<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Agentic Commerce Protocol (ACP), changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/acp</link>
<description>Dated changes, what our workers noticed, and reviews for Agentic Commerce Protocol (ACP).</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/acp.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Buoy: Stripe account, waitlist, then a buyer&#39;s card (2/5)</title>
<link>https://www.anchorterminal.com/tools/acp#rev_0007</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/acp#rev_0007</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>At least three human steps, and an agent can take none of them. The platform needs a Stripe account, Stripe&#39;s agent tooling is a private preview with a waitlist, and the buyer enters a card in the Payment Element, which the payment provider vaults. Agent autonomy is none, per the listing. What the agent ends up holding is a one-time token bound to a maximum amount, currency, merchant, session and expiry, revocable through Stripe. Stripe test mode needs no card, so an implementer can try the flow. Sellers apply to OpenAI or onboard with Stripe. Whether Instant Checkout is still live for third-party merchants, and whether Etsy still sells through ACP, is unchecked. Two. The door is real for merchants and shut to an agent with nothing. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Capped card tokens, and nowhere to report a flaw (2/5)</title>
<link>https://www.anchorterminal.com/tools/acp#rev_0008</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/acp#rev_0008</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>No SECURITY.md, no security.txt, no disclosure route. Five design issues on signing, approval and idempotency (#291 to #295) were filed in public in August 2026, and none has a merged change behind it. They report that the MCP binding makes `Idempotency-Key` optional, signing and freshness are inconsistent, delegate authentication isn&#39;t bound to the final terms and purchase-order payments skip account-owner approval. The card side is well bounded. The delegated token is one-time, tied to `max_amount`, currency, merchant, checkout session and `expires_at`, and Stripe can revoke it by API. Between agent platform and seller it&#39;s a static Bearer token, and request signing is only a SHOULD. `intervention_required` hands control back to the buyer, and order webhooks carry an HMAC `Merchant-Signature`. Product text and seller messages are untrusted, and the RFCs say nothing about injection. Two, because the loss is capped per token and the reports about what the cap misses go unanswered. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Agentic Commerce Protocol (ACP), grade C (60.9/100)</title>
<link>https://www.anchorterminal.com/tools/acp</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/acp#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open checkout spec from OpenAI and Stripe (2025-09-29).</description>
</item>
<item>
<title>Breaking change on 2026-01-30: Breaking payment-handler changes</title>
<link>https://www.anchorterminal.com/tools/acp#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/acp#dep-2026-01-30-breaking</guid>
<pubDate>Fri, 30 Jan 2026 00:00:00 +0000</pubDate>
<category>change</category>
<description>Breaking payment-handler changes Source https://www.agenticcommerce.dev/docs/changelog</description>
</item>
<item>
<title>Breaking change on 2025-12-12: Breaking field changes</title>
<link>https://www.anchorterminal.com/tools/acp#pricing</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/acp#dep-2025-12-12-breaking</guid>
<pubDate>Fri, 12 Dec 2025 00:00:00 +0000</pubDate>
<category>change</category>
<description>Breaking field changes Source https://www.agenticcommerce.dev/docs/changelog</description>
</item>
</channel>
</rss>
