The problem AP2 solves

When an AI agent buys something on a user’s behalf, three questions appear:

  • Authorisation: did the agent have the right to make this purchase?
  • Authenticity: was the agent really acting on a specific user’s instruction?
  • Liability: who is responsible in a dispute — the user, the agent or the platform?

Existing payment protocols were never designed for a purchase that a human does not initiate. AP2 is
Google’s answer to that gap.

Architecture: two mandates

AP2 uses a two-layer system of cryptographically signed documents.

Intent Mandate — issued by the user to the agent in advance:

{
  "authorized_categories": ["electronics", "books"],
  "max_price": 200,
  "currency": "USD",
  "valid_until": "2025-12-31",
  "signature": "<user_private_key>"
}

Cart Mandate — produced by the agent at the moment of a specific purchase:

{
  "items": [...],
  "total": 115,
  "merchant": "re:Store",
  "delivery_date": "2025-06-05",
  "intent_mandate_ref": "<hash>",
  "signature": "<agent_key>"
}

The payment system checks both mandates: if the Cart Mandate stays inside the limits of the Intent
Mandate, the transaction is authorised.

Where AP2 sits among agent protocols

AP2 extends A2A (Agent2Agent), Google’s base protocol for interaction between agents. Where MCP
(Anthropic’s Model Context Protocol) solves the problem of connecting agents to tools and data, AP2
solves the problem of financial transactions with provable consent.

Protocol Problem it solves
MCP Agent ↔ tools and data
A2A Agent ↔ agent
AP2 Agent ↔ payment system, with a mandate
ACP A broad agentic commerce standard

What this means for retailers

Support for AP2 on the payment gateway side is the condition for receiving orders from autonomous
agents. Without it, the agent either cannot complete the transaction at all or has to fall back on
manual confirmation from the user, which removes most of the value of autonomy.

Important: AP2 is an open protocol under active development. What matters for a retailer is
tracking its adoption by payment providers — gateway-level implementation arrives before
store-level integration does.