What Is AP2?

The Agent Payments Protocol (AP2) is an open, payment-rail-agnostic protocol from Google that lets AI agents make purchases on a user's behalf using cryptographically signed "mandates" as proof the user actually authorized the transaction.

Key facts

  • Announced by Google on September 16, 2025. The protocol was introduced by Stavan Parikh (VP/GM, Payments) and Rao Surapaneni (VP/GM, Business Applications Platform) in the Google Cloud Blog announcement.
  • 60+ launch partners. Collaborators named in the announcement include Adyen, American Express, Ant International, Coinbase, Etsy, Forter, Intuit, JCB, Mastercard, Mysten Labs, PayPal, Revolut, Salesforce, ServiceNow, UnionPay International, and Worldpay, per the Google Cloud Blog announcement.
  • Core mechanism: Mandates. AP2 defines an Intent Mandate (the user's initial instruction, e.g. "buy concert tickets under $200 when they go on sale") and a Cart Mandate (a tamper-proof, signed record of the exact items and price the user approved). Both use verifiable credentials to create a non-repudiable audit trail, per the Google Cloud Blog announcement.
  • Rail-agnostic by design. AP2 supports credit/debit cards, real-time bank transfers, and stablecoins/cryptocurrencies, and is built as an extension of the Agent2Agent (A2A) protocol with support for the Model Context Protocol (MCP), per the same announcement.
  • Open-source, Apache-2.0 licensed. Confirmed on the official google-agentic-commerce/AP2 GitHub repository, described there as "Building a Secure and Interoperable Future for AI-Driven Payments."
  • Governance transferred to the FIDO Alliance. On April 28, 2026, Google donated AP2 to the FIDO Alliance "to help further scale the technology and promote industry-wide innovation," per Google's blog post. That post also notes AP2 v0.2 introduced "Human Not Present" payments, letting agents execute pre-authorized transactions (e.g., buying limited-availability tickets) without the user present at the moment of purchase.

How it works

  1. The user gives the agent an instruction and constraints, captured as a signed Intent Mandate — this can be a real-time request or a delegated, conditional task with price/timing limits.
  2. The agent searches for and identifies matching products, services, or offers, without further human confirmation at this stage.
  3. Once the agent settles on exact items and a price, that selection is captured in a signed Cart Mandate, creating an unchangeable record of what the user is agreeing to pay.
  4. The user's approval links the Cart Mandate to a specific, authorized payment method.
  5. The mandates are passed to a payment processor or bank, which can independently verify the cryptographic signatures before authorizing the transaction, over whichever rail (card, bank transfer, or stablecoin) is in use.
  6. The signed mandate trail persists afterward, so that authorization, authenticity, and accountability can be established if there's a dispute.

AP2 vs. x402 vs. ACP

AP2 x402 ACP
Initiated by Google Coinbase Developer Platform OpenAI + Stripe
First published September 16, 2025 May 6, 2025 September 29, 2025
Payment rail Card, bank transfer, stablecoin (rail-agnostic) Stablecoins on Base / Solana Card rails via existing processors
Stablecoin support Yes — via x402 extension Yes — native Not specified in primary sources reviewed
Card support Yes No Yes
Authorization model Signed Intent/Cart Mandates (verifiable credentials) Signed payment verified by facilitator Checkout flow with capability negotiation
License Apache-2.0 Apache-2.0 Apache-2.0
Current governance Donated to FIDO Alliance (April 28, 2026) x402 Foundation (Linux Foundation) OpenAI and Stripe as Founding Maintainers

FAQ

What does AP2 stand for? Agent Payments Protocol. It's Google's open standard for letting AI agents transact on a user's behalf across payment rails, per the Google Cloud Blog announcement.

What is a "mandate" in AP2? A tamper-proof, cryptographically signed digital record. An Intent Mandate captures what the user asked for; a Cart Mandate captures the exact items and price the user approved before payment.

Does AP2 require cryptocurrency? No. AP2 is rail-agnostic and supports cards, real-time bank transfers, and stablecoins — the last via an x402 extension co-developed with Coinbase, the Ethereum Foundation, and MetaMask.

Who governs AP2 now? Google donated AP2 to the FIDO Alliance on April 28, 2026 to make it platform-agnostic and community-led, per Google's blog post.

What is "Human Not Present" payment in AP2? A mode introduced in AP2 v0.2 where an agent executes a transaction the user pre-authorized (with defined limits) without the user actively present at the moment of purchase, per Google's FIDO Alliance blog post.

Related terms