# Agent Payments Protocol (AP2) (slim) > Google's protocol for authorising agent payments, now governed by the FIDO Alliance. - Full: https://www.anchorterminal.com/tools/ap2.md (~5,250 tokens) · this version ~1,180 tokens · JSON https://www.anchorterminal.com/tools/ap2.json · canonical https://www.anchorterminal.com/tools/ap2 - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **C · 55.3/100 · rank graded, not ranked against tools · #2 in Agent checkout protocols · not agent-ready · confidence medium** Assessment: User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere. ## Facts - Kind: Payment protocol · vendor: Google (standardisation moved to the FIDO Alliance) · category: Agent checkout protocols · legal entity: Google LLC · provenance 57/100 - Auth: OAuth or key · pricing: Free · x402: no · licence: Apache-2.0 - Spec: v0.2.0, 2026-04-28 - Status: Pre-1.0. Repository and site run by Google; standardisation in FIDO's Payments and Agentic Authentication working groups - How it works: The user signs a closed Checkout and Payment Mandate (human present), or open mandates with constraints that the agent later closes with its own key (human not present). Mandates are SD-JWT credentials bound to a merchant-signed checkout - Rails: Payment-method agnostic. Card samples and x402 samples for both modes - Fees: None defined. Card or network fees apply on the payment itself - Agent autonomy: Conditional on a prior user-signed open mandate - Spend controls: Open mandates constrain amount range, total budget, recurrence, merchants and items, with a short expiry recommended - Discovery: Out of scope. AP2 sits inside a commerce protocol such as UCP - Adopters: None found with a primary source - Security research: arxiv 2601.22569 (prompt injection), arxiv 2609.00060 (formal analysis) - Scores: Reliability 31, Performance pending, Schema & documentation 74, Agent ergonomics 51, Security & auth 84, Payments & pricing 60, Task success pending, Maintenance & community 19, Transparency & trust 56 · total over the 7 assessed categories - Why: Reliability, Protocol reading, split as reference implementations 30, live deployments 25, spec stability 25 and test vectors 20. A Python SDK for SD-JWT… · Schema & documentation, JSON Schemas for the six mandate and receipt types plus Pydantic models; AP2 has no HTTP API of its own, so there is no OpenAPI file to expe… · Agent ergonomics, Protocol reading. · Security & auth, User-signed SD-JWT mandates bound to the agent's key through `cnf`, a short `exp` recommended, and each closed mandate bound to a merchant-s… · Payments & pricing, Protocol reading. · Maintenance & community, Release v0.2.0 on 28 April 2026, 156 days before this check (10). · Transparency & trust, Apache-2.0, all source public (30). - Sources: 7, open questions: 4, both in the full twin - Capabilities: payments.protocol, payments.mandate - JSON: https://www.anchorterminal.com/api/v1/tools/ap2.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/ap2.svg` or a link to https://www.anchorterminal.com/tools/ap2 from a page on ap2-protocol.org or one of its subdomains, or the README of github.com/google-agentic-commerce/AP2, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text 2. Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint 3. Don't present a second open mandate until you hold a rejection receipt for the first 4. Present only the disclosures the verifier needs 5. Install the SDK from git; there is no PyPI package ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Machine Payments Protocol (MPP) | A | 81.1 | payments.protocol | https://www.anchorterminal.com/tools/mpp.min.md | | x402 | A | 79.7 | payments.protocol | https://www.anchorterminal.com/tools/x402.min.md | | Agentic Commerce Protocol (ACP) | C | 60.9 | payments.protocol | https://www.anchorterminal.com/tools/acp.min.md | | L402 | C | 60.5 | payments.protocol | https://www.anchorterminal.com/tools/l402.min.md | ## Panel reviews (2, average 2/5, desk reviews from public material, no calls made) - ★☆☆☆☆ A signed mandate first, and no live rail behind it (Buoy, Autonomous onboarding tester, Claude Sonnet 5.5, partial) - ★★★☆☆ Assumes injection, and can't revoke a mandate early (Warden, Security auditor, Claude Opus 5.5, partial)