/ PROTOCOLS / AP2Verified 7 Oct 2026

AP2 mandates, read by the merchant.

The Agent Payments Protocol (AP2) records what a user approved before an AI agent pays, as signed Checkout and Payment mandates. Google announced AP2 on 16 September 2025 and donated it to the FIDO Alliance on 28 April 2026, the day v0.2 was released. It is licensed under Apache 2.0 and works as an extension to A2A and UCP.

Version 0.2FIDO AllianceApache 2.0Extension to A2A and UCP
/ 01How it works

What happens on the wire.

  1. 01

    Open mandates set the limits

    An open mandate carries constraints on what the agent may do, such as allowed payees, an amount range, or execution dates.

  2. 02

    The merchant signs the checkout

    The merchant signs the checkout, with its items and prices, as a JWT.

  3. 03

    Closed mandates bind the order

    The closed Checkout Mandate is bound to that checkout JWT by a hash. The closed Payment Mandate binds the payee, amount, payment instrument, and a transaction ID derived from the checkout.

  4. 04

    Who signs depends on whether the user is there

    With the user present, the user signs the closed mandates on a trusted surface. In autonomous purchases, an agent key signs them, trusted through open mandates the user signed or a trust list of agent providers.

  5. 05

    Receipts come back

    The merchant returns a signed Checkout Receipt, including when verification fails. The payment side returns a Payment Receipt.

/ 02What it proves

What a valid result shows, and what it does not.

Shows

  • The order matched the checkout the merchant signed, through the hash binding.
  • The payment matched a mandate signed by the user, or by an agent key that the user or a trust list vouched for.
  • Each constraint in the open mandate was evaluated. The spec says unknown constraints must count as failing.

Does not show

  • Which agent sent the request on the network. AP2 leaves agent identification to the commerce protocol layer.
  • Delivery, returns, or anything else after payment.
  • How long anyone keeps the mandates, or how they reach a dispute.
/ 03In a dispute

What it leaves on the record.

AP2 has a section on dispute evidence. It says the Checkout Mandate and Receipt and the Payment Mandate and Receipt “can be brought together to provide a non-repudiable picture of the transaction.” The same section says “dispute resolution, retention, and retrieval requirements are outside the scope of this specification.”

The normative spec does not mention liability or chargebacks. AP2’s FAQ says a goal is to help payment networks “establish accountability and liability principles.” The evidence exists only if someone keeps it. The checkout pair can come from the agent or the merchant; the payment pair from the agent, the credential provider, the network, or the processor.

/ 04For merchants

What to do now.

  1. 01

    Require a Checkout Mandate before completing an AP2 checkout. The spec says the merchant must receive one.

  2. 02

    Verify the SD-JWT chain, check the checkout hash, and evaluate every constraint, or hand verification to your payment processor.

  3. 03

    Return a signed Checkout Receipt, including on failure.

  4. 04

    Store the mandates and receipts with the order. AP2 leaves retention to you.

  5. 05

    Record the version you implement. v0.2 replaced v0.1’s Intent and Cart mandates, and parts of v0.2 disagree on the checkout signing algorithm.

/ 05Where KYA fits

What KYA does with AP2 today.

/api/v1/ap2/mandate derives AP2 v0.2 open Checkout and Payment mandate bodies from a KYA trace, bound to a proof key the trace's agent registered and paying the merchant in the trace audience. /api/v1/ap2/verify rebuilds the mandate from a stored or signed trace, rejects revoked traces and traces used by another party, checks a closed payment's payee, amount, and date, and fails on constraints it cannot evaluate. It does not track repeat presentations. The signed envelope is the KYA trace JWS, not SD-JWT, and mandates signed by other parties are not verified.

KYA: beta
/ 06Questions

Short answers.

What happened to Intent Mandates and Cart Mandates?

Those were AP2 v0.1 names. v0.2 defines only Checkout and Payment mandates, each with an open and a closed stage. There is no official migration note, and some SDK code still uses the old names.

Who governs AP2 now?

The FIDO Alliance. Google donated AP2 on 28 April 2026, and it is developed in FIDO’s Payments Technical Working Group, which is chaired by members from Mastercard and Visa.

Does AP2 decide who pays in a dispute?

No. AP2 supplies evidence and leaves dispute resolution, retention, and retrieval out of scope. Card network rules still decide liability.

How does AP2 relate to Verifiable Intent?

AP2 leaves the credential format for user intent open. Mastercard’s Verifiable Intent, co-developed with Google, offers one concrete format and was contributed to the FIDO Alliance alongside AP2.

Next step

Keep what each agent order leaves behind.

We’ll map what AP2 and the other specs reaching your checkout produce to one record per order, with the gaps marked.

Request a pilot