{"name":"KYA agentic commerce protocol map","url":"https://knowyouragent.xyz/protocols","verified_on":"2026-10-07","layers":[{"id":"transport","index":"L1","name":"Agent transport","question":"How does the agent reach tools and other agents?"},{"id":"identity","index":"L2","name":"Agent identity","question":"Who sent this request?"},{"id":"authority","index":"L3","name":"Authority and consent","question":"What did the person allow the agent to do?"},{"id":"commerce","index":"L4","name":"Commerce","question":"What is being bought, and on what terms?"},{"id":"payment","index":"L5","name":"Payment","question":"How does the money move?"},{"id":"program","index":"NET","name":"Network programs","question":"Which card-network bundles use these specs?"}],"entries":[{"id":"mcp","short":"MCP","name":"Model Context Protocol","layer":"transport","owner":"Agentic AI Foundation (Linux Foundation). Created by Anthropic.","status":"Open standard","version":"2026-07-28","license":null,"since":"2024-11-25","summary":"Connects an AI application to tools, data, and prompts. UCP and ACP both offer MCP bindings.","in_dispute":"Whatever tool-call log the host keeps. Access to a tool is not permission to buy.","guide_url":null,"sources":[{"label":"Specification","url":"https://modelcontextprotocol.io"},{"label":"Donation to the Agentic AI Foundation (9 Dec 2025)","url":"https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation"}]},{"id":"a2a","short":"A2A","name":"Agent2Agent Protocol","layer":"transport","owner":"Agentic AI Foundation since Aug 2026. Created by Google, then a Linux Foundation project.","status":"Open standard","version":"v1.0.1","license":null,"since":"2025-04-09","summary":"Lets agents built on different frameworks find each other through Agent Cards and work on tasks together. PACT and AP2 build on it.","in_dispute":"Task history between agents. Nothing specific to orders or payment.","guide_url":null,"sources":[{"label":"Specification","url":"https://a2a-protocol.org"},{"label":"A2A joins the Agentic AI Foundation (27 Aug 2026)","url":"https://a2a-protocol.org/latest/blog/2026/08/27/a-new-chapter-for-a2a-joining-the-agentic-ai-foundation/"}]},{"id":"web-bot-auth","short":"Web Bot Auth","name":"Web Bot Auth","layer":"identity","owner":"IETF webbotauth working group. Authors from Cloudflare and Google.","status":"IETF working-group draft","version":"draft-ietf-webbotauth-httpsig-protocol-00","license":null,"since":null,"summary":"An agent signs its HTTP requests and names a published key directory, so a site can verify the signature instead of trusting a user-agent string or IP address.","in_dispute":"Proof that a holder of a key published at a given URL signed the request. The draft says this shows nothing about who operates the agent or whether the request is authorized.","guide_url":"https://knowyouragent.xyz/protocols/web-bot-auth","sources":[{"label":"IETF draft","url":"https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/"},{"label":"Working group","url":"https://datatracker.ietf.org/wg/webbotauth/about/"}]},{"id":"visa-tap","short":"Visa TAP","name":"Trusted Agent Protocol","layer":"identity","owner":"Visa, developed with Cloudflare.","status":"Live","version":null,"license":"Visa developer terms (not an open-source licence)","since":"2025-10-14","summary":"Visa’s profile of HTTP Message Signatures. An approved agent signs its browsing and payment requests and can carry intent, consumer-recognition, and payment data.","in_dispute":"A signature tying the request to a Visa-approved agent. Visa says TAP aims to reduce chargebacks from unauthorized transactions; it defines no dispute process.","guide_url":"https://knowyouragent.xyz/protocols/visa-tap","sources":[{"label":"Specification","url":"https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications/"},{"label":"Visa announcement (14 Oct 2025)","url":"https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.21716.html"},{"label":"Reference code and README","url":"https://github.com/visa/trusted-agent-protocol"}]},{"id":"tacp","short":"TACP","name":"Trusted Agentic Commerce Protocol","layer":"identity","owner":"Forter","status":"Open spec","version":null,"license":"MIT","since":"2025-08-27","summary":"Mutual authentication between agent and merchant, with signed and encrypted messages (JWS, JWE, JWKS).","in_dispute":"Signed messages between agent and merchant. No dispute format.","guide_url":null,"sources":[{"label":"Repository","url":"https://github.com/forter/trusted-agentic-commerce-protocol"}]},{"id":"kyapay","short":"KYAPay","name":"KYAPay","layer":"identity","owner":"Skyfire","status":"IETF individual drafts","version":"draft-skyfire-oauth-kyapay-token-02","license":null,"since":null,"summary":"JWT formats for agent identity, payment, or both, plus a draft for exchanging them for OAuth access tokens. Individual drafts have no IETF standing.","in_dispute":"A signed token carrying the agent’s verified identity and, for payment tokens, an amount and currency.","guide_url":null,"sources":[{"label":"Token draft","url":"https://datatracker.ietf.org/doc/draft-skyfire-oauth-kyapay-token/"},{"label":"Token exchange draft","url":"https://datatracker.ietf.org/doc/draft-skyfire-oauth-kyapay-token-exchange/"},{"label":"kyapay.org","url":"https://kyapay.org"}]},{"id":"erc-8004","short":"ERC-8004","name":"Trustless Agents","layer":"identity","owner":"Ethereum ERC","status":"Draft","version":null,"license":null,"since":"2025-08-13","summary":"On-chain registries for agent identity, reputation, and validation. A June 2026 study found that only 3% to 15% of registrations, depending on the chain, had a valid file and a live service endpoint.","in_dispute":"Public on-chain identity and reputation entries for the agent.","guide_url":null,"sources":[{"label":"ERC-8004","url":"https://eips.ethereum.org/EIPS/eip-8004"},{"label":"Empirical study (arXiv 2606.26028)","url":"https://arxiv.org/abs/2606.26028"}]},{"id":"ap2","short":"AP2","name":"Agent Payments Protocol","layer":"authority","owner":"FIDO Alliance since Apr 2026. Created by Google.","status":"Open spec","version":"v0.2","license":"Apache 2.0","since":"2025-09-16","summary":"Signed Checkout and Payment mandates that record what the user approved, whether or not the user is present at purchase.","in_dispute":"Mandates and receipts that the spec calls a non-repudiable picture of the transaction. Retention, retrieval, and dispute resolution are out of its scope.","guide_url":"https://knowyouragent.xyz/protocols/ap2","sources":[{"label":"Specification","url":"https://ap2-protocol.org/ap2/specification/"},{"label":"Google donates AP2 to the FIDO Alliance","url":"https://blog.google/products-and-platforms/platforms/google-pay/agent-payments-protocol-fido-alliance/"}]},{"id":"verifiable-intent","short":"Verifiable Intent","name":"Verifiable Intent","layer":"authority","owner":"Mastercard, co-developed with Google. Contributed to the FIDO Alliance.","status":"Draft","version":"v0.1","license":"Apache 2.0","since":null,"summary":"A signed record of the user’s instruction that can be checked against the final cart. Designed to work with AP2 and UCP.","in_dispute":"Consent becomes “a durable artifact, verifiable after the fact.” The spec does not define how disputes are handled or assign liability.","guide_url":null,"sources":[{"label":"Specification","url":"https://verifiableintent.dev"},{"label":"Repository","url":"https://github.com/agent-intent/verifiable-intent"}]},{"id":"pact","short":"PACT","name":"Personal Agent Consent & Trust","layer":"authority","owner":"Decagon, co-developed with Instinct.","status":"Open spec","version":"PACT 1.0","license":"Apache 2.0","since":"2026-10-06","summary":"The user signs in to the business directly and grants a personal agent narrow scopes. Built on A2A 1.0 and OAuth 2.0.","in_dispute":"Under the Delegated profile, a signed receipt with each reply sent under a delegation token, recording the scopes used and actions taken. Nothing on payments or disputes.","guide_url":"https://knowyouragent.xyz/protocols/pap-vs-pact","sources":[{"label":"Specification","url":"https://openpactprotocol.org"},{"label":"Repository","url":"https://github.com/openpactprotocol/openpactprotocol"}]},{"id":"pap","short":"PAP","name":"Personal Agent Protocol","layer":"authority","owner":"Meta and Sierra, with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart.","status":"Announced. v0.1 spec promised for October 2026.","version":null,"license":null,"since":"2026-10-06","summary":"OAuth sessions for personal agents working with a business through its website, its APIs, or its own agent. A session can start as a guest; the customer grants read-only or write access.","in_dispute":"No spec published yet. Sierra says payments extensions could come later.","guide_url":"https://knowyouragent.xyz/protocols/pap-vs-pact","sources":[{"label":"Sierra announcement (6 Oct 2026)","url":"https://sierra.ai/blog/introducing-personal-agent-protocol"}]},{"id":"ucp","short":"UCP","name":"Universal Commerce Protocol","layer":"commerce","owner":"Founded by Google and Shopify. Stripe sits on the governing council.","status":"Live","version":"2026-08-25","license":"Apache 2.0","since":"2026-01-11","summary":"Catalog, cart, checkout, identity linking, and orders over REST, MCP, A2A, or an embedded transport. The merchant stays merchant of record.","in_dispute":"Order adjustments, where dispute is one example of an open-string type with no evidence fields. The optional AP2 mandates extension adds signed authorization.","guide_url":"https://knowyouragent.xyz/protocols/ucp","sources":[{"label":"Specification","url":"https://ucp.dev/latest/specification/overview/"},{"label":"Repository","url":"https://github.com/Universal-Commerce-Protocol/ucp"},{"label":"Governing council members","url":"https://github.com/Universal-Commerce-Protocol/.github/blob/main/MAINTAINERS.md"}]},{"id":"acp","short":"ACP","name":"Agentic Commerce Protocol","layer":"commerce","owner":"OpenAI, Stripe, and Meta (maintainers).","status":"Beta","version":"2026-04-17","license":"Apache 2.0","since":"2025-09-29","summary":"Checkout sessions, carts, product feeds, order updates, and delegated payment through a scoped token such as Stripe’s Shared Payment Token. The merchant stays merchant of record.","in_dispute":"Signed order webhooks. Dispute is a defined adjustment type that “covers chargebacks,” with a free-text reason and no evidence format.","guide_url":"https://knowyouragent.xyz/protocols/acp","sources":[{"label":"Repository","url":"https://github.com/agentic-commerce-protocol/agentic-commerce-protocol"},{"label":"Documentation","url":"https://www.agenticcommerce.dev/docs"}]},{"id":"x402","short":"x402","name":"x402","layer":"payment","owner":"x402 Foundation (Linux Foundation). Created by Coinbase.","status":"Live","version":"v2","license":"Apache 2.0","since":"2025-05-06","summary":"HTTP 402 payments: the server states a price, the client pays (mostly in stablecoins), and the request goes through. Lightning was added to the spec in Sep 2026, not yet to the SDKs.","in_dispute":"An optional signed-receipt extension meant for dispute evidence; its wire format is not yet stable. No card chargeback rights.","guide_url":null,"sources":[{"label":"Repository and specs","url":"https://github.com/x402-foundation/x402"},{"label":"Offer and receipt extension","url":"https://github.com/x402-foundation/x402/blob/main/specs/extensions/extension-offer-and-receipt.md"},{"label":"x402 Foundation launch","url":"https://x402.org/linux-foundation-announces-operational-launch-of-x402-foundation-to-standardize-internet-native-payments-for-ai-agents-and-applications/"}]},{"id":"mpp","short":"MPP","name":"Machine Payments Protocol","layer":"payment","owner":"Stripe and Tempo","status":"Open spec","version":null,"license":"CC0","since":"2026-03-18","summary":"HTTP 402 payment authorization for one-off charges, subscriptions, and sessions, across stablecoins, cards, Lightning, and other methods. Published as the IETF individual draft draft-httpauth-payment.","in_dispute":"Servers should include a Payment-Receipt header on successful paid responses. No dispute format.","guide_url":null,"sources":[{"label":"Specification","url":"https://mpp.dev/protocol"},{"label":"IETF individual draft","url":"https://datatracker.ietf.org/doc/draft-httpauth-payment/"},{"label":"Stripe announcement (18 Mar 2026)","url":"https://stripe.com/blog/machine-payments-protocol"}]},{"id":"l402","short":"L402","name":"L402","layer":"payment","owner":"Lightning Labs","status":"In production since 2020 (as LSAT).","version":null,"license":null,"since":null,"summary":"Pay-per-request API access using Lightning invoices and macaroons.","in_dispute":"Proof that an invoice was paid. Lightning payments have no chargebacks.","guide_url":null,"sources":[{"label":"Specification","url":"https://github.com/lightninglabs/L402"},{"label":"Documentation","url":"https://docs.lightning.engineering/the-lightning-network/l402"},{"label":"Lightning Labs launch post, Mar 2020","url":"https://lightning.engineering/posts/2020-03-30-lsat/"}]},{"id":"ack","short":"ACK","name":"Agent Commerce Kit","layer":"payment","owner":"Catena Labs","status":"Open source","version":null,"license":"MIT","since":null,"summary":"ACK-ID for agent identity with decentralized identifiers and verifiable credentials, and ACK-Pay for payments. A proposed v2 would drop the credential requirement and map ACK-Pay onto x402.","in_dispute":"A receipt issued as a verifiable credential, proving a payment requirement was met.","guide_url":null,"sources":[{"label":"Repository","url":"https://github.com/agentcommercekit/ack"},{"label":"ACK v2 proposal","url":"https://catena.com/blog/ack-v2-smaller-identity-core-x402-payment-profile"}]},{"id":"amp","short":"AMP","name":"Agentic Mobile Protocol","layer":"payment","owner":"Ant International","status":"Open source","version":null,"license":"Apache 2.0","since":"2026-04-28","summary":"Ant International’s protocol for agent payments. Its first phase covers 10 Alipay+ wallets and 7 acquirers.","in_dispute":"Ant offers AgentSafePay, a money-back guarantee for AMP transactions. That is a commercial promise, not a protocol rule.","guide_url":null,"sources":[{"label":"Repository","url":"https://github.com/ant-intl/AMP"},{"label":"Global rollout, 11 Sep 2026","url":"https://www.prnewswire.com/apac/news-releases/ant-internationals-agentic-mobile-protocol-rolls-out-globally-with-wallets-and-acquirers-initiating-collaboration-on-kya-interoperability-framework-with-mastercard-and-visa-302876108.html"}]},{"id":"visa-intelligent-commerce","short":"Visa Intelligent Commerce","name":"Visa Intelligent Commerce","layer":"program","owner":"Visa","status":"Program","version":null,"license":null,"since":null,"summary":"Visa’s agent commerce program. Under Visa’s rules, agentic payment providers must enroll in it. TAP is part of it, and Intelligent Commerce Connect, a pilot since April 2026, accepts payments started through TAP, MPP, ACP, and UCP.","in_dispute":"Visa Core Rules apply: the agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions.","guide_url":null,"sources":[{"label":"Intelligent Commerce Connect, 8 Apr 2026","url":"https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.22276.html"},{"label":"Visa Core Rules, Apr 2026 edition","url":"https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf"}]},{"id":"mastercard-agent-pay","short":"Agent Pay","name":"Mastercard Agent Pay","layer":"program","owner":"Mastercard","status":"Program","version":null,"license":null,"since":"2025-04-29","summary":"Mastercard’s agent payment program, built on Agentic Tokens. In October 2025 Mastercard said it is incorporating Web Bot Auth into Agent Pay. Agent Pay for Machines followed in June 2026.","in_dispute":"We found no published Mastercard dispute rule specific to agent transactions.","guide_url":null,"sources":[{"label":"Agent Pay announcement, Apr 2025","url":"https://newsroom.mastercard.com/news/press/2025/april/mastercard-unveils-agent-pay-pioneering-agentic-payments-technology-to-power-commerce-in-the-age-of-ai/"},{"label":"Cloudflare on Web Bot Auth in Agent Pay, Oct 2025","url":"https://www.cloudflare.com/press/press-releases/2025/cloudflare-collaborates-with-leading-payments-companies-to-secure-and-enable-agentic-commerce/"},{"label":"Agent Pay for Machines, Jun 2026","url":"https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html"}]},{"id":"amex-ace","short":"Amex ACE","name":"American Express Agentic Commerce Experiences","layer":"program","owner":"American Express","status":"Developer kit. Two specs in development.","version":null,"license":null,"since":"2026-04-14","summary":"Five services: agent registration, account enablement, intent intelligence, payment credentials, and cart context. The agent registration and cart context specs are still in development.","in_dispute":"American Express describes purchase protection for purchases by registered agents as a future feature.","guide_url":null,"sources":[{"label":"American Express agentic commerce","url":"https://www.americanexpress.com/en-us/company/agentic-commerce/"}]}],"dispute_rules":[{"source":"Visa Core Rules, 18 Apr 2026 edition","says":"An agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions “as if the Cardholder initiated the Transaction.” The provider must keep an order confirmation available to the cardholder for at least 120 days. The dispute chapter has no agent-specific condition.","url":"https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf"},{"source":"Visa dispute condition 10.4, from 24 Oct 2026","says":"In card-absent fraud disputes, the login ID used with an agentic payment provider can count as a matching data element, when the same card was used in two earlier undisputed transactions.","url":"https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf"},{"source":"AP2 v0.2","says":"Mandates and receipts give a “non-repudiable picture” of the transaction. Dispute resolution, retention, and retrieval are outside the spec’s scope.","url":"https://ap2-protocol.org/ap2/specification/#dispute-evidence"},{"source":"Verifiable Intent v0.1","says":"Evidence only. It “does not define how disputes are initiated, routed between parties, escalated, or resolved,” and does not assign liability or chargeback codes.","url":"https://verifiableintent.dev/spec/security-model/#25-dispute-evidence"},{"source":"ACP 2026-04-17","says":"Dispute is a defined order adjustment type: “‘dispute’ covers chargebacks.” The reason is free text and there is no evidence format.","url":"https://github.com/agentic-commerce-protocol/agentic-commerce-protocol"},{"source":"UCP 2026-08-25","says":"An order adjustment can be typed dispute, an open string with no reason-code or evidence fields. UCP supplies signed authorization through the optional AP2 mandates extension; other consent systems can supply separate evidence.","url":"https://ucp.dev/latest/specification/shopping/order/"},{"source":"Visa TAP","says":"The reference code’s README says TAP aims to “minimize chargebacks from unauthorized transactions.” The specification defines no dispute mechanism.","url":"https://github.com/visa/trusted-agent-protocol"},{"source":"x402","says":"Optional signed offers and receipts, intended in part for dispute evidence. The wire format is marked not stable.","url":"https://github.com/x402-foundation/x402/blob/main/specs/extensions/extension-offer-and-receipt.md"},{"source":"PACT 1.0","says":"Under the Delegated profile, each reply sent under a delegation token carries a signed receipt of scopes used and actions taken, and personal agents should keep them. Nothing on payments or disputes.","url":"https://openpactprotocol.org"},{"source":"PAP","says":"No spec yet. Nothing on receipts or disputes.","url":"https://sierra.ai/blog/introducing-personal-agent-protocol"}],"changes":[{"date":"2026-10-06","text":"Meta and Sierra announce PAP. Decagon publishes PACT 1.0 the same day.","url":"https://sierra.ai/blog/introducing-personal-agent-protocol"},{"date":"2026-09-30","text":"Mastercard says it is working with Skyfire, which it calls a provider of Know Your Agent (KYA) technology.","url":"https://www.financialcontent.com/article/bizwire-2026-9-30-mastercard-advances-agentic-commerce-with-new-trust-and-intelligence-services"},{"date":"2026-09-23","text":"x402 adds Lightning to the spec. No SDK support yet.","url":"https://github.com/x402-foundation/x402/pull/2861"},{"date":"2026-09-11","text":"Ant International publishes AMP on GitHub.","url":"https://www.prnewswire.com/apac/news-releases/ant-internationals-agentic-mobile-protocol-rolls-out-globally-with-wallets-and-acquirers-initiating-collaboration-on-kya-interoperability-framework-with-mastercard-and-visa-302876108.html"},{"date":"2026-09-10","text":"Ant International, Mastercard, and Visa say they will explore common principles for a Know-Your-Agent interoperability framework. No spec or timeline yet.","url":"https://en.prnasia.com/releases/apac/ant-international-mastercard-and-visa-initiate-collaboration-on-know-your-agent-interoperability-to-scale-agentic-commerce-547272.shtml"},{"date":"2026-09-09","text":"MPP’s IETF draft continues as draft-httpauth-payment-01.","url":"https://datatracker.ietf.org/doc/draft-httpauth-payment/"},{"date":"2026-09-01","text":"The IETF webbotauth working group adopts Web Bot Auth as a working-group draft.","url":"https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/"},{"date":"2026-08-27","text":"A2A joins the Agentic AI Foundation.","url":"https://a2a-protocol.org/latest/blog/2026/08/27/a-new-chapter-for-a2a-joining-the-agentic-ai-foundation/"},{"date":"2026-08-25","text":"UCP publishes version 2026-08-25.","url":"https://ucp.dev/latest/specification/overview/"},{"date":"2026-07-14","text":"The x402 Foundation becomes operational under the Linux Foundation.","url":"https://x402.org/linux-foundation-announces-operational-launch-of-x402-foundation-to-standardize-internet-native-payments-for-ai-agents-and-applications/"},{"date":"2026-06-10","text":"Mastercard launches Agent Pay for Machines.","url":"https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html"},{"date":"2026-04-28","text":"Google donates AP2 to the FIDO Alliance. Mastercard contributes Verifiable Intent.","url":"https://blog.google/products-and-platforms/platforms/google-pay/agent-payments-protocol-fido-alliance/"},{"date":"2026-04-24","text":"Meta joins OpenAI and Stripe as an ACP maintainer.","url":"https://github.com/agentic-commerce-protocol/agentic-commerce-protocol"},{"date":"2026-04-18","text":"Visa’s rules allow digital wallets and pass-through digital wallets in agentic transactions.","url":"https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf"},{"date":"2026-04-14","text":"American Express announces its Agentic Commerce Experiences developer kit.","url":"https://www.americanexpress.com/en-us/company/agentic-commerce/"},{"date":"2026-04-08","text":"Visa starts piloting Intelligent Commerce Connect, which accepts TAP, MPP, ACP, and UCP.","url":"https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.22276.html"}],"upcoming":[{"date":"2026-10","text":"Meta and Sierra plan to publish the PAP v0.1 specification this month.","url":"https://sierra.ai/blog/introducing-personal-agent-protocol"},{"date":"2026-10-24","text":"Visa’s updated card-absent fraud rule (dispute condition 10.4) applies, including login IDs for agentic payment providers.","url":"https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf"}]}