{
  "type": "stack",
  "id": "agent-that-can-buy-things",
  "title": "Agent that can buy things",
  "summary": "The pieces for an agent that pays for APIs per call with x402 stablecoins and buys from merchants with controlled virtual cards, with spend limits, proof of user intent and a full audit trail.",
  "author": "Agentica Author",
  "tags": [
    "payments",
    "agent-commerce",
    "x402",
    "stablecoins",
    "cards",
    "guardrails"
  ],
  "published": "2026-10-02",
  "last_verified": "2026-10-02",
  "entries": [
    "claude-agent-sdk",
    "x402",
    "coinbase-agentic-wallet",
    "usdc",
    "x402-bazaar",
    "cdp-x402",
    "stripe-issuing-for-agents",
    "agentic-commerce-protocol",
    "universal-commerce-protocol",
    "agent-payments-protocol",
    "stripe-agentic-commerce",
    "machine-payments-protocol",
    "browserbase",
    "langfuse"
  ],
  "links": {
    "html": "https://indexagentica.com/stacks/agent-that-can-buy-things/",
    "markdown": "https://indexagentica.com/stacks/agent-that-can-buy-things.md",
    "json": "https://indexagentica.com/api/longform/stacks/agent-that-can-buy-things.json",
    "source": "https://github.com/Drudley/indexagentica/blob/main/content-long/stacks/agent-that-can-buy-things.md"
  },
  "status": "published",
  "stack": {
    "use_case": "Let an agent pay for metered APIs and tools on its own and complete merchant purchases for a user, within budgets you set and with a record of who authorized what.",
    "components": [
      {
        "role": "Agent harness",
        "entry": "claude-agent-sdk",
        "name": "Claude Agent SDK",
        "url": "https://indexagentica.com/entries/claude-agent-sdk/",
        "why": "Runs the agent loop with tools, skills and MCP in your own app, so payment tools sit behind code you control rather than prompts. Any harness with tool calling works."
      },
      {
        "role": "Machine payment protocol",
        "entry": "x402",
        "name": "x402",
        "url": "https://indexagentica.com/entries/x402/",
        "why": "Pay per request for HTTP APIs and MCP tools: the server answers 402 with a price, the agent signs a stablecoin payment and retries. SDKs default to USD stablecoins and a $1 cap per payment."
      },
      {
        "role": "Agent wallet",
        "entry": "coinbase-agentic-wallet",
        "name": "Coinbase Agentic Wallet",
        "url": "https://indexagentica.com/entries/coinbase-agentic-wallet/",
        "why": "A wallet built for agents, as the awal CLI with skills or as an MCP server (npx @coinbase/payments-mcp), that pays x402 services with guardrails such as a per-call maximum amount."
      },
      {
        "role": "Settlement currency",
        "entry": "usdc",
        "name": "USDC",
        "url": "https://indexagentica.com/entries/usdc/",
        "why": "The stablecoin most x402 services price in. Fund the agent's wallet with only what it may spend, and test on Base Sepolia with faucet USDC first."
      },
      {
        "role": "Service discovery",
        "entry": "x402-bazaar",
        "name": "x402 Bazaar",
        "url": "https://indexagentica.com/entries/x402-bazaar/",
        "why": "A public index of x402-payable endpoints with prices and schemas, so the agent can find a paid API without a human signing up for keys."
      },
      {
        "role": "Card credentials",
        "entry": "stripe-issuing-for-agents",
        "name": "Stripe Issuing for Agents",
        "url": "https://indexagentica.com/entries/stripe-issuing-for-agents/",
        "why": "Single-use or per-agent virtual cards with spend limits, merchant-category controls and real-time authorization webhooks, usable for programmatic checkout (MPP, UCP, Shared Payment Tokens) or in a browser."
      },
      {
        "role": "Merchant checkout protocol",
        "entry": "agentic-commerce-protocol",
        "name": "Agentic Commerce Protocol (ACP)",
        "url": "https://indexagentica.com/entries/agentic-commerce-protocol/",
        "why": "OpenAI and Stripe's open checkout standard (beta); lets an agent complete a purchase through a merchant's agent-ready checkout with a delegated payment token."
      },
      {
        "role": "Merchant checkout protocol (alternative)",
        "entry": "universal-commerce-protocol",
        "name": "Universal Commerce Protocol (UCP)",
        "url": "https://indexagentica.com/entries/universal-commerce-protocol/",
        "why": "Capability-based commerce standard over REST, MCP or A2A, covering checkout, identity linking and orders, with support for AP2 mandates."
      },
      {
        "role": "Proof of user intent",
        "entry": "agent-payments-protocol",
        "name": "Agent Payments Protocol (AP2)",
        "url": "https://indexagentica.com/entries/agent-payments-protocol/",
        "why": "Signed Checkout and Payment Mandates record what the user authorized, either a specific purchase or constraints like a budget, giving merchants and you an audit trail."
      },
      {
        "role": "Browser for non-agent checkouts",
        "entry": "browserbase",
        "name": "Browserbase",
        "url": "https://indexagentica.com/entries/browserbase/",
        "why": "A hosted browser for merchants without an agent-checkout API, kept apart from your own machine and sessions."
      },
      {
        "role": "Tracing",
        "entry": "langfuse",
        "name": "Langfuse",
        "url": "https://indexagentica.com/entries/langfuse/",
        "why": "Records every tool call and payment decision so you can reconcile spend against what the agent did and why."
      }
    ]
  },
  "entries_detail": [
    {
      "id": "claude-agent-sdk",
      "name": "Claude Agent SDK",
      "summary": "Anthropic's SDK for building production agents with Claude Code as a library, in Python and TypeScript.",
      "url": "https://indexagentica.com/entries/claude-agent-sdk/",
      "json": "https://indexagentica.com/api/entries/claude-agent-sdk.json"
    },
    {
      "id": "x402",
      "name": "x402",
      "summary": "Open standard for internet-native payments built on HTTP 402, letting APIs and agents pay per request across crypto and fiat networks.",
      "url": "https://indexagentica.com/entries/x402/",
      "json": "https://indexagentica.com/api/entries/x402.json"
    },
    {
      "id": "coinbase-agentic-wallet",
      "name": "Coinbase Agentic Wallet",
      "summary": "Wallet tooling that lets AI agents hold, spend, trade and earn stablecoins with guardrails, via the awal CLI + skills or an MCP server.",
      "url": "https://indexagentica.com/entries/coinbase-agentic-wallet/",
      "json": "https://indexagentica.com/api/entries/coinbase-agentic-wallet.json"
    },
    {
      "id": "usdc",
      "name": "USDC",
      "summary": "Fully reserved dollar stablecoin issued by Circle, the settlement asset used by many agent payment rails including x402.",
      "url": "https://indexagentica.com/entries/usdc/",
      "json": "https://indexagentica.com/api/entries/usdc.json"
    },
    {
      "id": "x402-bazaar",
      "name": "x402 Bazaar",
      "summary": "Public catalog of x402 payment-gated services discovered by the CDP Facilitator; search by intent, browse resources or look up by merchant address.",
      "url": "https://indexagentica.com/entries/x402-bazaar/",
      "json": "https://indexagentica.com/api/entries/x402-bazaar.json"
    },
    {
      "id": "cdp-x402",
      "name": "Coinbase CDP x402 Facilitator",
      "summary": "Coinbase Developer Platform's x402 offering: a hosted facilitator that verifies and settles x402 payments, plus seller and buyer SDK quickstarts.",
      "url": "https://indexagentica.com/entries/cdp-x402/",
      "json": "https://indexagentica.com/api/entries/cdp-x402.json"
    },
    {
      "id": "stripe-issuing-for-agents",
      "name": "Stripe Issuing for Agents",
      "summary": "Issue cards and credentials that agents can use to purchase autonomously, with spend controls, real-time authorization decisioning and full visibility.",
      "url": "https://indexagentica.com/entries/stripe-issuing-for-agents/",
      "json": "https://indexagentica.com/api/entries/stripe-issuing-for-agents.json"
    },
    {
      "id": "agentic-commerce-protocol",
      "name": "Agentic Commerce Protocol (ACP)",
      "summary": "Open standard from OpenAI and Stripe for programmatic checkout flows between buyers, their AI agents and businesses.",
      "url": "https://indexagentica.com/entries/agentic-commerce-protocol/",
      "json": "https://indexagentica.com/api/entries/agentic-commerce-protocol.json"
    },
    {
      "id": "universal-commerce-protocol",
      "name": "Universal Commerce Protocol (UCP)",
      "summary": "Open standard giving platforms (AI agents, apps), businesses, payment service providers and credential providers a common language for commerce.",
      "url": "https://indexagentica.com/entries/universal-commerce-protocol/",
      "json": "https://indexagentica.com/api/entries/universal-commerce-protocol.json"
    },
    {
      "id": "agent-payments-protocol",
      "name": "Agent Payments Protocol (AP2)",
      "summary": "Open protocol for AI agents to make payments on behalf of users securely, complementing A2A and MCP.",
      "url": "https://indexagentica.com/entries/agent-payments-protocol/",
      "json": "https://indexagentica.com/api/entries/agent-payments-protocol.json"
    },
    {
      "id": "stripe-agentic-commerce",
      "name": "Stripe Agentic Commerce",
      "summary": "Stripe integrations for selling through agents and embedding commerce in AI interfaces, including Shared Payment Tokens for agent-initiated purchases.",
      "url": "https://indexagentica.com/entries/stripe-agentic-commerce/",
      "json": "https://indexagentica.com/api/entries/stripe-agentic-commerce.json"
    },
    {
      "id": "machine-payments-protocol",
      "name": "Machine Payments Protocol (MPP)",
      "summary": "Open standard for machine-to-machine payments over HTTP 402, co-developed by Tempo and Stripe; charge per API request, tool call or content.",
      "url": "https://indexagentica.com/entries/machine-payments-protocol/",
      "json": "https://indexagentica.com/api/entries/machine-payments-protocol.json"
    },
    {
      "id": "browserbase",
      "name": "Browserbase",
      "summary": "Hosted headless-browser infrastructure that gives agents access to the whole web.",
      "url": "https://indexagentica.com/entries/browserbase/",
      "json": "https://indexagentica.com/api/entries/browserbase.json"
    },
    {
      "id": "langfuse",
      "name": "Langfuse",
      "summary": "Open-source agent evals and observability platform: trace, evaluate and improve LLM applications and agents.",
      "url": "https://indexagentica.com/entries/langfuse/",
      "json": "https://indexagentica.com/api/entries/langfuse.json"
    }
  ],
  "related": [
    {
      "type": "guide",
      "id": "pay-for-an-api-with-x402",
      "title": "Pay for an API as an agent with x402",
      "url": "https://indexagentica.com/guides/pay-for-an-api-with-x402/",
      "json": "https://indexagentica.com/api/longform/guides/pay-for-an-api-with-x402.json"
    },
    {
      "type": "skill",
      "id": "pay-with-x402",
      "title": "Pay with x402",
      "url": "https://indexagentica.com/skills/pay-with-x402/",
      "json": "https://indexagentica.com/api/longform/skills/pay-with-x402.json"
    },
    {
      "type": "comparison",
      "id": "agent-payment-rails",
      "title": "Agent payment protocols compared",
      "url": "https://indexagentica.com/compare/agent-payment-rails/",
      "json": "https://indexagentica.com/api/longform/compare/agent-payment-rails.json"
    },
    {
      "type": "guide",
      "id": "run-untrusted-code-in-a-sandbox",
      "title": "Run agent-generated code safely in a sandbox",
      "url": "https://indexagentica.com/guides/run-untrusted-code-in-a-sandbox/",
      "json": "https://indexagentica.com/api/longform/guides/run-untrusted-code-in-a-sandbox.json"
    }
  ],
  "sources": [
    {
      "title": "x402 Protocol Specification v2",
      "url": "https://github.com/x402-foundation/x402/blob/main/specs/x402-specification-v2.md",
      "accessed": "2026-10-02"
    },
    {
      "title": "x402 docs, Quickstart for Buyers",
      "url": "https://docs.x402.org/getting-started/quickstart-for-buyers",
      "accessed": "2026-10-02"
    },
    {
      "title": "Coinbase CDP, Agentic Wallet overview",
      "url": "https://docs.cdp.coinbase.com/agentic-wallet/welcome",
      "accessed": "2026-10-02"
    },
    {
      "title": "x402 docs, Bazaar (Discovery Layer)",
      "url": "https://docs.x402.org/extensions/bazaar",
      "accessed": "2026-10-02"
    },
    {
      "title": "Stripe docs, Issuing for agents",
      "url": "https://docs.stripe.com/issuing/agents",
      "accessed": "2026-10-02"
    },
    {
      "title": "Agentic Commerce Protocol repository",
      "url": "https://github.com/agentic-commerce-protocol/agentic-commerce-protocol",
      "accessed": "2026-10-02"
    },
    {
      "title": "Universal Commerce Protocol repository",
      "url": "https://github.com/Universal-Commerce-Protocol/ucp",
      "accessed": "2026-10-02"
    },
    {
      "title": "AP2 documentation",
      "url": "https://ap2-protocol.org/",
      "accessed": "2026-10-02"
    }
  ],
  "front_matter": {
    "id": "agent-that-can-buy-things",
    "type": "stack",
    "title": "Agent that can buy things",
    "summary": "The pieces for an agent that pays for APIs per call with x402 stablecoins and buys from merchants with controlled virtual cards, with spend limits, proof of user intent and a full audit trail.",
    "description": "Two payment paths cover most of what an agent needs to buy. Machine payments (x402) handle per-request charges for APIs and MCP tools from a dedicated stablecoin wallet. Card payments handle merchants, through agent-checkout protocols where they exist and a browser where they don't, using single-use or per-agent virtual cards. This stack lists a component for each job and the guardrails to put around it.",
    "author": "Agentica Author",
    "use_case": "Let an agent pay for metered APIs and tools on its own and complete merchant purchases for a user, within budgets you set and with a record of who authorized what.",
    "components": [
      {
        "role": "Agent harness",
        "entry": "claude-agent-sdk",
        "why": "Runs the agent loop with tools, skills and MCP in your own app, so payment tools sit behind code you control rather than prompts. Any harness with tool calling works."
      },
      {
        "role": "Machine payment protocol",
        "entry": "x402",
        "why": "Pay per request for HTTP APIs and MCP tools: the server answers 402 with a price, the agent signs a stablecoin payment and retries. SDKs default to USD stablecoins and a $1 cap per payment."
      },
      {
        "role": "Agent wallet",
        "entry": "coinbase-agentic-wallet",
        "why": "A wallet built for agents, as the awal CLI with skills or as an MCP server (npx @coinbase/payments-mcp), that pays x402 services with guardrails such as a per-call maximum amount."
      },
      {
        "role": "Settlement currency",
        "entry": "usdc",
        "why": "The stablecoin most x402 services price in. Fund the agent's wallet with only what it may spend, and test on Base Sepolia with faucet USDC first."
      },
      {
        "role": "Service discovery",
        "entry": "x402-bazaar",
        "why": "A public index of x402-payable endpoints with prices and schemas, so the agent can find a paid API without a human signing up for keys."
      },
      {
        "role": "Card credentials",
        "entry": "stripe-issuing-for-agents",
        "why": "Single-use or per-agent virtual cards with spend limits, merchant-category controls and real-time authorization webhooks, usable for programmatic checkout (MPP, UCP, Shared Payment Tokens) or in a browser."
      },
      {
        "role": "Merchant checkout protocol",
        "entry": "agentic-commerce-protocol",
        "why": "OpenAI and Stripe's open checkout standard (beta); lets an agent complete a purchase through a merchant's agent-ready checkout with a delegated payment token."
      },
      {
        "role": "Merchant checkout protocol (alternative)",
        "entry": "universal-commerce-protocol",
        "why": "Capability-based commerce standard over REST, MCP or A2A, covering checkout, identity linking and orders, with support for AP2 mandates."
      },
      {
        "role": "Proof of user intent",
        "entry": "agent-payments-protocol",
        "why": "Signed Checkout and Payment Mandates record what the user authorized, either a specific purchase or constraints like a budget, giving merchants and you an audit trail."
      },
      {
        "role": "Browser for non-agent checkouts",
        "entry": "browserbase",
        "why": "A hosted browser for merchants without an agent-checkout API, kept apart from your own machine and sessions."
      },
      {
        "role": "Tracing",
        "entry": "langfuse",
        "why": "Records every tool call and payment decision so you can reconcile spend against what the agent did and why."
      }
    ],
    "tags": [
      "payments",
      "agent-commerce",
      "x402",
      "stablecoins",
      "cards",
      "guardrails"
    ],
    "entries": [
      "claude-agent-sdk",
      "x402",
      "coinbase-agentic-wallet",
      "usdc",
      "x402-bazaar",
      "cdp-x402",
      "stripe-issuing-for-agents",
      "agentic-commerce-protocol",
      "universal-commerce-protocol",
      "agent-payments-protocol",
      "stripe-agentic-commerce",
      "machine-payments-protocol",
      "browserbase",
      "langfuse"
    ],
    "sources": [
      {
        "title": "x402 Protocol Specification v2",
        "url": "https://github.com/x402-foundation/x402/blob/main/specs/x402-specification-v2.md",
        "accessed": "2026-10-02"
      },
      {
        "title": "x402 docs, Quickstart for Buyers",
        "url": "https://docs.x402.org/getting-started/quickstart-for-buyers",
        "accessed": "2026-10-02"
      },
      {
        "title": "Coinbase CDP, Agentic Wallet overview",
        "url": "https://docs.cdp.coinbase.com/agentic-wallet/welcome",
        "accessed": "2026-10-02"
      },
      {
        "title": "x402 docs, Bazaar (Discovery Layer)",
        "url": "https://docs.x402.org/extensions/bazaar",
        "accessed": "2026-10-02"
      },
      {
        "title": "Stripe docs, Issuing for agents",
        "url": "https://docs.stripe.com/issuing/agents",
        "accessed": "2026-10-02"
      },
      {
        "title": "Agentic Commerce Protocol repository",
        "url": "https://github.com/agentic-commerce-protocol/agentic-commerce-protocol",
        "accessed": "2026-10-02"
      },
      {
        "title": "Universal Commerce Protocol repository",
        "url": "https://github.com/Universal-Commerce-Protocol/ucp",
        "accessed": "2026-10-02"
      },
      {
        "title": "AP2 documentation",
        "url": "https://ap2-protocol.org/",
        "accessed": "2026-10-02"
      }
    ],
    "related": [
      "pay-for-an-api-with-x402",
      "pay-with-x402",
      "agent-payment-rails",
      "run-untrusted-code-in-a-sandbox"
    ],
    "last_verified": "2026-10-02",
    "published": "2026-10-02"
  },
  "markdown": "\n## Two ways an agent pays\n\n**Per call, in stablecoins.** For APIs and MCP tools that charge per request, the agent holds a small [USDC](https://indexagentica.com/entries/usdc/) balance in an [agent wallet](https://indexagentica.com/entries/coinbase-agentic-wallet/) and pays with [x402](https://indexagentica.com/entries/x402/): request, get 402 with a price, sign, retry. There are no accounts or API keys to create, and each payment is capped. The [x402 guide](https://indexagentica.com/guides/pay-for-an-api-with-x402/) walks through it, and the [pay-with-x402 skill](https://indexagentica.com/skills/pay-with-x402/) teaches a coding agent to do it safely.\n\n**At a merchant, by card.** For physical goods, subscriptions and anything sold through a normal checkout, the agent uses a card you control: a single-use or per-agent virtual card from [Stripe Issuing for agents](https://indexagentica.com/entries/stripe-issuing-for-agents/). Where the merchant supports an agent-checkout protocol ([ACP](https://indexagentica.com/entries/agentic-commerce-protocol/) or [UCP](https://indexagentica.com/entries/universal-commerce-protocol/)), the card travels as a delegated token and the agent never sees the number. Where it doesn't, the agent fills in the checkout in a hosted browser ([Browserbase](https://indexagentica.com/entries/browserbase/)).\n\nThe [agent payment protocols comparison](https://indexagentica.com/compare/agent-payment-rails/) explains how these protocols relate, including [MPP](https://indexagentica.com/entries/machine-payments-protocol/), which can serve both stablecoin and card payments on one endpoint.\n\n## Guardrails to set before the first purchase\n\n- **Separate money.** Give the agent its own wallet and its own cards. Fund the wallet with only what it may spend; never connect it to a treasury or a personal wallet.\n- **Caps at every layer.** x402 SDKs default to a $1 maximum per payment; keep a low cap and add a daily budget in your own tool code. On cards, use single-use cards per task, per-agent spend limits and merchant-category restrictions, and decline anything unexpected in Stripe's real-time authorization webhook.\n- **Human approval above a threshold.** Let the agent pay small metered charges on its own, and require a person to confirm purchases above an amount you choose. AP2 mandates are a standard way to record that confirmation, or the user's standing constraints for unattended purchases.\n- **Treat inputs as hostile.** Product pages, emails and API responses can carry prompt injections that try to trigger a purchase. Keep payment tools out of agents that browse untrusted content without a confirmation step, and check the recipient and amount in code, not in the prompt.\n- **Test first.** Use Base Sepolia and faucet USDC for x402, and Stripe test mode for cards, until the traces show the agent behaving as intended.\n- **Reconcile.** Trace every payment tool call with [Langfuse](https://indexagentica.com/entries/langfuse/) and match it against wallet transactions and card authorizations.\n",
  "raw": "---\nid: agent-that-can-buy-things\ntype: stack\ntitle: Agent that can buy things\nsummary: The pieces for an agent that pays for APIs per call with x402 stablecoins and buys from merchants with controlled virtual cards, with spend limits, proof of user intent and a full audit trail.\ndescription: \"Two payment paths cover most of what an agent needs to buy. Machine payments (x402) handle per-request charges for APIs and MCP tools from a dedicated stablecoin wallet. Card payments handle merchants, through agent-checkout protocols where they exist and a browser where they don't, using single-use or per-agent virtual cards. This stack lists a component for each job and the guardrails to put around it.\"\nauthor: Agentica Author\nuse_case: Let an agent pay for metered APIs and tools on its own and complete merchant purchases for a user, within budgets you set and with a record of who authorized what.\ncomponents:\n  - role: Agent harness\n    entry: claude-agent-sdk\n    why: \"Runs the agent loop with tools, skills and MCP in your own app, so payment tools sit behind code you control rather than prompts. Any harness with tool calling works.\"\n  - role: Machine payment protocol\n    entry: x402\n    why: \"Pay per request for HTTP APIs and MCP tools: the server answers 402 with a price, the agent signs a stablecoin payment and retries. SDKs default to USD stablecoins and a $1 cap per payment.\"\n  - role: Agent wallet\n    entry: coinbase-agentic-wallet\n    why: \"A wallet built for agents, as the awal CLI with skills or as an MCP server (npx @coinbase/payments-mcp), that pays x402 services with guardrails such as a per-call maximum amount.\"\n  - role: Settlement currency\n    entry: usdc\n    why: \"The stablecoin most x402 services price in. Fund the agent's wallet with only what it may spend, and test on Base Sepolia with faucet USDC first.\"\n  - role: Service discovery\n    entry: x402-bazaar\n    why: \"A public index of x402-payable endpoints with prices and schemas, so the agent can find a paid API without a human signing up for keys.\"\n  - role: Card credentials\n    entry: stripe-issuing-for-agents\n    why: \"Single-use or per-agent virtual cards with spend limits, merchant-category controls and real-time authorization webhooks, usable for programmatic checkout (MPP, UCP, Shared Payment Tokens) or in a browser.\"\n  - role: Merchant checkout protocol\n    entry: agentic-commerce-protocol\n    why: \"OpenAI and Stripe's open checkout standard (beta); lets an agent complete a purchase through a merchant's agent-ready checkout with a delegated payment token.\"\n  - role: Merchant checkout protocol (alternative)\n    entry: universal-commerce-protocol\n    why: \"Capability-based commerce standard over REST, MCP or A2A, covering checkout, identity linking and orders, with support for AP2 mandates.\"\n  - role: Proof of user intent\n    entry: agent-payments-protocol\n    why: \"Signed Checkout and Payment Mandates record what the user authorized, either a specific purchase or constraints like a budget, giving merchants and you an audit trail.\"\n  - role: Browser for non-agent checkouts\n    entry: browserbase\n    why: \"A hosted browser for merchants without an agent-checkout API, kept apart from your own machine and sessions.\"\n  - role: Tracing\n    entry: langfuse\n    why: \"Records every tool call and payment decision so you can reconcile spend against what the agent did and why.\"\ntags: [payments, agent-commerce, x402, stablecoins, cards, guardrails]\nentries: [claude-agent-sdk, x402, coinbase-agentic-wallet, usdc, x402-bazaar, cdp-x402, stripe-issuing-for-agents, agentic-commerce-protocol, universal-commerce-protocol, agent-payments-protocol, stripe-agentic-commerce, machine-payments-protocol, browserbase, langfuse]\nsources:\n  - title: x402 Protocol Specification v2\n    url: https://github.com/x402-foundation/x402/blob/main/specs/x402-specification-v2.md\n    accessed: 2026-10-02\n  - title: x402 docs, Quickstart for Buyers\n    url: https://docs.x402.org/getting-started/quickstart-for-buyers\n    accessed: 2026-10-02\n  - title: Coinbase CDP, Agentic Wallet overview\n    url: https://docs.cdp.coinbase.com/agentic-wallet/welcome\n    accessed: 2026-10-02\n  - title: x402 docs, Bazaar (Discovery Layer)\n    url: https://docs.x402.org/extensions/bazaar\n    accessed: 2026-10-02\n  - title: Stripe docs, Issuing for agents\n    url: https://docs.stripe.com/issuing/agents\n    accessed: 2026-10-02\n  - title: Agentic Commerce Protocol repository\n    url: https://github.com/agentic-commerce-protocol/agentic-commerce-protocol\n    accessed: 2026-10-02\n  - title: Universal Commerce Protocol repository\n    url: https://github.com/Universal-Commerce-Protocol/ucp\n    accessed: 2026-10-02\n  - title: AP2 documentation\n    url: https://ap2-protocol.org/\n    accessed: 2026-10-02\nrelated: [pay-for-an-api-with-x402, pay-with-x402, agent-payment-rails, run-untrusted-code-in-a-sandbox]\nlast_verified: 2026-10-02\npublished: 2026-10-02\n---\n\n## Two ways an agent pays\n\n**Per call, in stablecoins.** For APIs and MCP tools that charge per request, the agent holds a small [USDC](https://indexagentica.com/entries/usdc/) balance in an [agent wallet](https://indexagentica.com/entries/coinbase-agentic-wallet/) and pays with [x402](https://indexagentica.com/entries/x402/): request, get 402 with a price, sign, retry. There are no accounts or API keys to create, and each payment is capped. The [x402 guide](https://indexagentica.com/guides/pay-for-an-api-with-x402/) walks through it, and the [pay-with-x402 skill](https://indexagentica.com/skills/pay-with-x402/) teaches a coding agent to do it safely.\n\n**At a merchant, by card.** For physical goods, subscriptions and anything sold through a normal checkout, the agent uses a card you control: a single-use or per-agent virtual card from [Stripe Issuing for agents](https://indexagentica.com/entries/stripe-issuing-for-agents/). Where the merchant supports an agent-checkout protocol ([ACP](https://indexagentica.com/entries/agentic-commerce-protocol/) or [UCP](https://indexagentica.com/entries/universal-commerce-protocol/)), the card travels as a delegated token and the agent never sees the number. Where it doesn't, the agent fills in the checkout in a hosted browser ([Browserbase](https://indexagentica.com/entries/browserbase/)).\n\nThe [agent payment protocols comparison](https://indexagentica.com/compare/agent-payment-rails/) explains how these protocols relate, including [MPP](https://indexagentica.com/entries/machine-payments-protocol/), which can serve both stablecoin and card payments on one endpoint.\n\n## Guardrails to set before the first purchase\n\n- **Separate money.** Give the agent its own wallet and its own cards. Fund the wallet with only what it may spend; never connect it to a treasury or a personal wallet.\n- **Caps at every layer.** x402 SDKs default to a $1 maximum per payment; keep a low cap and add a daily budget in your own tool code. On cards, use single-use cards per task, per-agent spend limits and merchant-category restrictions, and decline anything unexpected in Stripe's real-time authorization webhook.\n- **Human approval above a threshold.** Let the agent pay small metered charges on its own, and require a person to confirm purchases above an amount you choose. AP2 mandates are a standard way to record that confirmation, or the user's standing constraints for unattended purchases.\n- **Treat inputs as hostile.** Product pages, emails and API responses can carry prompt injections that try to trigger a purchase. Keep payment tools out of agents that browse untrusted content without a confirmation step, and check the recipient and amount in code, not in the prompt.\n- **Test first.** Use Base Sepolia and faucet USDC for x402, and Stripe test mode for cards, until the traces show the agent behaving as intended.\n- **Reconcile.** Trace every payment tool call with [Langfuse](https://indexagentica.com/entries/langfuse/) and match it against wallet transactions and card authorizations.\n",
  "html": "<h2>Two ways an agent pays</h2>\n<p><strong>Per call, in stablecoins.</strong> For APIs and MCP tools that charge per request, the agent holds a small <a href=\"/entries/usdc/\">USDC</a> balance in an <a href=\"/entries/coinbase-agentic-wallet/\">agent wallet</a> and pays with <a href=\"/entries/x402/\">x402</a>: request, get 402 with a price, sign, retry. There are no accounts or API keys to create, and each payment is capped. The <a href=\"/guides/pay-for-an-api-with-x402/\">x402 guide</a> walks through it, and the <a href=\"/skills/pay-with-x402/\">pay-with-x402 skill</a> teaches a coding agent to do it safely.</p>\n<p><strong>At a merchant, by card.</strong> For physical goods, subscriptions and anything sold through a normal checkout, the agent uses a card you control: a single-use or per-agent virtual card from <a href=\"/entries/stripe-issuing-for-agents/\">Stripe Issuing for agents</a>. Where the merchant supports an agent-checkout protocol (<a href=\"/entries/agentic-commerce-protocol/\">ACP</a> or <a href=\"/entries/universal-commerce-protocol/\">UCP</a>), the card travels as a delegated token and the agent never sees the number. Where it doesn&#39;t, the agent fills in the checkout in a hosted browser (<a href=\"/entries/browserbase/\">Browserbase</a>).</p>\n<p>The <a href=\"/compare/agent-payment-rails/\">agent payment protocols comparison</a> explains how these protocols relate, including <a href=\"/entries/machine-payments-protocol/\">MPP</a>, which can serve both stablecoin and card payments on one endpoint.</p>\n<h2>Guardrails to set before the first purchase</h2>\n<ul><li><strong>Separate money.</strong> Give the agent its own wallet and its own cards. Fund the wallet with only what it may spend; never connect it to a treasury or a personal wallet.</li><li><strong>Caps at every layer.</strong> x402 SDKs default to a $1 maximum per payment; keep a low cap and add a daily budget in your own tool code. On cards, use single-use cards per task, per-agent spend limits and merchant-category restrictions, and decline anything unexpected in Stripe&#39;s real-time authorization webhook.</li><li><strong>Human approval above a threshold.</strong> Let the agent pay small metered charges on its own, and require a person to confirm purchases above an amount you choose. AP2 mandates are a standard way to record that confirmation, or the user&#39;s standing constraints for unattended purchases.</li><li><strong>Treat inputs as hostile.</strong> Product pages, emails and API responses can carry prompt injections that try to trigger a purchase. Keep payment tools out of agents that browse untrusted content without a confirmation step, and check the recipient and amount in code, not in the prompt.</li><li><strong>Test first.</strong> Use Base Sepolia and faucet USDC for x402, and Stripe test mode for cards, until the traces show the agent behaving as intended.</li><li><strong>Reconcile.</strong> Trace every payment tool call with <a href=\"/entries/langfuse/\">Langfuse</a> and match it against wallet transactions and card authorizations.</li></ul>"
}
