AP2, the Agent Payments Protocol, is an open standard from Google for letting an AI agent pay on a person's behalf while proving the person authorised it. Before an agent spends, the human signs a tamper-proof digital contract — a Mandate — that records exactly what was approved. A merchant or bank can then verify, cryptographically, that the payment reflects genuine human intent rather than an agent acting alone or on a hallucinated order.
AP2 uses three Mandates, each carried as a W3C Verifiable Credential: an Intent Mandate (the rules of engagement a user pre-signs for when they are away), a Cart Mandate (the exact items and price the user approves), and a Payment Mandate (a signal to the network that an agent initiated the transaction). Together they build a non-repudiable audit trail answering three questions — authorisation, authenticity, and accountability — that arise the moment a machine, not a person, initiates a payment.
Google announced AP2 in September 2025 with more than 60 payment and commerce partners. It builds on the Agent2Agent (A2A) and Model Context Protocol (MCP) standards, and is rail-agnostic: it supports cards and bank transfers directly, and stablecoins and crypto through the A2A x402 extension. AP2 sits at the payment-authorisation layer — above the card and stablecoin rails that settle the money, and alongside checkout standards like the Agentic Commerce Protocol. Partners and adoption are dated to mid-2026 and will move.