The problem AP2 solves
When an AI agent buys something on a user’s behalf, three questions appear:
- Authorisation: did the agent have the right to make this purchase?
- Authenticity: was the agent really acting on a specific user’s instruction?
- Liability: who is responsible in a dispute — the user, the agent or the platform?
Existing payment protocols were never designed for a purchase that a human does not initiate. AP2 is
Google’s answer to that gap.
Architecture: two mandates
AP2 uses a two-layer system of cryptographically signed documents.
Intent Mandate — issued by the user to the agent in advance:
{
"authorized_categories": ["electronics", "books"],
"max_price": 200,
"currency": "USD",
"valid_until": "2025-12-31",
"signature": "<user_private_key>"
}
Cart Mandate — produced by the agent at the moment of a specific purchase:
{
"items": [...],
"total": 115,
"merchant": "re:Store",
"delivery_date": "2025-06-05",
"intent_mandate_ref": "<hash>",
"signature": "<agent_key>"
}
The payment system checks both mandates: if the Cart Mandate stays inside the limits of the Intent
Mandate, the transaction is authorised.
Where AP2 sits among agent protocols
AP2 extends A2A (Agent2Agent), Google’s base protocol for interaction between agents. Where MCP
(Anthropic’s Model Context Protocol) solves the problem of connecting agents to tools and data, AP2
solves the problem of financial transactions with provable consent.
| Protocol | Problem it solves |
|---|---|
| MCP | Agent ↔ tools and data |
| A2A | Agent ↔ agent |
| AP2 | Agent ↔ payment system, with a mandate |
| ACP | A broad agentic commerce standard |
What this means for retailers
Support for AP2 on the payment gateway side is the condition for receiving orders from autonomous
agents. Without it, the agent either cannot complete the transaction at all or has to fall back on
manual confirmation from the user, which removes most of the value of autonomy.
Important: AP2 is an open protocol under active development. What matters for a retailer is
tracking its adoption by payment providers — gateway-level implementation arrives before
store-level integration does.