Agent Payment Protocols Adoption Tracker (October 2026)
Published 2026-10-09 · Publisher: Pink Agentic AI Payments (by PinkWallet)
Published by PinkWallet, which builds Pink Agentic AI Payments (an agent spending-control layer). Pink is not one of the protocols measured and does not integrate with any of them today.
We measured public adoption signals for three commerce-focused agent payment protocols, x402, AP2 (Agent Payments Protocol) and ACP (Agentic Commerce Protocol), plus L402 as a longer-running comparison point. For each protocol we read GitHub stats, package downloads, MCP Registry listings, repo-search counts, ecosystem pages and spec version history directly from the primary source. Full dataset, method and findings are published on GitHub and Hugging Face (links below); this page carries the same numbers.
Adoption signals, side by side
All figures measured 2026-10-08. Every cell in the published CSV links to the exact source URL and method used; "n/a" means no official package or page could be confirmed, not zero.
| Metric | x402 | AP2 | ACP | L402 |
|---|---|---|---|---|
| Canonical repo | x402-foundation/x402 | google-agentic-commerce/AP2 | agentic-commerce-protocol | lightninglabs/L402 |
| GitHub stars | 6,689 | 3,211 | 1,568 | 91 |
| GitHub forks | 2,146 | 509 | 253 | 19 |
| Contributors | 333 | 19 | 26 | 8 |
| Commits, last 90 days | 281 | 0 | 1 | 0 |
| Official npm weekly downloads1 | 485,082 | n/a | n/a | n/a |
| Official PyPI monthly downloads | 204,765 | n/a | n/a | n/a |
| MCP Registry servers naming it2 | 214 | 3 | 2 | 5 |
| GitHub repo-search hits (approx.)3 | 28,297 | 2,587 | 977 | 938 |
| Ecosystem / partners page | 15 facilitators listed | not found | not found | 3 implementations listed |
| Spec version | v2 | 0.2.0 | 2026-04-17 | unversioned |
| Spec last changed | 2026-08-31 | 2026-04-28 | 2026-07-18 | 2026-03-20 |
1 Sum of the 5 official npm packages maintained in the x402 monorepo, week of 2026-10-01 to 2026-10-07: x402 458,455, x402-fetch 13,516, x402-axios 1,642, x402-express 9,929, x402-next 1,540. 2 ACP's raw MCP Registry match count for the search term "ACP" was 8; after manually reading all 8 entries, 6 turned out to be unrelated tools that also abbreviate to ACP, leaving 2 genuine Stripe/OpenAI integrations. 3 GitHub documents repository search counts as approximate once results are large; the AP2 and ACP queries added disambiguating terms ("agent", the exact phrase "agentic commerce protocol") because the bare acronyms are too generic to use alone. "n/a" means not measurable with an official package we could confirm, not zero.
Findings
- x402 has by far the largest GitHub footprint of the three commerce-focused protocols. x402-foundation/x402 has 6,689 stars and 333 contributors, versus 3,211 stars and 19 contributors for AP2 (google-agentic-commerce/AP2), and 1,568 stars and 26 contributors for ACP (agentic-commerce-protocol/agentic-commerce-protocol).
- x402's spec repo is far more active day to day: 281 commits in the last 90 days, versus 1 for ACP and 0 for AP2. AP2's and L402's default branches had no commits in the 90 days before measurement (last push 2026-06-17 and 2026-06-09 respectively); ACP had exactly one.
- x402 has a real, measured package-download footprint; AP2 and ACP do not, as far as we could find. The official npm package
x402gets 458,455 downloads a week and the official PyPI packagex402gets 204,765 downloads a month. AP2 and ACP have no official npm or PyPI packages we could confirm: the only PyPI package namedap2belongs to an unrelated third-party repo, and ACP's own package name (@agentic-commerce-protocol/specification) returns a 404 on the npm registry. - x402 also dominates the MCP ecosystem: 214 distinct registered MCP servers name it, versus 3 for AP2 and roughly 2 (after removing false positives) for ACP. The raw, unverified registry count for "ACP" was 8, but 6 of those 8 are unrelated tools that happen to also abbreviate to "ACP" (an AI social network, an "Agentic Control Plane" cost and policy tool, an MCP-to-ACP coding-agent bridge, among others); only 2 are genuine Stripe or OpenAI Agentic Commerce Protocol integrations.
- x402's GitHub code-footprint search also leads, with 28,297 repos matching
x402 in:name,description,readme, versus 2,587 for AP2 with an added "agent" qualifier and 977 for the exact phrase "agentic commerce protocol". These are GitHub's own approximate search counts, not exact; see the caveats below. - AP2 has shipped one versioned release since launch; ACP ships on a rolling, date-stamped API version instead of GitHub releases. AP2's only GitHub Release is v0.2.0 (2026-04-28, "Release of V2"). ACP has no GitHub tags or releases at all; its spec versions are date strings in a changelog folder, the latest promoted one being 2026-04-17, with unreleased changes already in the spec directory as of 2026-07-18. x402 does not use GitHub Releases either; it tags per-package version bumps instead.
- x402 is the only one of the three with a maintained, named facilitator or implementer directory: its official docs list 15 production facilitators (Coinbase CDP, Fireblocks, Polygon, Celo, Corbits, among others). Neither AP2 nor ACP publishes an equivalent ecosystem or partners page as of 2026-10-08.
- L402 (the oldest of the four, dating to 2020) is now the smallest by every GitHub metric measured: 91 stars, 8 contributors, 0 commits in the last 90 days, no npm or PyPI package we could confirm as official, and only 5 MCP Registry servers naming it. Its own README lists just 3 "Implementations" (Aperture, lsat-js, boltwall) under a hand-maintained list, not a submission-based directory.
- Visa's "Trusted Agent Protocol" and Mastercard's "Agent Pay" have no public spec repo or document as of 2026-10-08 and are excluded from this tracker. GitHub searches for both surface only third-party demo or hackathon repos; the official Visa GitHub org (16 public repos) has nothing matching.
- L402 itself has two competing "canonical" homes on GitHub, which complicates any single adoption number for it:
lightninglabs/L402(91 stars, the originating org) and the independentl402-protocol/l402(227 stars, describing itself as a newer continuation). This tracker measured onlylightninglabs/L402; treat the L402 numbers above as a lower bound on total L402-branded GitHub activity.
What none of these protocols decide
We checked each spec for one question: does it define a standing per-agent spending budget, a general spending-policy engine, or a human-approval step as a protocol primitive, as opposed to a one-off, per-transaction authorization?
"Out of Scope: This specification does not include: ... Client-side budget management ... Session handling mechanisms"
Source: x402 specification v2, x402-foundation/x402, fetched 2026-10-08.
x402 defines a per-request payment authorization and settlement handshake between a client, a resource server and a facilitator. It has no concept of a standing budget across multiple payments, no spending-policy object, and no human-in-the-loop approval step; those are left to whatever wraps the client.
AP2 defines "Mandates", cryptographically signed objects that capture a user's authorization for one checkout, and a human-approval primitive for its "Human Present" flow. What it does not define is a standing, protocol-level object representing an agent's ongoing budget across many transactions: a Mandate authorizes one task or cart, not a continuing allowance.
ACP defines REST endpoints for creating, updating and completing a checkout session between an agent, a business and a payment processor. We found no mention of budgets, spending limits, or human-approval steps as protocol primitives anywhere in the README, the dated spec folders, or a targeted code search for "budget" or "spending_limit".
L402 defines an HTTP 402 challenge-and-response flow using Lightning invoices and macaroons for per-request API payment authentication. No budget, policy or approval concept appears in the spec text.
Where Pink fits
Pink Agentic AI Payments is an MCP server that checks per-agent budgets, payee rules and human-approval holds before a payment executes; try it in the public sandbox with test money.
Pink handles per-agent budgets, payee rules and human approvals for payments an agent makes through Pink's MCP server. It does not plug into x402, AP2, ACP or L402 today. The gap described above, how an organization decides in advance what an agent is allowed to spend, on what, and whether a human needs to sign off, is the gap a per-agent budget, rules and approval layer would need to fill if someone built one on top of any of these protocols. Try the sandbox: https://agentic-sandbox.pinkwallet.com.
Caveats
- Stars, forks and repo-search counts measure attention and SEO-adjacent naming, not production usage.
- GitHub's repository and code search counts are documented by GitHub as approximate for large result sets.
- npm and PyPI download counts include CI pipelines, mirrors and bots, not only human developers.
- "AP2" and especially "ACP" are generic enough strings that raw search and registry matches need manual de-noising; this was done for the MCP Registry metric, but GitHub repo-search counts for AP2 and ACP still carry residual noise despite added qualifier terms.
Method summary
Measured 2026-10-08 to 2026-10-09. For each protocol we picked the GitHub repo with the clearest claim to being the spec's official home, then read GitHub repo stats, a GitHub code-footprint search, official npm and PyPI package downloads (verified as official by checking the package's location inside the protocol's own repo or org), MCP Registry listings (deduplicated by server name, with manual false-positive removal for generic acronyms), each protocol's own ecosystem or partners page, and its spec version and last-changed date. Visa's Trusted Agent Protocol and Mastercard's Agent Pay were excluded because neither has a public spec repo or document. Full definitions, source list and limitations are in the published METHODOLOGY.md on GitHub.
How to cite
Pink Agentic AI Payments (PinkWallet). "Agent Payment Protocols Adoption Tracker (October 2026)." Published 2026-10-09. Dataset: github.com/Pink-Agentic-Payments/agent-payment-protocols-tracker and huggingface.co/datasets/Agentic-Payment/agent-payment-protocols-tracker-2026-10. Licensed CC BY 4.0.
Correct a number
This tracker and its underlying CSV are published under CC BY 4.0. If you maintain one of these protocols and a row is wrong or out of date, open a correction with the row name, the URL, and the exact text that supports a different result: github.com/Pink-Agentic-Payments/agent-payment-protocols-tracker/issues/new/choose.
See also
For a census of payment-adjacent MCP servers and which ones document spending controls, see the Payment MCP Servers Census (October 2026). For how to connect an agent to Pink's MCP server, see the developer docs.
Data
The full tracker (4 protocols, up to 20 metrics each, every cell with a source URL and method) is published alongside this report as a CSV under CC BY 4.0: agent-payment-protocols-tracker-2026-10.csv.






