# ACK-Pay (Agent Commerce Kit) > ACK-Pay is the open payment protocol in Agent Commerce Kit from Catena Labs. A server returns a signed Payment Request, the client pays through a Payment Service and retries with a receipt issued as a W3C Verifiable Credential. - Canonical: https://www.anchorterminal.com/tools/ack-pay - Markdown: https://www.anchorterminal.com/tools/ack-pay.md (~5,550 tokens) - Slim: https://www.anchorterminal.com/tools/ack-pay.min.md (~1,380 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/ack-pay.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade D · 53.6/100 · rank graded, not ranked against tools · #4 in Pay-per-call protocols · not agent-ready · confidence medium** ## Assessment Signed payment requests and receipts that any server can verify offline against a list of trusted issuers, with an MIT TypeScript SDK and passing CI. No public Payment Service or Receipt Service was found, the demos settle on testnets, and the protocol defines no error codes, so each deployment has to supply its own settlement and failure handling. ## Facts | Field | Value | | --- | --- | | Vendor | Catena Labs, Inc. (https://www.agentcommercekit.com) | | Kind | Payment protocol | | Category | Pay-per-call protocols (https://www.anchorterminal.com/categories/pay-per-call) | | Auth | None · No account or key. Servers sign Payment Requests with a key bound to a DID, and Receipt Services sign receipts that servers check against their own list of trusted issuer DIDs. Identity checks between parties can use ACK-ID. | | Pricing | Free (Free) · No protocol fee, and the SDK is MIT with nothing to buy. Settlement costs depend on the Payment Service and rail a deployment chooses. The docs say conversion and bridging fees should be shown to the client. No public Payment Service with published prices was found. | | Licence | MIT (docs and SDK) | | Packages | npm: `@agentcommercekit/ack-pay`; npm: `agentcommercekit` | | Source | https://github.com/agentcommercekit/ack | | Docs | https://www.agentcommercekit.com/ack-pay/introduction | | llms.txt | https://www.agentcommercekit.com/llms.txt | | Last release | 2026-08-04 | | GitHub stars | 159 (as of 2026-10-09) | | npm downloads / week | 54 | | Spec | ACK protocol version 2025-05-04, published as documentation pages | | Status | Vendor-published pattern, marked current and stable by its own versioning page. No standards body | | How it works | 402 with a signed Payment Request in the body, payment through the option's Payment Service, then a retry with a receipt (a Verifiable Credential) | | Rails | Any. Each payment option names a currency, network and Payment Service. Examples use USDC on Base and Solana, and Stripe | | Fees | No protocol fee. Payment Service fees are set by whoever runs one | | Agent autonomy | Depends on the Payment Service. Human approval before execution is described as an option | | Spend controls | None in the protocol. The demo has a per-transaction cap labelled illustrative | | Discovery | Not defined. The docs say registries could be added | | Reference SDK | `@agentcommercekit/ack-pay` 0.11.0, TypeScript, MIT | | Public deployments | None found in the pages read | | Capabilities | payments.protocol, payments.stablecoin | | Tags | protocol, verifiable-credentials, did, receipts, typescript, mit, llms-txt | | JSON | https://www.anchorterminal.com/api/v1/tools/ack-pay.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 38 | 7.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 66 | 10.7 | | Agent ergonomics | 13% | 16.2 | 47 | 7.6 | | Security & auth | 14% | 17.5 | 58 | 10.2 | | Payments & pricing | 10% | 12.5 | 77 | 9.6 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 53 | 4.6 | | Transparency & trust (editorial 63, provenance 57) | 7% | 8.8 | 60 | 5.2 | | Negative events | up to −15 | up to −15 | 2026-08-04, @agentcommercekit/ack-pay 0.11.0 fixed a revocation check that treated any failure to fetch or parse the status list as not revoked, so `verifyPaymentReceipt` accepted revoked credentials. The changelog describes the flaw in full and the repository has no published advisory. Fixed and documented, so we deduct 2 (https://github.com/agentcommercekit/ack/blob/main/packages/ack-pay/CHANGELOG.md, https://github.com/agentcommercekit/ack/security/advisories) | -2 | | **Total** | | | | **53.6 → D** | ### Why each score - Reliability 38: Graded as a protocol on reference implementations (30), public servers or processors (25), spec stability (25) and test vectors (20). One reference SDK in TypeScript at 0.11.0, with a payments demo and example issuer and verifier services in the repository (15). No public Payment Service or Receipt Service was found. The docs use example.com hosts and the demo settles on Base Sepolia, Solana devnet or a simulated Stripe payment (0). The versioning page names 2025-05-04 as the current stable protocol version and says the date changes only on incompatible changes, but the specification is prose documentation without normative language and the SDK is below 1.0 (15). No test vectors are published. The ack-pay package has seven unit test files, and the Check workflow passed on the last five pushes to main on the page read (8). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 66: The SDK exports Valibot and Zod schemas for the Payment Request, the payment option and the receipt claim, with no JSON Schema or OpenAPI file (15). llms.txt lists 39 pages and each has a Markdown copy (10). Pages on roles, both sequences, the Payment Service and receipts explain when each flow applies, in descriptive prose without MUST or SHOULD rules (13). A field table gives type and required status for every request field, while `network` and `recipient` are free strings whose format varies by network (10). JSON examples of a request and a receipt are given, and no error responses are defined (7). Date-based protocol versions and a changelog per package, though the docs and SDK disagree in places. The docs allow a DID in `serviceCallback` and open issue 205 reports the schema rejects it (11). - Agent ergonomics 47: A paid call takes a 402, a call to a Payment Service, a receipt and a retry, which is one party more than a direct 402 scheme. A receipt can be reused until it expires (15). A request can carry several payment options, there are server-initiated and client-initiated sequences and an optional `serviceCallback`, and no session or metering scheme is defined (12). No protocol error codes. The SDK throws two named error classes and the operations page asks implementers to write their own error taxonomy (5). The request `id` is there to stop replay and verifiers are told to reject reused receipts, with no idempotency key (8). One SDK, in TypeScript (7). - Security & auth 58: Payment Requests are signed JWTs and receipts are Verifiable Credentials checked against a list of trusted issuer DIDs, with revocation through a status list. Open issue 222 reports that `expiresAt` is not enforced (22). A human oversight page describes approval before execution, left to each Payment Service, and the demo's policy guard is labelled illustrative (10). The docs tell implementers to isolate LLM interfaces from signing components and list four receipt checks, with no warning about the free-text `description` (8). Receipts are signed records that can carry references to policy, mandate and settlement evidence (11). SECURITY.md gives a reporting address. No bug bounty, no security.txt and no published advisory, although 0.11.0 fixed a fail-open revocation check (7). - Payments & pricing 77: ACK-Pay is a payment protocol with a 402 request and a verifiable receipt, but it names no settlement method of its own and no public Payment Service was found to pay through (25). Scored with the self-hosted rule for the rest. No protocol fee, with any conversion fee left to the Payment Service to disclose (20). Docs and SDK are MIT with nothing to buy (20). The SDK installs from npm with no account, but a payment needs a Payment Service and a Receipt Service that somebody has to run (12). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 53: 0.11.0 of every package was tagged on 4 August 2026, 66 days before the check (20). That is the only release in the last 90 days, and nine changesets wait on main (0). 16 open issues, the oldest from 10 August 2026, and 37 open pull requests. Outside contributions were merged on main in September and on 6 October 2026 (15). One official SDK, current on npm (8). CI on every push, Dependabot and a scheduled audit workflow (10). - Transparency & trust 60: Docs and code are MIT, copyright Catena Labs, Inc. (30). No privacy policy or terms were found for agentcommercekit.com. The protocol pages say receipt metadata must not hold secrets or customer data and that the Payment Service hides the server's settlement account from the client (10). The versioning page defines Draft, Current and Final revisions, and the 0.11.0 changelog lists each removed API with its replacement (13). The ack-pay package depends on four workspace packages and valibot, and no telemetry was found in its manifest. The docs site names no legal entity, which appears only in the repository's LICENCE file and package manifests (10). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/ack-pay.md (JSON https://www.anchorterminal.com/fixes/ack-pay.json) ### What we couldn't check - Whether any Payment Service or Receipt Service runs ACK-Pay in production. None is named in the pages read. - unchecked: catenalabs.com. Its robots.txt request answered with a redirect that we did not follow, so the vendor's own site, blog and any hosted product were not read. - unchecked: the client-initiated sequence, use cases, summary, demo and ACK-ID pages of the docs, which were not read to keep to the page budget. - unchecked: the threads of the 16 open issues. Issue 222 on `expiresAt` was read by title only. In the source `createPaymentRequestToken` passes no expiry option to the JWT, which agrees with the title. - Whether the rendered docs pages link terms or a privacy policy in a footer. The Markdown copies and llms.txt link none. - Which protocol version follows 2025-05-04 and when. The roadmap lists x402 facilitation as planned research with no date. ### Sources - ACK-Pay introduction (Markdown copy): (seen 2026-10-09) - Payment Request payload and field table: (seen 2026-10-09) - Server-initiated sequence: (seen 2026-10-09) - Receipt format and verification steps: (seen 2026-10-09) - Payment Service role: (seen 2026-10-09) - Operational considerations and human oversight: (seen 2026-10-09) - Versioning policy: (seen 2026-10-09) - Roadmap: (seen 2026-10-09) - llms.txt: (seen 2026-10-09) - robots.txt (ai-input=yes) and security.txt (404): (seen 2026-10-09) - repository, read from a shallow clone at commit 3db94d6 (README, LICENCE, SECURITY.md, tags, changesets, ack-pay source and tests, payments demo): (seen 2026-10-09) - ack-pay changelog: (seen 2026-10-09) - open issues: (seen 2026-10-09) - security advisories (none published): (seen 2026-10-09) - Check workflow runs: (seen 2026-10-09) - npm latest version and weekly downloads: (seen 2026-10-09) - domain registration (RDAP): (seen 2026-10-09) ## Who's behind it (provenance 57/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Catena Labs, Inc. | 20/20 | | Domain age | agentcommercekit.com, registered 2025-05-02 (1 year) | 3/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | nothing hosted, so the MIT (docs and SDK) licence stands in | 10/10 | | Privacy policy | nothing hosted, not scored | n/a | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The docs site names no legal entity. Catena Labs, Inc. is the copyright holder in the repository's LICENCE file and the author in the package manifests. No terms or privacy policy were found for the docs site, so the MIT licence stands in. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT (docs and SDK) licence stands in and the check scores in full. **Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored. ## Live (updated 2026-10-09 18:44 UTC) - github `agentcommercekit/ack` agentcommercekit@0.11.0, released 2026-08-04 - npm `@agentcommercekit/ack-pay` 0.11.0 - npm `agentcommercekit` 0.11.0 - Watching changelog - Always current: https://www.anchorterminal.com/api/v1/live/ack-pay.json ## Probe metrics A specification has no endpoint to probe. Scores come from reference implementations, public facilitators, security analyses and adoption. See https://www.anchorterminal.com/benchmark/#kinds ## Strengths - Receipts are W3C Verifiable Credentials signed by a Receipt Service, so a server checks payment without calling the payment system - One Payment Request can list several options, such as USDC on Base and a card payment through Stripe, each with its own Payment Service - Docs and code are MIT, with llms.txt and a Markdown copy of every docs page - The SDK exports Valibot and Zod schemas for the request, the option and the receipt claim - CI builds, lints and tests on every push, and the last five runs on main on the page read passed ## Weaknesses - No public Payment Service or Receipt Service was found. The docs use example.com hosts and the demo pays on Base Sepolia, Solana devnet or a simulated Stripe flow - The protocol defines no error codes, idempotency key or retry header. The operations page tells implementers to design their own - One SDK, in TypeScript, at 0.11.0. One release in the last 90 days, with nine changesets waiting on main, including a receipt option check - 0.11.0 fixed a revocation check that accepted revoked credentials when the status list was unreachable. No GitHub advisory was published - Open issue 222 of 21 September 2026 reports that `expiresAt` on a Payment Request is never enforced - No terms, privacy policy, status page or security.txt on agentcommercekit.com ## Before you call it (notes for agents) 1. Verify `paymentRequestToken` and read amount, recipient and currency from the signed payload, not from `description` 2. Pass `trustedReceiptIssuers` to `verifyPaymentReceipt`. Without a trusted issuer list any DID can sign a receipt 3. Check amount, recipient and receipt reuse yourself. The SDK's claim verifier checks only the shape of the receipt 4. Use `@agentcommercekit/ack-pay` 0.11.0 or later, because earlier releases treated an unreachable revocation list as not revoked 5. Plan for a Payment Service and a Receipt Service you run or choose. The protocol names the roles and no public one was found ## Get started Install: ```bash npm i @agentcommercekit/ack-pay ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Machine Payments Protocol (MPP) | A | 81.1 | not ranked, protocol | payments.protocol, payments.stablecoin | no | https://www.anchorterminal.com/tools/mpp.md | | x402 | A | 79.7 | not ranked, protocol | payments.protocol, payments.stablecoin | no | https://www.anchorterminal.com/tools/x402.md | | Stripe API + MCP | A | 82.4 | 5 | payments.stablecoin | no | https://www.anchorterminal.com/tools/stripe-mcp.md | | Tempo | BB | 76.6 | 27 | payments.stablecoin | no | https://www.anchorterminal.com/tools/tempo.md | | Nevermined API + MCP | BB | 70.8 | 142 | payments.stablecoin | no | https://www.anchorterminal.com/tools/nevermined.md | | Circle Gateway Nanopayments | B | 67.6 | 247 | payments.stablecoin | no | https://www.anchorterminal.com/tools/circle-gateway-nanopayments.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Current protocol version is 2025-05-04, a date that changes only on incompatible changes (source: ) - 0.11.0 of 4 August 2026 made revocation checks fail closed and removed `createPaymentRequestBody` in favour of `createSignedPaymentRequest` (source: ) - The payments demo pays USDC on Base Sepolia or Solana devnet, or a simulated Stripe card payment (source: ) - `@agentcommercekit/ack-pay` had 54 npm downloads in the week to 7 October 2026 (source: ) - All 14 pay per call comparisons: https://www.anchorterminal.com/compare/pay-per-call/index.md ## Compare - [ACK-Pay (Agent Commerce Kit) vs Agentic Commerce Protocol (ACP)](https://www.anchorterminal.com/compare/ack-pay-vs-acp.md): D 53.6 vs C 60.9 - [ACK-Pay (Agent Commerce Kit) vs Agent Payments Protocol (AP2)](https://www.anchorterminal.com/compare/ack-pay-vs-ap2.md): D 53.6 vs C 55.3 - [ACK-Pay (Agent Commerce Kit) vs L402](https://www.anchorterminal.com/compare/ack-pay-vs-l402.md): D 53.6 vs C 60.5 - [ACK-Pay (Agent Commerce Kit) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/ack-pay-vs-mpp.md): D 53.6 vs A 81.1 - [ACK-Pay (Agent Commerce Kit) vs x402](https://www.anchorterminal.com/compare/ack-pay-vs-x402.md): D 53.6 vs A 79.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on agentcommercekit.com or one of its subdomains, or the README of github.com/agentcommercekit/ack. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "ack-pay", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html ACK-Pay (Agent Commerce Kit) on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![ACK-Pay (Agent Commerce Kit) on Anchor Terminal](https://www.anchorterminal.com/badges/ack-pay.svg)](https://www.anchorterminal.com/tools/ack-pay) ``` Plain link: ```html ACK-Pay (Agent Commerce Kit) on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say ACK-Pay (Agent Commerce Kit) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/ack-pay-dark.png - Light: https://www.anchorterminal.com/assets/share/ack-pay-light.png