Payment MCP servers & agent toolkits | Integrates Razorpay payment APIs with AI tools via MCP | Not labeled; READ_ONLY flag available |
razorpay.com/docs |
| Airwallex | AgentOS MCP | Payment MCP servers & agent toolkits | Money-out actions disabled by default; write tools need confirmation | Beta | airwallex.com |
| Plaid | Dashboard MCP server | Payment MCP servers & agent toolkits | Diagnostics and analytics tools only; does not move money | Active development; limited support | plaid.com/docs |
| PinkWallet | Pink Agentic AI Payment | Spend control / policy & approval layer | MCP server plus a console designed to enforce per-agent spending rules | Early access (waitlist); no public sandbox yet | pinkwallet.com/agentic |
| Locus | Locus | Spend control / policy & approval layer | Three-layer policy engine checks every agent transaction against a budget | GA; Y Combinator-backed | paywithlocus.com |
| PolicyLayer | PolicyLayer | Spend control / policy & approval layer | Checks every agent MCP tool call against policy before it runs | Live, self-serve | policylayer.com |
| SpendNod | SpendNod | Spend control / policy & approval layer | Open-source, self-hosted human-in-the-loop authorization gateway for agent transactions | Free, MIT-licensed | spendnod.com |
| goodmeta | agent-verifier-mcp | Spend control / policy & approval layer | MCP server enforcing a budget-authority protocol; tracks agent spend across services | Open source on GitHub | github.com/goodmeta |
| Skyfire | KYA + KYA-Pay tokens | Agent identity / KYA | Attaches verified identity to agents and funds per-agent spend limits | Commercial; self-serve signup | docs.skyfire.xyz |
| Cloudflare | Monetization Gateway (pay per crawl) | Agent identity / KYA | Verifies crawler identity and lets publishers charge AI agents via HTTP 402 | Announced July 1, 2026 | blog.cloudflare.com |
| Adyen | Agent Platform (ACP + UCP) | Checkout / agentic commerce platforms | Manages full ACP and UCP checkout flows for Adyen merchants | Live | docs.adyen.com |
| PayPal | Agent Ready (ACP) | Checkout / agentic commerce platforms | Lets merchants build a ChatGPT app that accepts payments via ACP | Live guide; some payment methods listed "coming soon" | developer.paypal.com |
| Checkout.com | ACP support | Checkout / agentic commerce platforms | Supports the Agentic Commerce Protocol for enterprise merchants | Announced November 25, 2025 | checkout.com/newsroom |
| Stripe | Agentic commerce (ACP checkout) | Checkout / agentic commerce platforms | Lets AI agents transact with sellers on a buyer's behalf | Seller integrations available; agent-side integration in private preview | docs.stripe.com/agentic-commerce |
PinkWallet publishes this map and is building a product in it; it is listed once, in the layer it belongs to, and is not scored or ranked against the other companies above.
What changed in 2026
- January 11, 2026: Google announced UCP (Universal Commerce Protocol), an open-source agentic-checkout standard built with Shopify, Etsy, Wayfair, Target and Walmart, describing it as "compatible with Agent Payments Protocol (AP2)" (Google Developers Blog).
- March 18, 2026: Stripe and Tempo published MPP (Machine Payments Protocol), described on its own spec site as "the open standard for machine-to-machine payments via HTTP 402" (mpp.dev).
- April 28, 2026: Google donated AP2 to the FIDO Alliance "to help further scale the technology and promote industry-wide innovation" (Google blog).
- July 1, 2026: Cloudflare announced its Monetization Gateway, "an engine that will give Cloudflare customers the ability to charge for any asset protected by Cloudflare: web pages, datasets, APIs, or MCP tools" (Cloudflare blog), extending its earlier x402-based "pay per crawl" from web pages to a general-purpose charging layer.
- July 14, 2026: The x402 Foundation had its operational launch under the Linux Foundation, with premier members including Google, Stripe, Visa, Mastercard, AWS and Coinbase (Linux Foundation).
- October 31, 2026 (upcoming): Stripe's MCP server stops accepting full-access secret keys or non-Agent-tagged restricted keys, per Stripe's own documentation: "Beginning October 31, 2026, Stripe MCP no longer accepts full-access secret keys or restricted API keys without the Agent tag" (docs.stripe.com/mcp).
How to read this map — and where it's thin
This map counts products, not maturity. A row appearing here means a company's own site, docs, or GitHub describes something real — it does not mean the product is generally available, widely adopted, or safe to wire up without your own review.
Two layers are genuinely thin, and it's worth saying so plainly:
- Spend control / policy is the least-institutionalized layer. PinkWallet's own Agentic Payments Readiness Report audited 13 payment providers across seven dimensions and found: "Guardrail specifics (spend limits, human confirmation, compliance screening) are the least-documented dimension across the sample. If spend control is a requirement for your deployment, expect to verify D5 directly with each vendor rather than relying on marketing language like 'enterprise-grade security.'" Consistent with that finding, most of the named products in this layer here are small, single-purpose tools (Locus, PolicyLayer, SpendNod, an open-source GitHub project) rather than offerings from the large payment processors — none of the PSP MCP documentation we reviewed describes a dedicated, cross-agent budget console; the controls it describes are narrower (a human-confirmation gate, a read-only flag, a client allowlist).
- Pricing for agent-specific usage is essentially undisclosed. The same report found "Eleven of thirteen vendors show 'pricing: not found' on D7.2 for an agent-specific rate; the other two (Circle, Stripe) explicitly reuse their general processing/product pricing rather than publishing an agent-specific rate card." If you're budgeting a deployment, expect a sales conversation before you see a number.
- "Has an MCP server" and "can move money without limits" are two different claims. Our companion piece, Payment MCP servers compared, found that among 16 companies checked, "money-out-by-default is the norm, not the exception" — most vendors ship live write tools (refunds, orders, payment links) with no purpose-built spend cap, relying instead on the underlying account's ordinary API-key or dashboard-role permissions.
- Adoption of the newer protocols is concentrated, not universal. In the same Readiness Report sample, x402 and ACP each have four self-described adopters (Circle, Coinbase, Crossmint, Stripe for x402; Stripe, Adyen, PayPal, Checkout.com for ACP); no vendor in that 13-company sample self-describes an AP2 integration in its own docs as of 2026-09-28.
Methodology
We built this map by combining PinkWallet's prior, source-verified research — the Agentic Payments Readiness Report 2026 (13 payment providers, 7 dimensions) and Payment MCP servers compared (16 companies) — with new verification for protocols, card-network programs, agent wallets, and the spend-control layer. For every row in the table above, we opened the company's own domain, documentation, or official GitHub repository directly (never a search-engine summary or a third-party directory listing) and recorded a verbatim quote supporting the "what it does" and "status" cells, kept in a companion sources file. Several candidate companies found in MCP directories and funding coverage during research — including Nekuda and Natural — are not included in the table because we could not confirm the specific payment-product claims on a company-owned primary page at the time of writing; see the companion sources file for details on what we checked and why they were left out.
This is a snapshot, not a permanent ranking. Company inclusion reflects what we could verify as of 2026-09-28, not funding, market share, or endorsement. Corrections welcome via pinkwallet.com/agentic.
FAQ
Who are the key companies building agentic AI payment infrastructure? There is no single leader across every layer. Among the 13 providers in PinkWallet's Readiness Report, Circle and Skyfire have the most fully documented agent guardrails (spend limits, approvals), and Stripe and Airwallex are the two whose MCP docs explicitly describe a money-movement permission boundary; Visa and Mastercard are extending their card networks with their own agent-identity and tokenization programs; Google, Coinbase, and OpenAI/Stripe each publish a foundational protocol (AP2, x402, ACP).
What are the layers of the agentic payments market map? Seven: protocols & standards, card-network agent programs, agent wallets & stablecoin rails, payment MCP servers & agent toolkits from PSPs, spend control/policy & approval, agent identity (KYA), and checkout/agentic commerce platforms. See "The seven layers" above.
Which fintech startups let AI agents hold and spend money? Coinbase (Agentic Wallet, USDC), Circle (Agent Wallets, time-bound spend limits), Crossmint (non-custodial stablecoin wallets), Fireblocks (Agentic Payments Suite, MPC custody), Privy and Turnkey (embedded/policy-scoped wallets), and Catena Labs (an AI-native banking platform pursuing a bank charter) each publish a wallet-style product an agent can hold funds in and spend from, per their own sites.
Which companies offer spending governance or policy controls for AI agent payments?
Dedicated policy/approval products in this map include Locus, PolicyLayer, SpendNod, and the open-source agent-verifier-mcp project, plus PinkWallet's Pink Agentic AI Payment (early access; waitlist; no public sandbox yet). Several wallet and MCP products also ship narrower, built-in controls — Circle's time-bound spend limits, Coinbase's per-session caps, Stripe's human-confirmation gate, and Airwallex's default-deny on money-out.
Where is the agentic payments market thinnest? In spend control. Across the 13 providers in PinkWallet's Readiness Report, guardrail specifics (spend limits, human confirmation, compliance screening) were the least-documented dimension. Most dedicated policy and approval products in this map are small, single-purpose tools rather than offerings from large payment processors. See AI agent spending controls.
Is MCP itself a payment protocol? No. The Model Context Protocol is a general-purpose way for an AI client to discover and call a company's tools; whether those tools can move money — and under what limits — is defined by each company's own server, not by MCP itself. See Payments over MCP.
Related
- What are agentic payments?
- What is x402?
- What is AP2?
- What is the Agentic Commerce Protocol (ACP)?
- What is an AI agent wallet?
- What are AI agent spending controls?
- What is Know Your Agent (KYA)?
- What is Mastercard Agent Pay?
- What is the Visa Trusted Agent Protocol?
- What are payments over MCP?
- Payment MCP servers compared
- x402 vs AP2 vs ACP
- Agentic Payments Readiness Report 2026






