/ PROTOCOLSVerified 7 Oct 2026

Agentic commerce protocols, layer by layer.

An agent order passes through several specs at once. One carries the request, one says who sent it, one records what the buyer allowed, one runs the order, and one moves the money. This map lists each spec, who runs it, how far along it is, and what it leaves on the record when an order is questioned.

18 specs3 network programsChecked 2026-10-07Primary source on every entry
/ 01The stack

Five layers, read from the wire up.

Most agent orders touch several layers. Each layer answers one question, and no spec answers all five. Card-network programs bundle specs from more than one layer.

L1

Agent transport

How does the agent reach tools and other agents?

L2

Agent identity

Who sent this request?

L3

Authority and consent

What did the person allow the agent to do?

L4

Commerce

What is being bought, and on what terms?

L5

Payment

How does the money move?

NET

Network programs

Which card-network bundles use these specs?

/ 02Index

Each spec, with its owner, status, and sources.

Status and version are as of 7 Oct 2026. “On the record” is what the spec leaves behind when an order is questioned. Where KYA reads a spec, the tag shows how far that work has gone.

L1 · Agent transport

MCP

Model Context Protocol

Agentic AI Foundation (Linux Foundation). Created by Anthropic.

Connects an AI application to tools, data, and prompts. UCP and ACP both offer MCP bindings.

On the recordWhatever tool-call log the host keeps. Access to a tool is not permission to buy.

Open standardVersion 2026-07-28Since 25 Nov 2024

A2A

Agent2Agent Protocol

Agentic AI Foundation since Aug 2026. Created by Google, then a Linux Foundation project.

Lets agents built on different frameworks find each other through Agent Cards and work on tasks together. PACT and AP2 build on it.

On the recordTask history between agents. Nothing specific to orders or payment.

L2 · Agent identity

Web Bot Auth

IETF webbotauth working group. Authors from Cloudflare and Google.

An agent signs its HTTP requests and names a published key directory, so a site can verify the signature instead of trusting a user-agent string or IP address.

On the recordProof that a holder of a key published at a given URL signed the request. The draft says this shows nothing about who operates the agent or whether the request is authorized.

IETF working-group draftVersion draft-ietf-webbotauth-httpsig-protocol-00
KYA: beta

Visa TAP

Trusted Agent Protocol

Visa, developed with Cloudflare.

Visa’s profile of HTTP Message Signatures. An approved agent signs its browsing and payment requests and can carry intent, consumer-recognition, and payment data.

On the recordA signature tying the request to a Visa-approved agent. Visa says TAP aims to reduce chargebacks from unauthorized transactions; it defines no dispute process.

LiveLicence: Visa developer terms (not an open-source licence)Since 14 Oct 2025
KYA: beta

TACP

Trusted Agentic Commerce Protocol

Forter

Mutual authentication between agent and merchant, with signed and encrypted messages (JWS, JWE, JWKS).

On the recordSigned messages between agent and merchant. No dispute format.

Open specLicence: MITSince 27 Aug 2025

KYAPay

Skyfire

JWT formats for agent identity, payment, or both, plus a draft for exchanging them for OAuth access tokens. Individual drafts have no IETF standing.

On the recordA signed token carrying the agent’s verified identity and, for payment tokens, an amount and currency.

IETF individual draftsVersion draft-skyfire-oauth-kyapay-token-02

ERC-8004

Trustless Agents

Ethereum ERC

On-chain registries for agent identity, reputation, and validation. A June 2026 study found that only 3% to 15% of registrations, depending on the chain, had a valid file and a live service endpoint.

On the recordPublic on-chain identity and reputation entries for the agent.

L3 · Authority and consent

AP2

Agent Payments Protocol

FIDO Alliance since Apr 2026. Created by Google.

Signed Checkout and Payment mandates that record what the user approved, whether or not the user is present at purchase.

On the recordMandates and receipts that the spec calls a non-repudiable picture of the transaction. Retention, retrieval, and dispute resolution are out of its scope.

Open specVersion v0.2Licence: Apache 2.0Since 16 Sept 2025
KYA: beta

Verifiable Intent

Mastercard, co-developed with Google. Contributed to the FIDO Alliance.

A signed record of the user’s instruction that can be checked against the final cart. Designed to work with AP2 and UCP.

On the recordConsent becomes “a durable artifact, verifiable after the fact.” The spec does not define how disputes are handled or assign liability.

DraftVersion v0.1Licence: Apache 2.0
KYA: planned

PACT

Personal Agent Consent & Trust

Decagon, co-developed with Instinct.

The user signs in to the business directly and grants a personal agent narrow scopes. Built on A2A 1.0 and OAuth 2.0.

On the recordUnder the Delegated profile, a signed receipt with each reply sent under a delegation token, recording the scopes used and actions taken. Nothing on payments or disputes.

Open specVersion PACT 1.0Licence: Apache 2.0Since 6 Oct 2026

PAP

Personal Agent Protocol

Meta and Sierra, with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart.

OAuth sessions for personal agents working with a business through its website, its APIs, or its own agent. A session can start as a guest; the customer grants read-only or write access.

On the recordNo spec published yet. Sierra says payments extensions could come later.

Announced. v0.1 spec promised for October 2026.Since 6 Oct 2026

L4 · Commerce

UCP

Universal Commerce Protocol

Founded by Google and Shopify. Stripe sits on the governing council.

Catalog, cart, checkout, identity linking, and orders over REST, MCP, A2A, or an embedded transport. The merchant stays merchant of record.

On the recordOrder adjustments, where dispute is one example of an open-string type with no evidence fields. The optional AP2 mandates extension adds signed authorization.

LiveVersion 2026-08-25Licence: Apache 2.0Since 11 Jan 2026
KYA: planned

ACP

Agentic Commerce Protocol

OpenAI, Stripe, and Meta (maintainers).

Checkout sessions, carts, product feeds, order updates, and delegated payment through a scoped token such as Stripe’s Shared Payment Token. The merchant stays merchant of record.

On the recordSigned order webhooks. Dispute is a defined adjustment type that “covers chargebacks,” with a free-text reason and no evidence format.

BetaVersion 2026-04-17Licence: Apache 2.0Since 29 Sept 2025

L5 · Payment

x402

x402 Foundation (Linux Foundation). Created by Coinbase.

HTTP 402 payments: the server states a price, the client pays (mostly in stablecoins), and the request goes through. Lightning was added to the spec in Sep 2026, not yet to the SDKs.

On the recordAn optional signed-receipt extension meant for dispute evidence; its wire format is not yet stable. No card chargeback rights.

MPP

Machine Payments Protocol

Stripe and Tempo

HTTP 402 payment authorization for one-off charges, subscriptions, and sessions, across stablecoins, cards, Lightning, and other methods. Published as the IETF individual draft draft-httpauth-payment.

On the recordServers should include a Payment-Receipt header on successful paid responses. No dispute format.

L402

Lightning Labs

Pay-per-request API access using Lightning invoices and macaroons.

On the recordProof that an invoice was paid. Lightning payments have no chargebacks.

ACK

Agent Commerce Kit

Catena Labs

ACK-ID for agent identity with decentralized identifiers and verifiable credentials, and ACK-Pay for payments. A proposed v2 would drop the credential requirement and map ACK-Pay onto x402.

On the recordA receipt issued as a verifiable credential, proving a payment requirement was met.

Open sourceLicence: MIT

AMP

Agentic Mobile Protocol

Ant International

Ant International’s protocol for agent payments. Its first phase covers 10 Alipay+ wallets and 7 acquirers.

On the recordAnt offers AgentSafePay, a money-back guarantee for AMP transactions. That is a commercial promise, not a protocol rule.

Open sourceLicence: Apache 2.0Since 28 Apr 2026

NET · Network programs

Visa Intelligent Commerce

Visa

Visa’s agent commerce program. Under Visa’s rules, agentic payment providers must enroll in it. TAP is part of it, and Intelligent Commerce Connect, a pilot since April 2026, accepts payments started through TAP, MPP, ACP, and UCP.

On the recordVisa Core Rules apply: the agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions.

Agent Pay

Mastercard Agent Pay

Mastercard

Mastercard’s agent payment program, built on Agentic Tokens. In October 2025 Mastercard said it is incorporating Web Bot Auth into Agent Pay. Agent Pay for Machines followed in June 2026.

On the recordWe found no published Mastercard dispute rule specific to agent transactions.

Amex ACE

American Express Agentic Commerce Experiences

American Express

Five services: agent registration, account enablement, intent intelligence, payment credentials, and cart context. The agent registration and cart context specs are still in development.

On the recordAmerican Express describes purchase protection for purchases by registered agents as a future feature.

Developer kit. Two specs in development.Since 14 Apr 2026
/ 03In a dispute

Card rules decide liability. The specs supply evidence.

Signatures, mandates, and receipts each answer part of a dispute. Most specs leave storing and retrieving them to someone else, and AP2 says so outright.

Visa Core Rules, 18 Apr 2026 edition

An agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions “as if the Cardholder initiated the Transaction.” The provider must keep an order confirmation available to the cardholder for at least 120 days. The dispute chapter has no agent-specific condition.

Source

Visa dispute condition 10.4, from 24 Oct 2026

In card-absent fraud disputes, the login ID used with an agentic payment provider can count as a matching data element, when the same card was used in two earlier undisputed transactions.

Source

AP2 v0.2

Mandates and receipts give a “non-repudiable picture” of the transaction. Dispute resolution, retention, and retrieval are outside the spec’s scope.

Source

Verifiable Intent v0.1

Evidence only. It “does not define how disputes are initiated, routed between parties, escalated, or resolved,” and does not assign liability or chargeback codes.

Source

ACP 2026-04-17

Dispute is a defined order adjustment type: “‘dispute’ covers chargebacks.” The reason is free text and there is no evidence format.

Source

UCP 2026-08-25

An order adjustment can be typed dispute, an open string with no reason-code or evidence fields. UCP supplies signed authorization through the optional AP2 mandates extension; other consent systems can supply separate evidence.

Source

Visa TAP

The reference code’s README says TAP aims to “minimize chargebacks from unauthorized transactions.” The specification defines no dispute mechanism.

Source

x402

Optional signed offers and receipts, intended in part for dispute evidence. The wire format is marked not stable.

Source

PACT 1.0

Under the Delegated profile, each reply sent under a delegation token carries a signed receipt of scopes used and actions taken, and personal agents should keep them. Nothing on payments or disputes.

Source

PAP

No spec yet. Nothing on receipts or disputes.

Source

KYA’s evidence record keeps these pieces together for each agent order: the authorization evidence your store had, the checks it ran, and what happened afterward. Evidence records are in a founding merchant pilot. How an agent order goes on the record

/ 04Read the labels

The distinctions behind most mix-ups.

Identity is not authority

A valid signature ties a request to a published key. A mandate or consent grant says what the agent may do. Web Bot Auth and TAP answer the first question; AP2, Verifiable Intent, and PACT answer the second.

Checkout is not settlement

UCP and ACP structure the order. Card networks, x402, and MPP move the money. AP2 records that the user authorized the payment.

A program is not a protocol

Visa Intelligent Commerce, Mastercard Agent Pay, and Amex ACE are programs. TAP and Agentic Tokens are parts of them. Verifiable Intent is a separate open spec that Mastercard maintains.

TAP is not TACP

Visa TAP signs HTTP requests with agent identity and intent. Forter’s TACP is a separate, MIT-licensed protocol for mutual authentication and encrypted exchange.

PAP is not PACT

Both were announced on 6 October 2026, and Instinct works on both. PAP (Meta and Sierra) has no published spec yet. PACT (Decagon) published a 1.0 spec the same day.

KYA is not KYAPay

“Know Your Agent” is a category. KYAPay is Skyfire’s token protocol. KnowYourAgent is the company that publishes this page. Four meanings of the term

/ 05Where KYA fits

What KYA reads today, and what it does not.

KYA reads some of these specs today and plans to read others. It does not replace any of them. The status below comes from the same registry as our public manifest at /api/v1/meta/protocols.

KYA Agent Trust Trace

Ed25519-signed trace JWTs bind an agent request to a hashed principal, audience, scope, and spending limit. External adoption is not proven.

KYA: beta

Web Bot Auth

Directory and verifier routes are live. The verifier accepts the legacy string form of Signature-Agent only, so it rejects signatures that use the dictionary form the -00 draft requires. AgentCheck signs its outbound page requests when a Web Bot Auth key is provisioned; other outbound agent HTTP calls are not signed.

KYA: beta

Visa Trusted Agent Protocol

Merchant-scoped TAP registry, public key lookup, and Shopify verification flow are live. A generic public TAP verifier is not exposed yet.

KYA: beta

Agent Payments Protocol (AP2)

/api/v1/ap2/mandate derives AP2 v0.2 open Checkout and Payment mandate bodies from a KYA trace, bound to a proof key the trace's agent registered and paying the merchant in the trace audience. /api/v1/ap2/verify rebuilds the mandate from a stored or signed trace, rejects revoked traces and traces used by another party, checks a closed payment's payee, amount, and date, and fails on constraints it cannot evaluate. It does not track repeat presentations. The signed envelope is the KYA trace JWS, not SD-JWT, and mandates signed by other parties are not verified.

KYA: beta

Mastercard Verifiable Intent

Open draft spec for a signed record of the user's instruction that can be checked against the final cart. KYA traces carry scope, max_amount, and action_hash, but KYA does not issue or verify Verifiable Intent credentials.

KYA: planned

Universal Commerce Protocol (UCP)

Open standard for catalog, cart, checkout, identity linking, and orders. KYA publishes a UCP profile at /.well-known/ucp for its Shopify sandbox catalog demo; it does not carry traces through UCP checkout.

KYA: planned
/ 06What changed

Dated changes, newest first.

We re-check every entry against its primary source and log what moved. Announced dates that have not arrived are listed separately.

Coming up

  1. 2026-10

    Meta and Sierra plan to publish the PAP v0.1 specification this month.

    Source
  2. 2026-10-24

    Visa’s updated card-absent fraud rule (dispute condition 10.4) applies, including login IDs for agentic payment providers.

    Source

Changed

  1. 2026-10-06

    Meta and Sierra announce PAP. Decagon publishes PACT 1.0 the same day.

    Source
  2. 2026-09-30

    Mastercard says it is working with Skyfire, which it calls a provider of Know Your Agent (KYA) technology.

    Source
  3. 2026-09-23

    x402 adds Lightning to the spec. No SDK support yet.

    Source
  4. 2026-09-11

    Ant International publishes AMP on GitHub.

    Source
  5. 2026-09-10

    Ant International, Mastercard, and Visa say they will explore common principles for a Know-Your-Agent interoperability framework. No spec or timeline yet.

    Source
  6. 2026-09-09

    MPP’s IETF draft continues as draft-httpauth-payment-01.

    Source
  7. 2026-09-01

    The IETF webbotauth working group adopts Web Bot Auth as a working-group draft.

    Source
  8. 2026-08-27

    A2A joins the Agentic AI Foundation.

    Source
  9. 2026-08-25

    UCP publishes version 2026-08-25.

    Source
  10. 2026-07-14

    The x402 Foundation becomes operational under the Linux Foundation.

    Source
  11. 2026-06-10

    Mastercard launches Agent Pay for Machines.

    Source
  12. 2026-04-28

    Google donates AP2 to the FIDO Alliance. Mastercard contributes Verifiable Intent.

    Source
  13. 2026-04-24

    Meta joins OpenAI and Stripe as an ACP maintainer.

    Source
  14. 2026-04-18

    Visa’s rules allow digital wallets and pass-through digital wallets in agentic transactions.

    Source
  15. 2026-04-14

    American Express announces its Agentic Commerce Experiences developer kit.

    Source
  16. 2026-04-08

    Visa starts piloting Intelligent Commerce Connect, which accepts TAP, MPP, ACP, and UCP.

    Source
/ 07Questions

Short answers.

What is the difference between ACP and UCP?

Both define how an AI agent places an order with a merchant. ACP, maintained by OpenAI, Stripe, and Meta, centers on checkout sessions and delegated payment through a scoped token, and is still labeled beta. UCP, founded by Google and Shopify, covers catalog, cart, checkout, identity linking, and orders over REST, MCP, A2A, or an embedded transport. In both, the merchant stays merchant of record.

Do agentic commerce protocols change chargeback rules?

No. Card network rules still decide disputes. Visa’s April 2026 rules treat an agentic payment provider as the cardholder and hold the cardholder responsible for its actions. From 24 October 2026, a login ID used with an agentic payment provider can count as matching evidence in some card-absent fraud disputes. The protocols supply evidence such as signatures, mandates, and receipts.

Is Web Bot Auth the same as Visa TAP?

No. Both build on RFC 9421 HTTP Message Signatures, and Visa describes TAP as aligned with Web Bot Auth. Web Bot Auth is an IETF draft that uses the web-bot-auth tag and a key directory named in the request. Visa TAP uses its own tags, keys that Visa publishes, an 8-minute nonce window, and optional consumer and payment data. A verifier written for one does not check the other as-is.

Does a valid agent signature prove the buyer approved the order?

No. A Web Bot Auth or Visa TAP signature shows that the request was signed with a published key. What the buyer allowed is a separate record, such as an AP2 mandate, a Verifiable Intent credential, or a PACT consent grant. Keep both, and keep them apart.

How this page is checked: each entry was compared with its primary source on 7 Oct 2026, and versions are the latest we found that day. If something here is wrong or out of date, send a correction. We fix it and log the change above.

Next step

See what your agent orders leave behind.

We’ll map the specs that reach your checkout today to the evidence you keep for each order, and mark what is missing.

Request a pilot