/ PROTOCOLS / ACPVerified 7 Oct 2026

ACP: five endpoints and a scoped token.

The Agentic Commerce Protocol (ACP) defines how an AI agent checks out with a merchant: checkout sessions, delegated payment through a scoped token, order updates, and, since version 2026-04-17, carts and product feeds. OpenAI and Stripe released it on 29 September 2025, and Meta joined them as a maintainer in April 2026. It is licensed under Apache 2.0 and labeled beta.

Version 2026-04-17BetaOpenAI, Stripe, MetaApache 2.0
/ 01How it works

What happens on the wire.

  1. 01

    The merchant exposes checkout

    Five REST endpoints create, update, read, complete, and cancel a checkout session. An MCP binding is also defined.

  2. 02

    The agent authenticates

    Requests carry a bearer token. A request signature and timestamp are recommended, not required, and the signature covers canonical JSON rather than following RFC 9421.

  3. 03

    Payment is delegated

    The merchant’s payment provider issues a delegated token, such as Stripe’s Shared Payment Token. It is limited to one checkout session, a maximum amount, a currency, the merchant, and an expiry time.

  4. 04

    The merchant charges as usual

    Authorization and settlement run through the merchant’s own payment provider. The merchant stays merchant of record.

  5. 05

    Order updates go back

    The merchant must send order_create and order_update webhooks to the agent’s platform, signed with HMAC.

/ 02What it proves

What a valid result shows, and what it does not.

Shows

  • The payment token could only be used within its allowance: one checkout session, an amount cap, a currency, the merchant, and an expiry time.
  • Order webhooks came from the merchant, through their HMAC signature.

Does not show

  • Which agent sent a request, beyond holding a bearer token. Request signatures are optional, and there is no public-key discovery like UCP’s.
  • A signed record of what the buyer approved. ACP has no mandate format; it relies on the scoped token and, where used, 3-D Secure through Delegate Authentication.
  • Why a dispute was raised. The dispute adjustment has a free-text reason only.
/ 03In a dispute

What it leaves on the record.

ACP lists dispute as an order adjustment type, and the spec says “‘dispute’ covers chargebacks.” The reason is free text, and there is no evidence format. A draft RFC for seller-backed payment handlers says sellers should report refunds and disputes back to the agent.

The merchant carries the chargeback. OpenAI’s production guide says: “Your platform is responsible for handling refunds and chargebacks, as you accepted the payment directly from the customer as the merchant of record.” Keep the checkout session, the token allowance, and the webhooks you sent with each order.

/ 04For merchants

What to do now.

  1. 01

    If you sell through an ACP agent, find out whether your payment provider issues delegated tokens. Stripe’s Shared Payment Token is the reference.

  2. 02

    Implement the five checkout endpoints and the order webhooks, which the spec requires.

  3. 03

    Verify the request signature when the agent sends one, and record when it does not.

  4. 04

    Keep the checkout session, token allowance, and webhook payloads with the order. You handle the chargebacks.

/ 05Questions

Short answers.

Is ACP the same as ChatGPT Instant Checkout?

No. Instant Checkout was OpenAI’s product on top of ACP. Since March 2026, Shopify says ChatGPT users buying from Shopify merchants complete purchases in an in-app browser that keeps the merchant’s own checkout. The ACP spec continues separately; its latest stable version is 2026-04-17.

Who handles chargebacks on an ACP order?

The merchant, as merchant of record. OpenAI’s production guide says the merchant handles refunds and chargebacks and should report status changes through the order update webhook.

What is a Shared Payment Token?

Stripe’s delegated payment token for ACP. It can only be used within its allowance: one checkout session, a maximum amount, a currency, the merchant, and an expiry time.

Next step

Keep what each agent order leaves behind.

We’ll map what ACP and the other specs reaching your checkout produce to one record per order, with the gaps marked.

Request a pilot