Why payment mandates exist
In classic e-commerce the user authorises the payment personally, by pressing Pay. In agentic
commerce the purchase can be initiated by an AI agent: the user said once “buy me trainers under
$90”, and the agent then acts on its own.
That raises a question. How do the merchant and the payment system establish that the purchase was
sanctioned? And how are the agent’s actions kept inside the boundaries the user set?
AP2, Google’s protocol, answers with payment mandates: cryptographically signed structures that
record the user’s permission.
The two types of mandate
Intent Mandate — the mandate of intention. It records the original permission and its
parameters:
- What is allowed (product category, type of action)
- The limits (budget, brands, conditions)
- The time window it stays valid
Cart Mandate — the mandate of the basket. It records one concrete transaction before payment:
- The list of items, SKUs and quantities
- The final price
- The delivery terms
The two-stage structure lets the agent act autonomously inside the intention while still requiring a
final confirmation before every payment.
Cryptographic protection
User -> signs an Intent Mandate with their key
Agent -> acts inside the Intent Mandate
Agent -> builds a Cart Mandate -> the user signs it
Merchant -> verifies the signatures -> processes the payment
Neither the agent nor the merchant can change the contents of a signed mandate. If the agent tries
to push through a transaction that falls outside the Intent Mandate, the payment system rejects it.
Important: payment mandates are specific to Google’s AP2 protocol (2025). Other protocols —
ACP, UCP — solve the same authorisation problem differently, and the standard is still taking
shape.