ACP: five endpoints and a scoped token.
The Agentic Commerce Protocol (ACP) defines how an AI agent checks out with a merchant: checkout sessions, delegated payment through a scoped token, order updates, and, since version 2026-04-17, carts and product feeds. OpenAI and Stripe released it on 29 September 2025, and Meta joined them as a maintainer in April 2026. It is licensed under Apache 2.0 and labeled beta.
What happens on the wire.
- 01
The merchant exposes checkout
Five REST endpoints create, update, read, complete, and cancel a checkout session. An MCP binding is also defined.
- 02
The agent authenticates
Requests carry a bearer token. A request signature and timestamp are recommended, not required, and the signature covers canonical JSON rather than following RFC 9421.
- 03
Payment is delegated
The merchant’s payment provider issues a delegated token, such as Stripe’s Shared Payment Token. It is limited to one checkout session, a maximum amount, a currency, the merchant, and an expiry time.
- 04
The merchant charges as usual
Authorization and settlement run through the merchant’s own payment provider. The merchant stays merchant of record.
- 05
Order updates go back
The merchant must send order_create and order_update webhooks to the agent’s platform, signed with HMAC.
What a valid result shows, and what it does not.
Shows
- The payment token could only be used within its allowance: one checkout session, an amount cap, a currency, the merchant, and an expiry time.
- Order webhooks came from the merchant, through their HMAC signature.
Does not show
- Which agent sent a request, beyond holding a bearer token. Request signatures are optional, and there is no public-key discovery like UCP’s.
- A signed record of what the buyer approved. ACP has no mandate format; it relies on the scoped token and, where used, 3-D Secure through Delegate Authentication.
- Why a dispute was raised. The dispute adjustment has a free-text reason only.
What it leaves on the record.
ACP lists dispute as an order adjustment type, and the spec says “‘dispute’ covers chargebacks.” The reason is free text, and there is no evidence format. A draft RFC for seller-backed payment handlers says sellers should report refunds and disputes back to the agent.
The merchant carries the chargeback. OpenAI’s production guide says: “Your platform is responsible for handling refunds and chargebacks, as you accepted the payment directly from the customer as the merchant of record.” Keep the checkout session, the token allowance, and the webhooks you sent with each order.
What to do now.
- 01
If you sell through an ACP agent, find out whether your payment provider issues delegated tokens. Stripe’s Shared Payment Token is the reference.
- 02
Implement the five checkout endpoints and the order webhooks, which the spec requires.
- 03
Verify the request signature when the agent sends one, and record when it does not.
- 04
Keep the checkout session, token allowance, and webhook payloads with the order. You handle the chargebacks.
Short answers.
Is ACP the same as ChatGPT Instant Checkout?
No. Instant Checkout was OpenAI’s product on top of ACP. Since March 2026, Shopify says ChatGPT users buying from Shopify merchants complete purchases in an in-app browser that keeps the merchant’s own checkout. The ACP spec continues separately; its latest stable version is 2026-04-17.
Who handles chargebacks on an ACP order?
The merchant, as merchant of record. OpenAI’s production guide says the merchant handles refunds and chargebacks and should report status changes through the order update webhook.
What is a Shared Payment Token?
Stripe’s delegated payment token for ACP. It can only be used within its allowance: one checkout session, a maximum amount, a currency, the merchant, and an expiry time.
Keep what each agent order leaves behind.
We’ll map what ACP and the other specs reaching your checkout produce to one record per order, with the gaps marked.