Resources | Entersekt

Agent Payments Protocol (AP2)

Written by Entersekt | Feb 10, 2026, 1:00:00 PM

What banks need to know

Agent Payments Protocol (AP2) is an open protocol for agent initiated payments. It creates signed proof of what an AI agent was allowed to buy, how payment was approved, and which party verified each step. Entersekt helps you connect identity, risk, and payment trust across digital journeys.

If you work in banking, payments, or fraud, AP2 matters because agentic commerce changes a core assumption. The person choosing an item may no longer be the same party completing checkout in real time. This article explains what AP2 is, how it works, where it fits with FIDO and UCP, and what it means for banking controls.

Key takeaways: Agent Payments Protocol (AP2)

  • AP2 is an open protocol that secures payments executed by software agents acting on behalf of a person or business.
  • Its core job is to create verifiable proof of user intent, checkout terms, payment authorization, and transaction evidence.
  • AP2 uses mandates and receipts to bind a payment to a specific checkout state, reducing replay and tampering risk.
  • Entersekt helps you assess risk and step up authentication only when an agent driven payment needs closer scrutiny.
  • For banks and issuers, AP2 shifts trust decisions earlier in the payment journey and makes auditability far more important.

Agentic commerce fraud is one reason AP2 matters for banks and issuers. By creating verifiable proof of delegated authority, checkout terms, and payment authorization, AP2 helps reduce ambiguity around disputed agent actions, checkout tampering, and replay risk. 

What is Agent Payments Protocol (AP2)?

Agent Payments Protocol, or AP2, is an open protocol for securing payments executed by AI agents. Its purpose is to let agents act on delegated authority while giving merchants, credential issuers, and payment parties cryptographic evidence of what was approved.

According to the AP2 specification, the protocol covers roles, verification duties, checkout and payment mandates, and receipts. It does not replace a commerce protocol. Instead, it adds a trust layer to agent driven transactions.

Why AP2 matters for banking and payments

AP2 matters because card and account payment systems were built around direct human action at checkout. Agentic commerce breaks that assumption. A bank now has to judge not only the payment event, but also the delegation event that came before it.

This changes dispute handling, fraud analysis, and authentication design. It also raises new questions about scope, revocation, and proof. Entersekt gives issuers richer signals for payment trust through 3-D Secure and risk aware authentication journeys tied to transaction context.

How AP2 works

AP2 works by binding payment approval to a specific checkout state. That state is signed, approved, and later submitted as evidence during payment completion. As a result, the merchant and payment side can verify that the authorized payment matches the agreed purchase.

Which roles exist in AP2?

The AP2 specification describes five main roles: the Shopping Agent, Credential Provider, Merchant, Payment Processor, and Trusted Surface. Each role has a distinct verification task. This separation matters because trust is distributed rather than assumed.

For example:

What are mandates and receipts in AP2?

Mandates are signed proofs of intent and authorization. A Checkout Mandate secures what is being bought. A Payment Mandate secures how that checkout may be paid.

Receipts record that each step was accepted and processed. This structure gives all sides evidence that can support later review, exception handling, and dispute analysis.

Human present and autonomous AP2 flows

AP2 supports direct approval and autonomous execution. In a human present flow, the person approves the closed checkout and payment mandates before the agent completes payment.

In a human not present flow, the person approves broader instructions first, and the agent later executes the purchase under those limits. The AP2 flow guide notes that unresolved constraints can bring the person back into the loop for a fresh approval when needed.

That design is important for banks. It means autonomy does not remove control. It changes where control is applied and how evidence is recorded.

How AP2 fits with FIDO and UCP

AP2 is moving toward broader industry stewardship through the FIDO Alliance. FIDO has said its work on trusted agentic interactions includes agentic payment frameworks drawn from Google’s AP2 and Mastercard’s Verifiable Intent contributions.

You can review that direction in the FIDO Alliance announcement. This matters because open governance can improve interoperability, shared terminology, and trust across issuers, merchants, and agent platforms.

AP2 also aligns with the Universal Commerce Protocol. The UCP and AP2 guide describes AP2 as the trust layer for agent led checkout and payment flows.

What risks does AP2 address?

AP2 addresses a narrow but important problem: proving that an agent had authority to execute a specific payment under specific terms. That can reduce ambiguity around checkout tampering, replay, and disputed agent actions.

It does not solve every fraud issue on its own. Banks still need identity checks, risk scoring, behavioral analysis, device trust, transaction monitoring, and step up controls for higher risk moments. Entersekt links those controls across channels through Context Aware™ Authentication.

Entersekt also connects payment journeys to issuer decisioning through issuer focused payment security. That matters when agent activity, scam pressure, and account risk need one coordinated decision path.

What AP2 means for fraud teams and issuers

Fraud teams should treat AP2 as a new evidence and control layer, not as a complete fraud stack. The key shift is that user intent, agent authority, and payment execution become linked artifacts that can be checked together.

For issuers, this may improve approval confidence when the protocol data is trustworthy and the risk context is low. It may also justify stronger challenges when the delegated scope, device posture, or transaction pattern looks unusual.

Entersekt helps you adapt those decisions across banking and commerce journeys. That is one reason Entersekt’s view on AI mandates focuses on governance, verification, and smarter intervention points.

FAQs about Agent Payments Protocol (AP2)

➡️ Is AP2 a payment rail?

No. AP2 is a security and trust protocol for agent initiated payments. It sits on top of commerce and payment flows to add signed proof, delegated authority, and audit evidence. It does not replace card networks, account to account rails, or checkout systems.

➡️ Does AP2 replace authentication?

No. AP2 records and binds authorization evidence, but banks still need authentication and risk checks. Entersekt helps you apply biometric, device, and risk based controls at the moments that matter. That can help you judge when an agent action deserves approval, review, or a stronger challenge.

➡️ What is the difference between AP2 and Verifiable Intent?

AP2 is a protocol for secure agent performed payments, while Verifiable Intent focuses on tamper resistant records of user authorized agent actions. FIDO has said both contributions will inform open standards for trusted agentic commerce. Together, they point toward clearer proof of intent and clearer proof of execution.

➡️ Why should issuers care about AP2?

Issuers should care because agentic commerce changes how payment trust is created and checked. Entersekt gives you payment risk context across digital banking and e commerce journeys. That helps you connect delegated authority, transaction signals, and issuer decisioning more intelligently.

➡️ Can AP2 help with disputes?

Yes. AP2 is designed to create evidence that can support dispute review. Checkout mandates, payment mandates, and receipts give parties a clearer record of what was approved and processed. Entersekt helps you add stronger authentication and risk signals to that record when higher assurance is needed.