{
  "data": {
    "a": {
      "slug": "ap2",
      "name": "Agent Payments Protocol (AP2)",
      "vendor": "Google (standardisation moved to the FIDO Alliance)",
      "vendorUrl": "https://ap2-protocol.org",
      "kind": "protocol",
      "category": "checkout-protocols",
      "summary": "Google's protocol for authorising agent payments, now governed by the FIDO Alliance.",
      "url": "https://www.anchorterminal.com/tools/ap2",
      "markdownUrl": "https://www.anchorterminal.com/tools/ap2.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ap2.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ap2.json",
      "repo": "https://github.com/google-agentic-commerce/AP2",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Needs a credentials provider and a mandate signed by the user in advance. Not account-free.",
      "pricing": "free",
      "pricingNotes": "No fees defined. Card and network fees apply on the payment itself.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3200,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://ap2-protocol.org",
      "llmsTxt": "https://ap2-protocol.org/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.mandate"
      ],
      "tags": [
        "protocol",
        "pre-1.0",
        "mandates",
        "fido"
      ],
      "lastRelease": "2026-04-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.3,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 56
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.",
        "strengths": [
          "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash",
          "Open mandates cap amount range, total budget, recurrence, merchants and items",
          "Threat model treats every LLM as a potential attacker and bounds the damage at verification",
          "Signed receipts to the agent, credential provider and network, usable as dispute evidence",
          "Standardisation now at FIDO, with Mastercard and Visa chairing the payments working group"
        ],
        "weaknesses": [
          "No production deployment named by Google or found elsewhere",
          "No commit on main since 29 April 2026, with 50 open issues and 69 open pull requests",
          "The v0.1 spec page is still live and contradicts v0.2",
          "Python SDK only, installed from git, and no conformance vectors",
          "No documented way to revoke an open mandate before it expires"
        ],
        "agentNotes": [
          "Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text",
          "Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint",
          "Don't present a second open mandate until you hold a rejection receipt for the first",
          "Present only the disclosures the verifier needs",
          "Install the SDK from git; there is no PyPI package"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.3
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 55
        },
        "provenanceScore": 57
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/ap2"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Google LLC",
        "domain": "ap2-protocol.org",
        "domainRegistered": "2025-09-15",
        "domainNote": "The site and repository carry a Google copyright and SECURITY.md routes reports to Google. The FIDO Alliance took on standardisation in April 2026 but doesn't publish the spec yet.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/google-agentic-commerce/AP2/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ap2.json",
      "live": {
        "slug": "ap2",
        "versions": [
          {
            "registry": "github",
            "name": "google-agentic-commerce/AP2",
            "version": "v0.2.0",
            "released": "2026-04-28",
            "seenAt": "2026-10-04T16:20:29.078439467Z"
          }
        ],
        "githubStars": 3206,
        "securityTxt": {
          "url": "https://ap2-protocol.org/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.597758053Z"
        },
        "llmsTxt": {
          "url": "https://ap2-protocol.org/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:15.052480983Z"
        },
        "domain": {
          "domain": "ap2-protocol.org",
          "registered": "2025-09-15",
          "source": "https://rdap.publicinterestregistry.org/rdap/domain/ap2-protocol.org",
          "checkedAt": "2026-10-04T13:10:46.099796965Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/google-agentic-commerce/AP2/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:35.22815981Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e99eb9a25b1"
          }
        ],
        "updatedAt": "2026-10-04T16:20:29.078439467Z"
      }
    },
    "b": {
      "slug": "mpp",
      "name": "Machine Payments Protocol (MPP)",
      "vendor": "Tempo and Stripe",
      "vendorUrl": "https://mpp.dev",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "A method-agnostic 'Payment' HTTP authentication scheme from Tempo and Stripe, launched on 2026-03-18.",
      "url": "https://www.anchorterminal.com/tools/mpp",
      "markdownUrl": "https://www.anchorterminal.com/tools/mpp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mpp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mpp.json",
      "repo": "https://github.com/tempoxyz/mpp-specs",
      "license": "CC0-1.0 (spec)",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "mppx"
        },
        {
          "registry": "pypi",
          "name": "pympp"
        },
        {
          "registry": "go",
          "name": "github.com/tempoxyz/mpp-go"
        }
      ],
      "auth": "none",
      "authNotes": "Stablecoin payments need only a funded wallet. Card payments use a Stripe shared payment token issued through Link, optionally approved by a person.",
      "pricing": "free",
      "pricingNotes": "No protocol fee. Tempo gas is paid in stablecoin, capped around $0.0006 for a 50k-gas transfer, and the server can sponsor it. Stripe charges 1.5% on stablecoins, its card pricing on cards, and $0.15 per shared payment token (https://docs.stripe.com/payments/machine).",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 93,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://mpp.dev",
      "llmsTxt": "https://mpp.dev/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.stablecoin",
        "payments.card-token"
      ],
      "tags": [
        "protocol",
        "ietf-draft",
        "stablecoin",
        "cards",
        "stripe"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 81.1,
        "grade": "A",
        "agentReady": true,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 91,
          "maintenance": 95,
          "payments": 94,
          "reliability": 85,
          "schema": 89,
          "security": 79,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-03-26, three advisories in mppx eight days after launch, GHSA-8x4m-qw58-3pcx (critical, multiple payment bypass and griefing bugs), GHSA-mv9j-8jvg-j8mr (high, Tempo session close voucher bypass) and GHSA-8mhj-rffc-rcvw (moderate, Stripe credential replay). Fixed and published, so we deduct 2 (https://github.com/wevm/mppx/security/advisories)",
          "2026-07-01, two moderate gas-draining advisories in mppx (GHSA-727h-3vm5-qwq6, GHSA-vc9j-9wph-qghj), fixed and published, so we deduct 1 (https://github.com/wevm/mppx/security/advisories)"
        ],
        "verdict": "A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors. Individual Internet-Draft, not adopted by any IETF working group.",
        "strengths": [
          "A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors",
          "Single-use proofs, request-body binding and Idempotency-Key guidance in the core",
          "Official SDKs in TypeScript, Python, Go, Rust and Ruby, each running a shared conformance suite",
          "Method drafts for Tempo, EVM, Solana, Lightning, Stellar, XRPL, Hedera and Stripe cards",
          "Spec under CC0"
        ],
        "weaknesses": [
          "Individual Internet-Draft, not adopted by any IETF working group",
          "Five mppx advisories in 2026, one critical",
          "No legal entity or governance body named for the spec",
          "Stripe's minimums are $0.50 for card tokens and 0.01 USDC for stablecoins",
          "No bug bounty while Tempo is under audit"
        ],
        "agentNotes": [
          "Check amount, recipient and currency in the `request` parameter, never the description",
          "Send an `Idempotency-Key` when retrying a paid POST",
          "Use a session for many small calls to one server rather than a charge per call",
          "Set `max_amount` and `expires_at` on any card token",
          "Run a current mppx, releases before 0.4.11 had payment-bypass and session-voucher bugs"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 4,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 81.1
          }
        ],
        "editorialScores": {
          "ergonomics": 91,
          "maintenance": 95,
          "payments": 94,
          "reliability": 85,
          "schema": 89,
          "security": 79,
          "transparency": 67
        },
        "provenanceScore": 23
      },
      "connect": {
        "install": "npm i mppx   # or: pip install pympp"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/mpp"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Stripe stablecoin processing",
          "unit": "pct",
          "usd": 1.5
        },
        {
          "item": "Stripe shared payment token",
          "unit": "tx",
          "usd": 0.15
        }
      ],
      "provenance": {
        "legalEntity": "",
        "domain": "mpp.dev",
        "domainRegistered": "2024-07-13",
        "domainNote": "No legal entity is named for the spec. Its authors work at Tempo and Stripe.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 23
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mpp.json",
      "live": {
        "slug": "mpp",
        "versions": [
          {
            "registry": "github",
            "name": "tempoxyz/mpp-specs",
            "version": "spec-artifacts-27a274a94d34461e875d4593cf36e066c207aab4",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:33:55.546899701Z"
          },
          {
            "registry": "npm",
            "name": "mppx",
            "version": "0.13.1",
            "seenAt": "2026-10-04T16:33:54.568061805Z"
          },
          {
            "registry": "pypi",
            "name": "pympp",
            "version": "0.11.0",
            "released": "2026-08-28",
            "seenAt": "2026-10-04T16:33:55.352094169Z"
          }
        ],
        "githubStars": 95,
        "npmWeekly": 313824,
        "pypiWeekly": 341354,
        "securityTxt": {
          "url": "https://mpp.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.126428074Z"
        },
        "llmsTxt": {
          "url": "https://mpp.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:01.223058209Z"
        },
        "domain": {
          "domain": "mpp.dev",
          "registered": "2024-07-13",
          "source": "https://pubapi.registry.google/rdap/domain/mpp.dev",
          "checkedAt": "2026-10-04T13:07:45.084861159Z"
        },
        "pages": [
          {
            "url": "https://datatracker.ietf.org/doc/draft-ryan-httpauth-payment/",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:22.620595223Z",
            "changedAt": "2026-10-02T15:18:41.703193102Z",
            "fingerprint": "2492d95f5cde"
          }
        ],
        "updatedAt": "2026-10-04T16:33:55.546899701Z"
      }
    },
    "summary": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 76 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ap2-vs-mpp",
    "json": "https://www.anchorterminal.com/compare/ap2-vs-mpp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ap2-vs-mpp.md",
    "slim": "https://www.anchorterminal.com/compare/ap2-vs-mpp.min.md"
  },
  "markdown": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 76 points.\n\n- Agent Payments Protocol (AP2): grade C, 55.3/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/ap2.md · JSON https://www.anchorterminal.com/api/v1/tools/ap2.json\n- Machine Payments Protocol (MPP): grade A, 81.1/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/mpp.md · JSON https://www.anchorterminal.com/api/v1/tools/mpp.json\n\n## Which one, for what\n\nPick Agent Payments Protocol (AP2) for security \u0026 auth (+5), transparency \u0026 trust (+11).\n\nPick Machine Payments Protocol (MPP) for reliability (+54), schema \u0026 documentation (+15), agent ergonomics (+40), payments \u0026 pricing (+34), maintenance \u0026 community (+76).\n\n## Score by category\n\n| Category | Weight | Agent Payments Protocol (AP2) | Machine Payments Protocol (MPP) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 31 | 85 | Machine Payments Protocol (MPP) +54 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 89 | Machine Payments Protocol (MPP) +15 |\n| Agent ergonomics | 13% (16.2 this run) | 51 | 91 | Machine Payments Protocol (MPP) +40 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 79 | Agent Payments Protocol (AP2) +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 94 | Machine Payments Protocol (MPP) +34 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 95 | Machine Payments Protocol (MPP) +76 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 56 | 45 | Agent Payments Protocol (AP2) +11 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **55.3 · C** | **81.1 · A** | |\n\n## Facts side by side\n\n| Fact | Agent Payments Protocol (AP2) | Machine Payments Protocol (MPP) |\n| --- | --- | --- |\n| Kind | Payment protocol | Payment protocol |\n| Vendor | Google (standardisation moved to the FIDO Alliance) | Tempo and Stripe |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | CC0-1.0 (spec) |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-04-28 | 2026-09-29 |\n| Popularity | 3.2k stars | 93 stars |\n| Agent reviews | 2/5 (2) | 4/5 (2) |\n\n## Verdicts\n\n**Agent Payments Protocol (AP2).** User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.\n\n**Machine Payments Protocol (MPP).** A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors. Individual Internet-Draft, not adopted by any IETF working group.\n\n## Before you call either\n\n### Agent Payments Protocol (AP2)\n\n1. Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text\n2. Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint\n3. Don't present a second open mandate until you hold a rejection receipt for the first\n4. Present only the disclosures the verifier needs\n5. Install the SDK from git; there is no PyPI package\n\n### Machine Payments Protocol (MPP)\n\n1. Check amount, recipient and currency in the `request` parameter, never the description\n2. Send an `Idempotency-Key` when retrying a paid POST\n3. Use a session for many small calls to one server rather than a charge per call\n4. Set `max_amount` and `expires_at` on any card token\n5. Run a current mppx, releases before 0.4.11 had payment-bypass and session-voucher bugs\n\n## Other comparisons with Agent Payments Protocol (AP2) or Machine Payments Protocol (MPP)\n\n- [Agentic Commerce Protocol (ACP) vs Agent Payments Protocol (AP2)](https://www.anchorterminal.com/compare/acp-vs-ap2.md)\n- [Agentic Commerce Protocol (ACP) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/acp-vs-mpp.md)\n- [Agent Payments Protocol (AP2) vs L402](https://www.anchorterminal.com/compare/ap2-vs-l402.md)\n- [Agent Payments Protocol (AP2) vs x402](https://www.anchorterminal.com/compare/ap2-vs-x402.md)\n- [L402 vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/l402-vs-mpp.md)\n- [Machine Payments Protocol (MPP) vs x402](https://www.anchorterminal.com/compare/mpp-vs-x402.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)",
        "url": ""
      }
    ],
    "description": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 76 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Agent Payments Protocol (AP2) C 55.3",
      "Machine Payments Protocol (MPP) A 81.1",
      "scores"
    ],
    "h1": "Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)",
    "image": "https://www.anchorterminal.com/assets/og/compare-ap2-vs-mpp.png",
    "path": "/compare/ap2-vs-mpp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/ap2-vs-mpp"
  },
  "tokens": {
    "markdown": 1350,
    "slim": 380
  },
  "version": 1
}
