What is the Agent Payments Protocol (AP2)?
Last verified 2026-05-31The Agent Payments Protocol (AP2) is an open, payment-agnostic protocol announced by Google on 16 September 2025 to securely authorize and execute agent-led payments across platforms. It was developed with more than 60 organizations, including Mastercard, PayPal, American Express, Adyen and Coinbase, and is designed as an extension of the Agent2Agent (A2A) protocol and the Model Context Protocol (MCP). AP2 spans cards, stablecoins and real-time bank transfers, and uses verifiable credentials (mandates) to capture user intent. Crypto payments are handled through the A2A x402 extension.
Key facts
| Author / steward | Google, with 60+ partner organizations |
|---|---|
| Announced | 2025-09-16 |
| License | Open specification (public GitHub repository) |
| Governance | Led by Google Cloud, developed openly with more than 60 organizations; public technical specification on GitHub |
| Scope | An open, payment-agnostic protocol to securely initiate and transact agent-led payments across platforms; uses verifiable credentials / mandates to capture user intent |
| Transport | Extension of the Agent2Agent (A2A) protocol and Model Context Protocol (MCP) |
| Payment | Payment-agnostic: cards, stablecoins and real-time bank transfers; crypto via the A2A x402 extension |
| Maturity | announced |
What makes it distinctive
- Announced by Google on 16 September 2025
- Developed with more than 60 organizations (Mastercard, PayPal, American Express, Adyen, Coinbase, Etsy and others)
- Designed as an extension of the A2A protocol and MCP
- Payment-agnostic framework spanning cards, stablecoins and bank transfers
- Crypto payments enabled through the A2A x402 extension
How AP2 works
AP2 addresses one question: how can a merchant and a payment network trust that an agent-initiated payment reflects what the user actually authorized? Its answer is verifiable credentials (mandates): cryptographic records that capture the user’s intent and accompany the transaction. AP2 is payment-agnostic by design, spanning cards, stablecoins and real-time bank transfers, so the same authorization framework works across rails. Crypto payments are handled through the A2A x402 extension, developed with Coinbase and others.
Specification and governance
Google announced AP2 on 16 September 2025 with more than 60 organizations, including Mastercard, PayPal, American Express, Adyen and Coinbase. The protocol is designed as an extension of A2A and MCP, and a public technical specification is available on GitHub (see the announcement and ap2-protocol.org).
How AP2 fits the stack
AP2 sits at the authorization layer, above the transport protocols and beside the checkout standards. UCP states compatibility with AP2 mandates; ACP solves checkout for a specific surface while AP2 aims at cross-platform payment authorization (ACP vs AP2); and it extends rather than competes with MCP (AP2 vs MCP).
Limitations and open questions
AP2 is the broadest framework of the group but also the one whose production deployments are least visible in primary sources so far: the September 2025 announcement emphasized partners and design rather than live consumer flows. Its maturity tag on this site remains announced until shipping deployments are verifiable. The interplay between AP2 mandates and UCP checkout in real deployments is the main thing to watch.
Who should care
Payment networks, issuers and PSPs that need an authorization model for agent-led payments across rails, and platforms that want one framework rather than per-network integrations.
Adoption
- Google Cloud: Protocol author (2025-09-16). source
- Mastercard: Payment network (2025-09-16). source
- PayPal: Payments platform (2025-09-16). source
- American Express: Payment network (2025-09-16). source
- Coinbase: Crypto / x402 extension (2025-09-16). source
- Intuit: Financial software (2025-09-16). source
- Worldpay: Payment processor (2025-09-16). source
- Salesforce: CRM and commerce (2025-09-16). source