Agent payment protocols compared
x402, MPP, L402, ACP, AP2 and UCP compared on what each standardizes, payment rails, wire format, governance, spec status and SDKs, so you can tell machine-payment protocols from agent-checkout protocols.
Comparison
| Entry | What it standardizes | Payment rails | Wire format | Governance | Spec status | SDKs and reference code |
|---|---|---|---|---|---|---|
| x402 | Paying for an HTTP resource or MCP tool call in the same request (machine payments) | Stablecoins and tokens on EVM chains and Solana, identified by CAIP-2 network IDs; schemes exact, upto, batch-settlement and auth-capture | HTTP 402 with PAYMENT-REQUIRED, PAYMENT-SIGNATURE and PAYMENT-RESPONSE headers (v1 used X-PAYMENT); MCP via _meta x402/payment | x402 Foundation under the Linux Foundation (operational launch July 2026); repo x402-foundation/x402 | v2 (spec dated 2025-12-09) | Official TypeScript, Python and Go SDKs; hosted facilitators such as Coinbase CDP |
| Machine Payments Protocol (MPP) | Paying for an HTTP resource, tool call or stream in the same request (machine payments), with one-time, session and subscription intents | Method-neutral: Tempo stablecoins, Stripe and card methods, EVM, Lightning, Solana, Stellar, XRPL and others, each specified by its rail | HTTP 402 with a WWW-Authenticate: Payment challenge, a payment Credential on retry and a Payment-Receipt; also JSON-RPC/MCP and WebSocket transports | Co-authored by Tempo and Stripe; core submitted to the IETF as the Payment HTTP Authentication Scheme; payment methods owned by each rail | IETF Internet-Draft (draft-httpauth-payment); docs at mpp.dev | Official TypeScript (mppx), Python, Rust, Go and Ruby SDKs |
| L402 (Lightning HTTP 402) | Paying for and authenticating to an API with a Lightning payment (machine payments) | Bitcoin over the Lightning Network | HTTP 402 with WWW-Authenticate carrying a macaroon and a Lightning invoice; the client presents the macaroon with the payment preimage | Lightning Labs | Published by Lightning Labs; implemented by the Aperture proxy | Aperture reverse proxy (MIT) |
| Agentic Commerce Protocol (ACP) | Checkout between a buyer's AI agent and a merchant: carts, checkout sessions, fulfillment, orders, delegated payment tokens | Cards and other methods through the merchant's PSP; Stripe Shared Payment Token was the first compatible PSP token | REST (OpenAPI and JSON Schema) or MCP | Maintained by OpenAI and Stripe; Apache-2.0; CLA required | Beta; latest stable 2026-04-17 (cart, feed, orders, authentication, MCP) | OpenAPI and JSON Schema per version, RFCs and examples; ChatGPT was the first agent platform |
| Universal Commerce Protocol (UCP) | Commerce capabilities a business declares for agents and apps: checkout, identity linking (OAuth 2.0), orders, payment token exchange, plus extensions | Payment-method neutral; PSPs and credential providers exchange tokens; supports AP2 mandates | Transport-agnostic: REST, MCP or A2A, with a discoverable business profile | Open source (Apache-2.0, 'UCP Authors'), with retail, travel and platform companies shown on ucp.dev | Dated stable releases; latest 2026-08-25 | SDKs, samples and conformance tests in the Universal-Commerce-Protocol GitHub org |
| Agent Payments Protocol (AP2) | Proof that a user authorized an agent's purchase: signed Checkout and Payment Mandates (verifiable digital credentials), human-present or not | Cards first; roadmap adds e-wallets, real-time bank transfers and digital currencies; x402 samples exist | Extension for A2A and UCP (also positioned for MCP) | Created by Google; donated to the FIDO Alliance, where standardization continues in its working groups | v0.2 | Python SDK; Python, Go and Android samples (Apache-2.0) |
Verdict: If your agent needs to pay per API call or tool call, choose between x402 and MPP: x402 has the larger live ecosystem and Linux Foundation governance, MPP is method-neutral (cards and many chains) and on the IETF track, and MPP documents serving x402 clients from the same endpoint. Use L402 only if you want Bitcoin Lightning. If your agent buys from merchants on a user's behalf, you will meet ACP (ChatGPT, Stripe) and UCP (retail, travel and platform participants), with AP2 mandates as the evidence layer for user intent.
Two problems, six protocols
"Agent payments" covers two different jobs, and most confusion comes from mixing them up.
Machine payments put a price on a request. An agent calls an API or an MCP tool, gets HTTP 402 Payment Required with a price, pays, and retries. There is no merchant checkout, no cart and often no human in the loop; amounts are often fractions of a cent. x402, the Machine Payments Protocol (MPP) and L402 live here.
Agent checkout lets an agent buy from a merchant for a person: products, carts, shipping, taxes, card networks, refunds, and evidence that the person really authorized it. The Agentic Commerce Protocol (ACP), the Universal Commerce Protocol (UCP) and the Agent Payments Protocol (AP2) live here. They are complementary more than competing: ACP and UCP describe the checkout conversation, and AP2 describes signed mandates that prove intent, which UCP explicitly supports.
Machine payments: x402, MPP and L402
All three reuse HTTP 402, and the flows look alike: challenge, pay, retry with proof, receive the resource and a receipt. The differences are in rails and governance.
- x402 carries its payment terms and proofs in its own headers (
PAYMENT-REQUIRED,PAYMENT-SIGNATURE,PAYMENT-RESPONSE) and settles in stablecoins on EVM chains and Solana, usually through a facilitator such as Coinbase CDP. Since July 2026 it has been governed by the x402 Foundation under the Linux Foundation. x402.org showed about 75 million transactions in the last 30 days when checked. The x402 guide walks through a full payment. - MPP frames payment as an HTTP authentication scheme (
WWW-Authenticate: Payment, then a Credential, then aPayment-Receipt) and submits that core to the IETF. It leaves the rails to "payment methods" owned by each rail, so one endpoint can accept Tempo stablecoins, cards through Stripe, Lightning and several chains. It adds session and subscription intents for metered and recurring billing. MPP's docs include a guide to serving x402 clients from the same endpoint, so choosing MPP on the server doesn't lock out x402 buyers. - L402 binds a macaroon (a bearer token with caveats) to a Lightning invoice; paying the invoice reveals the preimage that makes the token valid, so the server verifies payment without a database lookup. It is the oldest of the three and the natural choice if you already run Lightning.
For an agent builder the practical questions are which services you want to call and what they accept (the x402 Bazaar is a public discovery index for x402 services), which wallet the agent holds, and whether you need card or fiat rails (MPP's card and Stripe methods).
Agent checkout: ACP, UCP and AP2
- ACP is maintained by OpenAI and Stripe and is still marked beta, with dated releases (the latest stable is 2026-04-17, which added carts, product feeds, orders, authentication and MCP). The merchant stays merchant of record and can accept or decline per agent. Payment credentials travel as delegated tokens; Stripe's Shared Payment Token was the first. ChatGPT was the first agent platform to implement it.
- UCP breaks commerce into capabilities a business declares in a discoverable profile: checkout, identity linking over OAuth 2.0, orders and payment token exchange, with extensions such as discounts, fulfillment and loyalty. It is transport-agnostic (REST, MCP or A2A) and ships conformance tests. Its latest stable release is dated 2026-08-25.
- AP2 doesn't run the checkout; it proves authority. A Checkout Mandate captures what is being bought and a Payment Mandate authorizes a specific instrument, each in an "open" form (constraints for autonomous buying, like a budget) or a "closed" form (a specific, final purchase). The mandates are signed verifiable digital credentials, chained into an audit trail. Recent change: AP2 v0.2 (released 2026-04-28) focuses on human-not-present flows, and Google donated AP2 to the FIDO Alliance, where standardization continues.
Recent changes worth knowing
- x402's canonical repository moved to
x402-foundation/x402;coinbase/x402is now a development fork. - x402 v2 renamed its headers; older v1 code that sends
X-PAYMENTneeds the migration guide. - AP2's documentation now describes Checkout and Payment Mandates, each with open and closed stages. The v0.1 material (September 2025) described Intent, Cart and Payment Mandates, so older tutorials use different names.
- ACP moved from a single spec to dated versions with capability negotiation, extensions and an MCP binding.
Where card networks and Stripe fit
Card networks and processors run their own agent programs on top of or beside these protocols, including Visa Intelligent Commerce, the Mastercard Agent Suite, Stripe's agentic commerce tools and Stripe Issuing for agents. Their exact terms weren't compared here; check each entry's sources. To assemble these pieces into a working agent, see the agent that can buy things stack.
Directory entries in this comparison
- x402: Open standard for internet-native payments built on HTTP 402, letting APIs and agents pay per request across crypto and fiat networks.
- x402 Bazaar: Public catalog of x402 payment-gated services discovered by the CDP Facilitator; search by intent, browse resources or look up by merchant address.
- Machine Payments Protocol (MPP): Open standard for machine-to-machine payments over HTTP 402, co-developed by Tempo and Stripe; charge per API request, tool call or content.
- L402 (Lightning HTTP 402): Lightning Labs standard for paying for and authenticating to APIs with Bitcoin Lightning payments; Aperture is the reference reverse proxy.
- Agentic Commerce Protocol (ACP): Open standard from OpenAI and Stripe for programmatic checkout flows between buyers, their AI agents and businesses.
- Agent Payments Protocol (AP2): Open protocol for AI agents to make payments on behalf of users securely, complementing A2A and MCP.
- Universal Commerce Protocol (UCP): Open standard giving platforms (AI agents, apps), businesses, payment service providers and credential providers a common language for commerce.
- Coinbase CDP x402 Facilitator: Coinbase Developer Platform's x402 offering: a hosted facilitator that verifies and settles x402 payments, plus seller and buyer SDK quickstarts.
- Stripe Agentic Commerce: Stripe integrations for selling through agents and embedding commerce in AI interfaces, including Shared Payment Tokens for agent-initiated purchases.
- Stripe Issuing for Agents: Issue cards and credentials that agents can use to purchase autonomously, with spend controls, real-time authorization decisioning and full visibility.
- Visa Intelligent Commerce: Visa's portfolio for agentic commerce, embedding payment credentials, controls, authentication and protections into AI-initiated purchases.
- Mastercard Agent Suite for Merchants: Mastercard developer product to bring agentic commerce to merchants through a single integration.
- Coinbase Agentic Wallet: Wallet tooling that lets AI agents hold, spend, trade and earn stablecoins with guardrails, via the awal CLI + skills or an MCP server.
Related
- Pay for an API as an agent with x402 (Guide)
- Pay with x402 (Skill)
- Agent that can buy things (Stack)
Sources
- x402 Protocol Specification v2, accessed
- x402 HTTP transport v2, accessed
- x402.org, accessed
- MPP, What is MPP?, accessed
- MPP, Governance, accessed
- MPP, HTTP 402, accessed
- MPP, Payment methods, accessed
- IETF draft, The Payment HTTP Authentication Scheme, accessed
- Lightning Labs docs, L402, accessed
- lightninglabs/aperture, accessed
- Agentic Commerce Protocol repository, accessed
- agenticcommerce.dev, accessed
- Universal Commerce Protocol repository, accessed
- ucp.dev documentation index, accessed
- AP2 documentation, accessed
- AP2 repository, accessed