Loading patterns…
Agent Payment Mandates (AP2)
Authorizes agent-initiated purchases through a chain of cryptographically signed, verifiable-credential mandates instead of handing an agent raw card details. An Intent Mandate captures the user's up-front constraints (max price, allowed merchants, time-to-live) so the agent can buy while the user is not present; a Cart Mandate is merchant-signed and user-co-signed for the exact items and price, giving what-you-see-is-what-you-pay; and a Payment Mandate is shared with the payment network. The signed chain forms a non-repudiable audit trail that resolves authorization, authenticity, and accountability for autonomous spend, and it is rail-agnostic with an A2A-x402 profile for crypto rails. Distinct from authenticated-delegation: that pattern grants an agent scoped authority to act, whereas AP2 binds each specific purchase to a signed mandate chain a payment network can independently verify.
In 30 seconds
- What
- Agent requests purchases within user-signed constraints; merchant and user co-sign exact cart; payment network verifies the signed mandate chain before settling.
- When to use
- Autonomous agent spending where user cannot approve each transaction in real time, and audit trail and non-repudiation matter more than speed.
- Watch out
- Mandate expiry, revocation, and constraint drift create gaps; if agent or merchant signs outside user intent, the chain breaks and disputes become costly.
Ask the AI expert about this pattern
Opens the assistant with your question prefilled. You review it before sending.
Agent Payment Mandates (AP2): Overview
Authorizes agent-initiated purchases through a chain of cryptographically signed, verifiable-credential mandates instead of handing an agent raw card details. An Intent Mandate captures the user's up-front constraints (max price, allowed merchants, time-to-live) so the agent can buy while the user is not present; a Cart Mandate is merchant-signed and user-co-signed for the exact items and price, giving what-you-see-is-what-you-pay; and a Payment Mandate is shared with the payment network. The signed chain forms a non-repudiable audit trail that resolves authorization, authenticity, and accountability for autonomous spend, and it is rail-agnostic with an A2A-x402 profile for crypto rails. Distinct from authenticated-delegation: that pattern grants an agent scoped authority to act, whereas AP2 binds each specific purchase to a signed mandate chain a payment network can independently verify.
- Intent Mandate encodes user constraints (max price, allowed merchants, TTL) for human-not-present purchases
- Cart Mandate is merchant-signed and user-co-signed for exact items and price
- Payment Mandate is shared with the payment network to authorize settlement
- Chained verifiable credentials form a non-repudiable audit trail
- Resolves authorization, authenticity, and accountability for autonomous spend
- Rail-agnostic, with an A2A-x402 extension for stablecoin settlement
The Agent Architect
One pattern, one tradeoff, one production failure story. A short weekly briefing for people building agentic systems.
Weekly email, one-click unsubscribe. We only use your address to send the briefing.
References
The papers, specifications, and repositories this pattern is based on.
From the engineer behind this catalog
Get your agent architecture reviewed
This page documents one pattern. Your system runs dozens, and most failures live in how they fit together. Have the whole design reviewed against the 288 patterns in this catalog: architecture, reliability, evaluation and cost, every finding mapped to the pattern that fixes it.
€750 instead of €1,500, one week, written report and walkthrough call, until 30 September