Agentic commerce protocols, layer by layer.
An agent order passes through several specs at once. One carries the request, one says who sent it, one records what the buyer allowed, one runs the order, and one moves the money. This map lists each spec, who runs it, how far along it is, and what it leaves on the record when an order is questioned.
Five layers, read from the wire up.
Most agent orders touch several layers. Each layer answers one question, and no spec answers all five. Card-network programs bundle specs from more than one layer.
Network programs
Which card-network bundles use these specs?
Each spec, with its owner, status, and sources.
Status and version are as of 7 Oct 2026. “On the record” is what the spec leaves behind when an order is questioned. Where KYA reads a spec, the tag shows how far that work has gone.
L1 · Agent transport
MCP
Model Context Protocol
Agentic AI Foundation (Linux Foundation). Created by Anthropic.
Connects an AI application to tools, data, and prompts. UCP and ACP both offer MCP bindings.
On the recordWhatever tool-call log the host keeps. Access to a tool is not permission to buy.
A2A
Agent2Agent Protocol
Agentic AI Foundation since Aug 2026. Created by Google, then a Linux Foundation project.
Lets agents built on different frameworks find each other through Agent Cards and work on tasks together. PACT and AP2 build on it.
On the recordTask history between agents. Nothing specific to orders or payment.
L2 · Agent identity
Web Bot Auth
IETF webbotauth working group. Authors from Cloudflare and Google.
An agent signs its HTTP requests and names a published key directory, so a site can verify the signature instead of trusting a user-agent string or IP address.
On the recordProof that a holder of a key published at a given URL signed the request. The draft says this shows nothing about who operates the agent or whether the request is authorized.
Visa TAP
Trusted Agent Protocol
Visa, developed with Cloudflare.
Visa’s profile of HTTP Message Signatures. An approved agent signs its browsing and payment requests and can carry intent, consumer-recognition, and payment data.
On the recordA signature tying the request to a Visa-approved agent. Visa says TAP aims to reduce chargebacks from unauthorized transactions; it defines no dispute process.
TACP
Trusted Agentic Commerce Protocol
Forter
Mutual authentication between agent and merchant, with signed and encrypted messages (JWS, JWE, JWKS).
On the recordSigned messages between agent and merchant. No dispute format.
KYAPay
Skyfire
JWT formats for agent identity, payment, or both, plus a draft for exchanging them for OAuth access tokens. Individual drafts have no IETF standing.
On the recordA signed token carrying the agent’s verified identity and, for payment tokens, an amount and currency.
ERC-8004
Trustless Agents
Ethereum ERC
On-chain registries for agent identity, reputation, and validation. A June 2026 study found that only 3% to 15% of registrations, depending on the chain, had a valid file and a live service endpoint.
On the recordPublic on-chain identity and reputation entries for the agent.
L3 · Authority and consent
AP2
Agent Payments Protocol
FIDO Alliance since Apr 2026. Created by Google.
Signed Checkout and Payment mandates that record what the user approved, whether or not the user is present at purchase.
On the recordMandates and receipts that the spec calls a non-repudiable picture of the transaction. Retention, retrieval, and dispute resolution are out of its scope.
Verifiable Intent
Mastercard, co-developed with Google. Contributed to the FIDO Alliance.
A signed record of the user’s instruction that can be checked against the final cart. Designed to work with AP2 and UCP.
On the recordConsent becomes “a durable artifact, verifiable after the fact.” The spec does not define how disputes are handled or assign liability.
PACT
Personal Agent Consent & Trust
Decagon, co-developed with Instinct.
The user signs in to the business directly and grants a personal agent narrow scopes. Built on A2A 1.0 and OAuth 2.0.
On the recordUnder the Delegated profile, a signed receipt with each reply sent under a delegation token, recording the scopes used and actions taken. Nothing on payments or disputes.
PAP
Personal Agent Protocol
Meta and Sierra, with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart.
OAuth sessions for personal agents working with a business through its website, its APIs, or its own agent. A session can start as a guest; the customer grants read-only or write access.
On the recordNo spec published yet. Sierra says payments extensions could come later.
L4 · Commerce
UCP
Universal Commerce Protocol
Founded by Google and Shopify. Stripe sits on the governing council.
Catalog, cart, checkout, identity linking, and orders over REST, MCP, A2A, or an embedded transport. The merchant stays merchant of record.
On the recordOrder adjustments, where dispute is one example of an open-string type with no evidence fields. The optional AP2 mandates extension adds signed authorization.
ACP
Agentic Commerce Protocol
OpenAI, Stripe, and Meta (maintainers).
Checkout sessions, carts, product feeds, order updates, and delegated payment through a scoped token such as Stripe’s Shared Payment Token. The merchant stays merchant of record.
On the recordSigned order webhooks. Dispute is a defined adjustment type that “covers chargebacks,” with a free-text reason and no evidence format.
L5 · Payment
x402
x402 Foundation (Linux Foundation). Created by Coinbase.
HTTP 402 payments: the server states a price, the client pays (mostly in stablecoins), and the request goes through. Lightning was added to the spec in Sep 2026, not yet to the SDKs.
On the recordAn optional signed-receipt extension meant for dispute evidence; its wire format is not yet stable. No card chargeback rights.
MPP
Machine Payments Protocol
Stripe and Tempo
HTTP 402 payment authorization for one-off charges, subscriptions, and sessions, across stablecoins, cards, Lightning, and other methods. Published as the IETF individual draft draft-httpauth-payment.
On the recordServers should include a Payment-Receipt header on successful paid responses. No dispute format.
L402
Lightning Labs
Pay-per-request API access using Lightning invoices and macaroons.
On the recordProof that an invoice was paid. Lightning payments have no chargebacks.
ACK
Agent Commerce Kit
Catena Labs
ACK-ID for agent identity with decentralized identifiers and verifiable credentials, and ACK-Pay for payments. A proposed v2 would drop the credential requirement and map ACK-Pay onto x402.
On the recordA receipt issued as a verifiable credential, proving a payment requirement was met.
AMP
Agentic Mobile Protocol
Ant International
Ant International’s protocol for agent payments. Its first phase covers 10 Alipay+ wallets and 7 acquirers.
On the recordAnt offers AgentSafePay, a money-back guarantee for AMP transactions. That is a commercial promise, not a protocol rule.
NET · Network programs
Visa Intelligent Commerce
Visa
Visa’s agent commerce program. Under Visa’s rules, agentic payment providers must enroll in it. TAP is part of it, and Intelligent Commerce Connect, a pilot since April 2026, accepts payments started through TAP, MPP, ACP, and UCP.
On the recordVisa Core Rules apply: the agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions.
Agent Pay
Mastercard Agent Pay
Mastercard
Mastercard’s agent payment program, built on Agentic Tokens. In October 2025 Mastercard said it is incorporating Web Bot Auth into Agent Pay. Agent Pay for Machines followed in June 2026.
On the recordWe found no published Mastercard dispute rule specific to agent transactions.
Amex ACE
American Express Agentic Commerce Experiences
American Express
Five services: agent registration, account enablement, intent intelligence, payment credentials, and cart context. The agent registration and cart context specs are still in development.
On the recordAmerican Express describes purchase protection for purchases by registered agents as a future feature.
Card rules decide liability. The specs supply evidence.
Signatures, mandates, and receipts each answer part of a dispute. Most specs leave storing and retrieving them to someone else, and AP2 says so outright.
Visa Core Rules, 18 Apr 2026 edition
An agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions “as if the Cardholder initiated the Transaction.” The provider must keep an order confirmation available to the cardholder for at least 120 days. The dispute chapter has no agent-specific condition.
SourceVisa dispute condition 10.4, from 24 Oct 2026
In card-absent fraud disputes, the login ID used with an agentic payment provider can count as a matching data element, when the same card was used in two earlier undisputed transactions.
SourceAP2 v0.2
Mandates and receipts give a “non-repudiable picture” of the transaction. Dispute resolution, retention, and retrieval are outside the spec’s scope.
SourceVerifiable Intent v0.1
Evidence only. It “does not define how disputes are initiated, routed between parties, escalated, or resolved,” and does not assign liability or chargeback codes.
SourceACP 2026-04-17
Dispute is a defined order adjustment type: “‘dispute’ covers chargebacks.” The reason is free text and there is no evidence format.
SourceUCP 2026-08-25
An order adjustment can be typed dispute, an open string with no reason-code or evidence fields. UCP supplies signed authorization through the optional AP2 mandates extension; other consent systems can supply separate evidence.
SourceVisa TAP
The reference code’s README says TAP aims to “minimize chargebacks from unauthorized transactions.” The specification defines no dispute mechanism.
Sourcex402
Optional signed offers and receipts, intended in part for dispute evidence. The wire format is marked not stable.
SourcePACT 1.0
Under the Delegated profile, each reply sent under a delegation token carries a signed receipt of scopes used and actions taken, and personal agents should keep them. Nothing on payments or disputes.
SourceKYA’s evidence record keeps these pieces together for each agent order: the authorization evidence your store had, the checks it ran, and what happened afterward. Evidence records are in a founding merchant pilot. How an agent order goes on the record
The distinctions behind most mix-ups.
Identity is not authority
A valid signature ties a request to a published key. A mandate or consent grant says what the agent may do. Web Bot Auth and TAP answer the first question; AP2, Verifiable Intent, and PACT answer the second.
Checkout is not settlement
UCP and ACP structure the order. Card networks, x402, and MPP move the money. AP2 records that the user authorized the payment.
A program is not a protocol
Visa Intelligent Commerce, Mastercard Agent Pay, and Amex ACE are programs. TAP and Agentic Tokens are parts of them. Verifiable Intent is a separate open spec that Mastercard maintains.
TAP is not TACP
Visa TAP signs HTTP requests with agent identity and intent. Forter’s TACP is a separate, MIT-licensed protocol for mutual authentication and encrypted exchange.
PAP is not PACT
Both were announced on 6 October 2026, and Instinct works on both. PAP (Meta and Sierra) has no published spec yet. PACT (Decagon) published a 1.0 spec the same day.
KYA is not KYAPay
“Know Your Agent” is a category. KYAPay is Skyfire’s token protocol. KnowYourAgent is the company that publishes this page. Four meanings of the term
What KYA reads today, and what it does not.
KYA reads some of these specs today and plans to read others. It does not replace any of them. The status below comes from the same registry as our public manifest at /api/v1/meta/protocols.
KYA Agent Trust Trace
Ed25519-signed trace JWTs bind an agent request to a hashed principal, audience, scope, and spending limit. External adoption is not proven.
Web Bot Auth
Directory and verifier routes are live. The verifier accepts the legacy string form of Signature-Agent only, so it rejects signatures that use the dictionary form the -00 draft requires. AgentCheck signs its outbound page requests when a Web Bot Auth key is provisioned; other outbound agent HTTP calls are not signed.
Visa Trusted Agent Protocol
Merchant-scoped TAP registry, public key lookup, and Shopify verification flow are live. A generic public TAP verifier is not exposed yet.
Agent Payments Protocol (AP2)
/api/v1/ap2/mandate derives AP2 v0.2 open Checkout and Payment mandate bodies from a KYA trace, bound to a proof key the trace's agent registered and paying the merchant in the trace audience. /api/v1/ap2/verify rebuilds the mandate from a stored or signed trace, rejects revoked traces and traces used by another party, checks a closed payment's payee, amount, and date, and fails on constraints it cannot evaluate. It does not track repeat presentations. The signed envelope is the KYA trace JWS, not SD-JWT, and mandates signed by other parties are not verified.
Mastercard Verifiable Intent
Open draft spec for a signed record of the user's instruction that can be checked against the final cart. KYA traces carry scope, max_amount, and action_hash, but KYA does not issue or verify Verifiable Intent credentials.
Universal Commerce Protocol (UCP)
Open standard for catalog, cart, checkout, identity linking, and orders. KYA publishes a UCP profile at /.well-known/ucp for its Shopify sandbox catalog demo; it does not carry traces through UCP checkout.
Dated changes, newest first.
We re-check every entry against its primary source and log what moved. Announced dates that have not arrived are listed separately.
Coming up
Changed
- 2026-10-06
Meta and Sierra announce PAP. Decagon publishes PACT 1.0 the same day.
Source - 2026-09-30
Mastercard says it is working with Skyfire, which it calls a provider of Know Your Agent (KYA) technology.
Source - 2026-09-23
x402 adds Lightning to the spec. No SDK support yet.
Source - 2026-09-11
Ant International publishes AMP on GitHub.
Source - 2026-09-10
Ant International, Mastercard, and Visa say they will explore common principles for a Know-Your-Agent interoperability framework. No spec or timeline yet.
Source - 2026-09-09
MPP’s IETF draft continues as draft-httpauth-payment-01.
Source - 2026-09-01
The IETF webbotauth working group adopts Web Bot Auth as a working-group draft.
Source - 2026-08-27
A2A joins the Agentic AI Foundation.
Source - 2026-08-25
UCP publishes version 2026-08-25.
Source - 2026-07-14
The x402 Foundation becomes operational under the Linux Foundation.
Source - 2026-06-10
Mastercard launches Agent Pay for Machines.
Source - 2026-04-28
Google donates AP2 to the FIDO Alliance. Mastercard contributes Verifiable Intent.
Source - 2026-04-24
Meta joins OpenAI and Stripe as an ACP maintainer.
Source - 2026-04-18
Visa’s rules allow digital wallets and pass-through digital wallets in agentic transactions.
Source - 2026-04-14
American Express announces its Agentic Commerce Experiences developer kit.
Source - 2026-04-08
Visa starts piloting Intelligent Commerce Connect, which accepts TAP, MPP, ACP, and UCP.
Source
Short answers.
What is the difference between ACP and UCP?
Both define how an AI agent places an order with a merchant. ACP, maintained by OpenAI, Stripe, and Meta, centers on checkout sessions and delegated payment through a scoped token, and is still labeled beta. UCP, founded by Google and Shopify, covers catalog, cart, checkout, identity linking, and orders over REST, MCP, A2A, or an embedded transport. In both, the merchant stays merchant of record.
Do agentic commerce protocols change chargeback rules?
No. Card network rules still decide disputes. Visa’s April 2026 rules treat an agentic payment provider as the cardholder and hold the cardholder responsible for its actions. From 24 October 2026, a login ID used with an agentic payment provider can count as matching evidence in some card-absent fraud disputes. The protocols supply evidence such as signatures, mandates, and receipts.
Is Web Bot Auth the same as Visa TAP?
No. Both build on RFC 9421 HTTP Message Signatures, and Visa describes TAP as aligned with Web Bot Auth. Web Bot Auth is an IETF draft that uses the web-bot-auth tag and a key directory named in the request. Visa TAP uses its own tags, keys that Visa publishes, an 8-minute nonce window, and optional consumer and payment data. A verifier written for one does not check the other as-is.
Does a valid agent signature prove the buyer approved the order?
No. A Web Bot Auth or Visa TAP signature shows that the request was signed with a published key. What the buyer allowed is a separate record, such as an AP2 mandate, a Verifiable Intent credential, or a PACT consent grant. Keep both, and keep them apart.
How this page is checked: each entry was compared with its primary source on 7 Oct 2026, and versions are the latest we found that day. If something here is wrong or out of date, send a correction. We fix it and log the change above.
See what your agent orders leave behind.
We’ll map the specs that reach your checkout today to the evidence you keep for each order, and mark what is missing.