What is the Agent Payments Protocol (AP2)?

Last verified 2026-09-01

The Agent Payments Protocol (AP2) is an open, payment-agnostic protocol announced by Google on 16 September 2025 to securely authorize and execute agent-led payments across platforms. It was developed with more than 60 organizations, including Mastercard, PayPal, American Express, Adyen and Coinbase, and is designed as an extension of the Agent2Agent (A2A) protocol and the Model Context Protocol (MCP). AP2 spans cards, stablecoins and real-time bank transfers, and uses verifiable credentials (mandates) to capture user intent. Crypto payments are handled through the A2A x402 extension.

Key facts

Author / stewardCreated by Google; donated to the FIDO Alliance
Announced2025-09-16
LicenseOpen specification (public GitHub repository)
GovernanceAnnounced and initially led by Google Cloud with more than 60 organizations; ownership transferred to the FIDO Alliance on 28 April 2026 to keep the protocol platform-agnostic and community-led; public technical specification on GitHub
ScopeAn open, payment-agnostic protocol to securely initiate and transact agent-led payments across platforms; uses verifiable credentials / mandates to capture user intent
TransportExtension of the Agent2Agent (A2A) protocol and Model Context Protocol (MCP)
PaymentPayment-agnostic: cards, stablecoins and real-time bank transfers; crypto via the A2A x402 extension
Maturitydonated

What makes it distinctive

  • Announced by Google on 16 September 2025
  • Donated to the FIDO Alliance on 28 April 2026; ownership left Google to keep AP2 platform-agnostic and community-led
  • AP2 v0.2, released the same day, adds Human Not Present payments so an agent can execute a pre-authorized purchase autonomously
  • Verifiable Intent, an AP2-compatible tamper-proof log of user-authorized agent actions co-developed with Mastercard, is also being donated to FIDO
  • Developed with more than 60 organizations (Mastercard, PayPal, American Express, Adyen, Coinbase, Etsy and others)
  • Designed as an extension of the A2A protocol and MCP
  • Payment-agnostic framework spanning cards, stablecoins and bank transfers
  • Crypto payments enabled through the A2A x402 extension

How AP2 works

AP2 addresses one question: how can a merchant and a payment network trust that an agent-initiated payment reflects what the user actually authorized? Its answer is verifiable credentials (mandates): cryptographic records that capture the user’s intent and accompany the transaction. AP2 is payment-agnostic by design, spanning cards, stablecoins and real-time bank transfers, so the same authorization framework works across rails. Crypto payments are handled through the A2A x402 extension, developed with Coinbase and others.

Specification and governance

Google announced AP2 on 16 September 2025 with more than 60 organizations, including Mastercard, PayPal, American Express, Adyen and Coinbase. The protocol is designed as an extension of A2A and MCP, and a public technical specification is available on GitHub (see the announcement and ap2-protocol.org).

Governance changed hands on 28 April 2026: Google donated AP2 to the FIDO Alliance, stating that transferring ownership keeps the protocol platform-agnostic and community-led. The same day it released AP2 v0.2, which adds Human Not Present payments so an agent can execute a pre-authorized purchase autonomously. Verifiable Intent, an AP2-compatible record of user-authorized agent actions co-developed with Mastercard, was also donated to FIDO. AP2 joins MCP and A2A among agentic standards governed through foundations, while their transfer histories differ.

How AP2 fits the stack

AP2 sits at the authorization layer, above the transport protocols and beside the checkout standards. UCP states compatibility with AP2 mandates; ACP solves checkout for a specific surface while AP2 aims at cross-platform payment authorization (ACP vs AP2); and it extends rather than competes with MCP (AP2 vs MCP).

Limitations and open questions

AP2 is the broadest framework of the group but also the one whose production deployments are least visible in primary sources so far: the September 2025 announcement emphasized partners and design rather than live consumer flows. Its maturity tag on this site remains announced until shipping deployments are verifiable. The interplay between AP2 mandates and UCP checkout in real deployments is the main thing to watch.

Who should care

Payment networks, issuers and PSPs that need an authorization model for agent-led payments across rails, and platforms that want one framework rather than per-network integrations.

Adoption

  • Google Cloud: Protocol author (2025-09-16). source
  • Mastercard: Payment network (2025-09-16). source
  • PayPal: Payments platform (2025-09-16). source
  • American Express: Payment network (2025-09-16). source
  • Coinbase: Crypto / x402 extension (2025-09-16). source
  • Intuit: Financial software (2025-09-16). source
  • Worldpay: Payment processor (2025-09-16). source
  • Salesforce: CRM and commerce (2025-09-16). source
  • FIDO Alliance: Standards body (2026-04-28). source
  • Mastercard: Payment network (2026-04-28). source

See the full adoption tracker →

Frequently asked questions

Who is behind AP2?
Google announced AP2 on 16 September 2025, developed with more than 60 organizations including Mastercard, PayPal and American Express.
How does AP2 relate to MCP?
AP2 is designed as an extension of the Agent2Agent (A2A) protocol and the Model Context Protocol (MCP).
What payment methods does AP2 support?
It is payment-agnostic: cards, stablecoins and real-time bank transfers, with crypto via the A2A x402 extension.