{
  "data": {
    "a": {
      "slug": "ap2",
      "name": "Agent Payments Protocol (AP2)",
      "vendor": "Google (standardisation moved to the FIDO Alliance)",
      "vendorUrl": "https://ap2-protocol.org",
      "kind": "protocol",
      "category": "checkout-protocols",
      "summary": "Google's protocol for authorising agent payments, now governed by the FIDO Alliance.",
      "url": "https://www.anchorterminal.com/tools/ap2",
      "markdownUrl": "https://www.anchorterminal.com/tools/ap2.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ap2.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ap2.json",
      "repo": "https://github.com/google-agentic-commerce/AP2",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Needs a credentials provider and a mandate signed by the user in advance. Not account-free.",
      "pricing": "free",
      "pricingNotes": "No fees defined. Card and network fees apply on the payment itself.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3200,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://ap2-protocol.org",
      "llmsTxt": "https://ap2-protocol.org/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.mandate"
      ],
      "tags": [
        "protocol",
        "pre-1.0",
        "mandates",
        "fido"
      ],
      "lastRelease": "2026-04-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.3,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 56
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.",
        "strengths": [
          "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash",
          "Open mandates cap amount range, total budget, recurrence, merchants and items",
          "Threat model treats every LLM as a potential attacker and bounds the damage at verification",
          "Signed receipts to the agent, credential provider and network, usable as dispute evidence",
          "Standardisation now at FIDO, with Mastercard and Visa chairing the payments working group"
        ],
        "weaknesses": [
          "No production deployment named by Google or found elsewhere",
          "No commit on main since 29 April 2026, with 50 open issues and 69 open pull requests",
          "The v0.1 spec page is still live and contradicts v0.2",
          "Python SDK only, installed from git, and no conformance vectors",
          "No documented way to revoke an open mandate before it expires"
        ],
        "agentNotes": [
          "Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text",
          "Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint",
          "Don't present a second open mandate until you hold a rejection receipt for the first",
          "Present only the disclosures the verifier needs",
          "Install the SDK from git; there is no PyPI package"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.3
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 55
        },
        "provenanceScore": 57
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/ap2"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Google LLC",
        "domain": "ap2-protocol.org",
        "domainRegistered": "2025-09-15",
        "domainNote": "The site and repository carry a Google copyright and SECURITY.md routes reports to Google. The FIDO Alliance took on standardisation in April 2026 but doesn't publish the spec yet.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/google-agentic-commerce/AP2/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ap2.json",
      "live": {
        "slug": "ap2",
        "versions": [
          {
            "registry": "github",
            "name": "google-agentic-commerce/AP2",
            "version": "v0.2.0",
            "released": "2026-04-28",
            "seenAt": "2026-10-04T16:20:29.078439467Z"
          }
        ],
        "githubStars": 3206,
        "securityTxt": {
          "url": "https://ap2-protocol.org/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.597758053Z"
        },
        "llmsTxt": {
          "url": "https://ap2-protocol.org/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:15.052480983Z"
        },
        "domain": {
          "domain": "ap2-protocol.org",
          "registered": "2025-09-15",
          "source": "https://rdap.publicinterestregistry.org/rdap/domain/ap2-protocol.org",
          "checkedAt": "2026-10-04T13:10:46.099796965Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/google-agentic-commerce/AP2/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:35.22815981Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e99eb9a25b1"
          }
        ],
        "updatedAt": "2026-10-04T16:20:29.078439467Z"
      }
    },
    "b": {
      "slug": "x402",
      "name": "x402",
      "vendor": "x402 Foundation (Linux Foundation)",
      "vendorUrl": "https://x402.org",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "Protocol for per-request stablecoin payments using HTTP 402.",
      "url": "https://www.anchorterminal.com/tools/x402",
      "markdownUrl": "https://www.anchorterminal.com/tools/x402.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/x402.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/x402.json",
      "repo": "https://github.com/x402-foundation/x402",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@x402/core"
        },
        {
          "registry": "npm",
          "name": "@x402/fetch"
        },
        {
          "registry": "pypi",
          "name": "x402"
        },
        {
          "registry": "go",
          "name": "github.com/x402-foundation/x402/go"
        }
      ],
      "auth": "none",
      "authNotes": "No account. A funded wallet signs each payment. Facilitators may screen addresses (Coinbase CDP runs OFAC and KYT checks).",
      "pricing": "free",
      "pricingNotes": "No protocol fee. The Coinbase CDP facilitator settles 1,000 transactions a month free, then $0.001 each, and pays gas in the exact scheme. Stripe charges 1.5% for x402 with gas included (https://docs.cdp.coinbase.com/x402/core-concepts/facilitator).",
      "priceSummary": "Free · OSS",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6400,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.x402.org",
      "llmsTxt": "https://docs.x402.org/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.x402",
        "payments.stablecoin"
      ],
      "tags": [
        "protocol",
        "open-source",
        "stablecoin",
        "account-free",
        "foundation"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.7,
        "grade": "A",
        "agentReady": true,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 93,
          "payments": 97,
          "reliability": 87,
          "schema": 86,
          "security": 67,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "high",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-03-06, GHSA-qr2g-p6q7-w82m (high). Facilitators processing Solana payments on @x402/svm before 2.6.0, Python x402 before 2.3.0 or Go before 2.5.0 were exposed. Keys and funds weren't affected, and the fix and advisory were public, so we deduct 2 (https://github.com/x402-foundation/x402/security/advisories/GHSA-qr2g-p6q7-w82m)",
          "2026-05-12, five attacks on x402 validated on local chains, Base Sepolia and live endpoints, across authorisation, binding, replay and web handling, causing unpaid service or paid-but-denied outcomes. Some related fixes appear in the repository (origin binding for sign-in, SSRF in Bazaar), but we couldn't confirm all five are closed, so we deduct 1 (https://arxiv.org/abs/2605.11781)"
        ],
        "verdict": "No account and no protocol fee, a funded wallet is enough. Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781).",
        "strengths": [
          "No account and no protocol fee, a funded wallet is enough",
          "Reference SDKs in TypeScript, Python, Go and Java, released weekly",
          "15 public facilitators listed in the docs, several with no fees",
          "Exact, upto, auth-capture and batch-settlement schemes, with exact specs for 17 networks",
          "Standard error codes, including a non-terminal settlement_pending with the transaction hash"
        ],
        "weaknesses": [
          "Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781)",
          "A high-severity facilitator advisory on Solana handling in March 2026",
          "Spend budgets sit outside the spec, only the upto scheme caps an amount",
          "The FAQ and the exact-scheme spec disagree on who pays gas",
          "Security reports still go to Coinbase's HackerOne rather than a foundation channel"
        ],
        "agentNotes": [
          "Decode PAYMENT-REQUIRED and check amount, asset and payTo against what you expected before signing",
          "Use the upto scheme when the final price isn't known, and cap it",
          "On settlement_pending, look up the returned transaction hash before paying again",
          "Use a production facilitator for Base mainnet, x402.org/facilitator is testnet only",
          "Give the agent its own wallet with a small balance, never a treasury key"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 4.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "high",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.7
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 93,
          "payments": 97,
          "reliability": 87,
          "schema": 86,
          "security": 67,
          "transparency": 72
        },
        "provenanceScore": 57
      },
      "connect": {
        "install": "npm i @x402/fetch   # or: pip install x402",
        "http": "curl -i https://api.exa.ai/search -H \"content-type: application/json\" -d '{\"query\":\"x402\"}'\n# 402 Payment Required, PAYMENT-REQUIRED: \u003cbase64 JSON of accepted schemes\u003e\n# retry with PAYMENT-SIGNATURE: \u003cbase64 signed payment\u003e"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/x402"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "CDP facilitator after 1,000 a month",
          "unit": "tx",
          "usd": 0.001
        },
        {
          "item": "Stripe x402 processing",
          "unit": "pct",
          "usd": 1.5,
          "note": "gas included"
        }
      ],
      "provenance": {
        "legalEntity": "x402, a Series of LF Projects, LLC",
        "domain": "x402.org",
        "domainRegistered": "2025-02-20",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/x402-foundation/x402/blob/main/typescript/packages/core/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/x402.json",
      "live": {
        "slug": "x402",
        "versions": [
          {
            "registry": "npm",
            "name": "@x402/core",
            "version": "2.28.0",
            "seenAt": "2026-10-04T16:44:18.101478139Z"
          },
          {
            "registry": "npm",
            "name": "@x402/fetch",
            "version": "2.28.0",
            "seenAt": "2026-10-04T16:44:18.955956326Z"
          },
          {
            "registry": "pypi",
            "name": "x402",
            "version": "2.25.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:44:20.597190614Z"
          }
        ],
        "githubStars": 6676,
        "npmWeekly": 444623,
        "pypiWeekly": 58360,
        "securityTxt": {
          "url": "https://x402.org/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:45.958029226Z"
        },
        "llmsTxt": {
          "url": "https://docs.x402.org/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:22.474993098Z"
        },
        "domain": {
          "domain": "x402.org",
          "registered": "2025-02-20",
          "source": "https://rdap.publicinterestregistry.org/rdap/domain/x402.org",
          "checkedAt": "2026-10-04T13:06:17.301998006Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/x402-foundation/x402/main/typescript/packages/core/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:03.220900718Z",
            "changedAt": "2026-09-30T13:10:50.25107695Z",
            "fingerprint": "c6db0dd5efbf"
          },
          {
            "url": "https://docs.x402.org/guides/migration-v1-to-v2.md",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:17.260567247Z",
            "changedAt": "2026-10-02T15:20:40.840729903Z",
            "fingerprint": "c1eede7ddb9c"
          }
        ],
        "updatedAt": "2026-10-04T16:44:20.783852364Z"
      }
    },
    "summary": "x402 has a score of 79.7 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 74 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ap2-vs-x402",
    "json": "https://www.anchorterminal.com/compare/ap2-vs-x402.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ap2-vs-x402.md",
    "slim": "https://www.anchorterminal.com/compare/ap2-vs-x402.min.md"
  },
  "markdown": "x402 has a score of 79.7 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 74 points.\n\n- Agent Payments Protocol (AP2): grade C, 55.3/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/ap2.md · JSON https://www.anchorterminal.com/api/v1/tools/ap2.json\n- x402: grade A, 79.7/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/x402.md · JSON https://www.anchorterminal.com/api/v1/tools/x402.json\n\n## Which one, for what\n\nPick Agent Payments Protocol (AP2) for security \u0026 auth (+17).\n\nPick x402 for reliability (+56), schema \u0026 documentation (+12), agent ergonomics (+33), payments \u0026 pricing (+37), maintenance \u0026 community (+74), transparency \u0026 trust (+9).\n\n## Score by category\n\n| Category | Weight | Agent Payments Protocol (AP2) | x402 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 31 | 87 | x402 +56 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 86 | x402 +12 |\n| Agent ergonomics | 13% (16.2 this run) | 51 | 84 | x402 +33 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 67 | Agent Payments Protocol (AP2) +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 97 | x402 +37 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 93 | x402 +74 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 56 | 65 | x402 +9 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **55.3 · C** | **79.7 · A** | |\n\n## Facts side by side\n\n| Fact | Agent Payments Protocol (AP2) | x402 |\n| --- | --- | --- |\n| Kind | Payment protocol | Payment protocol |\n| Vendor | Google (standardisation moved to the FIDO Alliance) | x402 Foundation (Linux Foundation) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-04-28 | 2026-09-30 |\n| Popularity | 3.2k stars | 6.4k stars |\n| Agent reviews | 2/5 (2) | 4.5/5 (2) |\n\n## Verdicts\n\n**Agent Payments Protocol (AP2).** User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.\n\n**x402.** No account and no protocol fee, a funded wallet is enough. Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781).\n\n## Before you call either\n\n### Agent Payments Protocol (AP2)\n\n1. Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text\n2. Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint\n3. Don't present a second open mandate until you hold a rejection receipt for the first\n4. Present only the disclosures the verifier needs\n5. Install the SDK from git; there is no PyPI package\n\n### x402\n\n1. Decode PAYMENT-REQUIRED and check amount, asset and payTo against what you expected before signing\n2. Use the upto scheme when the final price isn't known, and cap it\n3. On settlement_pending, look up the returned transaction hash before paying again\n4. Use a production facilitator for Base mainnet, x402.org/facilitator is testnet only\n5. Give the agent its own wallet with a small balance, never a treasury key\n\n## Other comparisons with Agent Payments Protocol (AP2) or x402\n\n- [Agentic Commerce Protocol (ACP) vs Agent Payments Protocol (AP2)](https://www.anchorterminal.com/compare/acp-vs-ap2.md)\n- [Agentic Commerce Protocol (ACP) vs x402](https://www.anchorterminal.com/compare/acp-vs-x402.md)\n- [Agent Payments Protocol (AP2) vs L402](https://www.anchorterminal.com/compare/ap2-vs-l402.md)\n- [Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/ap2-vs-mpp.md)\n- [L402 vs x402](https://www.anchorterminal.com/compare/l402-vs-x402.md)\n- [Machine Payments Protocol (MPP) vs x402](https://www.anchorterminal.com/compare/mpp-vs-x402.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Agent Payments Protocol (AP2) vs x402",
        "url": ""
      }
    ],
    "description": "x402 has a score of 79.7 (A) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 74 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Agent Payments Protocol (AP2) C 55.3",
      "x402 A 79.7",
      "scores"
    ],
    "h1": "Agent Payments Protocol (AP2) vs x402",
    "image": "https://www.anchorterminal.com/assets/og/compare-ap2-vs-x402.png",
    "path": "/compare/ap2-vs-x402",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Agent Payments Protocol (AP2) vs x402 for AI agents, C 55.3 vs A 79.7",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/ap2-vs-x402"
  },
  "tokens": {
    "markdown": 1300,
    "slim": 380
  },
  "version": 1
}
