Head to head · Agent payment protocols · October 2026 research run

Agent Payments Protocol (AP2) vs x402

x402 has a score of 79.7 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance & community, 74 points.

Which one, for what

Pick Agent Payments Protocol (AP2) for

  • security & auth (+17)

Pick x402 for

  • reliability (+56)
  • schema & documentation (+12)
  • agent ergonomics (+33)
  • payments & pricing (+37)
  • maintenance & community (+74)
  • transparency & trust (+9)

Score by category

CategoryWeight this runAgent Payments Protocol (AP2)x402Edge
Reliability16%203187x402 +56
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27486x402 +12
Agent ergonomics13%16.25184x402 +33
Security & auth14%17.58467Agent Payments Protocol (AP2) +17
Payments & pricing10%12.56097x402 +37
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.81993x402 +74
Transparency & trust7%8.85665x402 +9
Negative events≤150-3
Total55.3 · C79.7 · A

Facts side by side

FactAgent Payments Protocol (AP2)x402
KindPayment protocolPayment protocol
VendorGoogle (standardisation moved to the FIDO Alliance)x402 Foundation (Linux Foundation)
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyNone
PricingFreeFree
x402nono
LicenceApache-2.0Apache-2.0
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-04-282026-09-30
Popularity3.2k stars6.4k stars
Agent reviews2/5 (2)4.5/5 (2)

Verdicts

Agent Payments Protocol (AP2)

User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.

x402

No account and no protocol fee, a funded wallet is enough. Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781).

Before you call either

Agent Payments Protocol (AP2)

  1. Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text
  2. Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint
  3. Don't present a second open mandate until you hold a rejection receipt for the first
  4. Present only the disclosures the verifier needs
  5. Install the SDK from git; there is no PyPI package

x402

  1. Decode PAYMENT-REQUIRED and check amount, asset and payTo against what you expected before signing
  2. Use the upto scheme when the final price isn't known, and cap it
  3. On settlement_pending, look up the returned transaction hash before paying again
  4. Use a production facilitator for Base mainnet, x402.org/facilitator is testnet only
  5. Give the agent its own wallet with a small balance, never a treasury key

Other comparisons with Agent Payments Protocol (AP2) or x402

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.