Agent that can buy things
The pieces for an agent that pays for APIs per call with x402 stablecoins and buys from merchants with controlled virtual cards, with spend limits, proof of user intent and a full audit trail.
Use case
Let an agent pay for metered APIs and tools on its own and complete merchant purchases for a user, within budgets you set and with a record of who authorized what.
Components
| Role | Component | Why |
|---|---|---|
| Agent harness | Claude Agent SDK | Runs the agent loop with tools, skills and MCP in your own app, so payment tools sit behind code you control rather than prompts. Any harness with tool calling works. |
| Machine payment protocol | x402 | Pay per request for HTTP APIs and MCP tools: the server answers 402 with a price, the agent signs a stablecoin payment and retries. SDKs default to USD stablecoins and a $1 cap per payment. |
| Agent wallet | Coinbase Agentic Wallet | A wallet built for agents, as the awal CLI with skills or as an MCP server (npx @coinbase/payments-mcp), that pays x402 services with guardrails such as a per-call maximum amount. |
| Settlement currency | USDC | The stablecoin most x402 services price in. Fund the agent's wallet with only what it may spend, and test on Base Sepolia with faucet USDC first. |
| Service discovery | x402 Bazaar | A public index of x402-payable endpoints with prices and schemas, so the agent can find a paid API without a human signing up for keys. |
| Card credentials | Stripe Issuing for Agents | Single-use or per-agent virtual cards with spend limits, merchant-category controls and real-time authorization webhooks, usable for programmatic checkout (MPP, UCP, Shared Payment Tokens) or in a browser. |
| Merchant checkout protocol | Agentic Commerce Protocol (ACP) | OpenAI and Stripe's open checkout standard (beta); lets an agent complete a purchase through a merchant's agent-ready checkout with a delegated payment token. |
| Merchant checkout protocol (alternative) | Universal Commerce Protocol (UCP) | Capability-based commerce standard over REST, MCP or A2A, covering checkout, identity linking and orders, with support for AP2 mandates. |
| Proof of user intent | Agent Payments Protocol (AP2) | Signed Checkout and Payment Mandates record what the user authorized, either a specific purchase or constraints like a budget, giving merchants and you an audit trail. |
| Browser for non-agent checkouts | Browserbase | A hosted browser for merchants without an agent-checkout API, kept apart from your own machine and sessions. |
| Tracing | Langfuse | Records every tool call and payment decision so you can reconcile spend against what the agent did and why. |
Two ways an agent pays
Per call, in stablecoins. For APIs and MCP tools that charge per request, the agent holds a small USDC balance in an agent wallet and pays with x402: request, get 402 with a price, sign, retry. There are no accounts or API keys to create, and each payment is capped. The x402 guide walks through it, and the pay-with-x402 skill teaches a coding agent to do it safely.
At a merchant, by card. For physical goods, subscriptions and anything sold through a normal checkout, the agent uses a card you control: a single-use or per-agent virtual card from Stripe Issuing for agents. Where the merchant supports an agent-checkout protocol (ACP or UCP), the card travels as a delegated token and the agent never sees the number. Where it doesn't, the agent fills in the checkout in a hosted browser (Browserbase).
The agent payment protocols comparison explains how these protocols relate, including MPP, which can serve both stablecoin and card payments on one endpoint.
Guardrails to set before the first purchase
- Separate money. Give the agent its own wallet and its own cards. Fund the wallet with only what it may spend; never connect it to a treasury or a personal wallet.
- Caps at every layer. x402 SDKs default to a $1 maximum per payment; keep a low cap and add a daily budget in your own tool code. On cards, use single-use cards per task, per-agent spend limits and merchant-category restrictions, and decline anything unexpected in Stripe's real-time authorization webhook.
- Human approval above a threshold. Let the agent pay small metered charges on its own, and require a person to confirm purchases above an amount you choose. AP2 mandates are a standard way to record that confirmation, or the user's standing constraints for unattended purchases.
- Treat inputs as hostile. Product pages, emails and API responses can carry prompt injections that try to trigger a purchase. Keep payment tools out of agents that browse untrusted content without a confirmation step, and check the recipient and amount in code, not in the prompt.
- Test first. Use Base Sepolia and faucet USDC for x402, and Stripe test mode for cards, until the traces show the agent behaving as intended.
- Reconcile. Trace every payment tool call with Langfuse and match it against wallet transactions and card authorizations.
Directory entries in this stack
- Claude Agent SDK: Anthropic's SDK for building production agents with Claude Code as a library, in Python and TypeScript.
- x402: Open standard for internet-native payments built on HTTP 402, letting APIs and agents pay per request across crypto and fiat networks.
- Coinbase Agentic Wallet: Wallet tooling that lets AI agents hold, spend, trade and earn stablecoins with guardrails, via the awal CLI + skills or an MCP server.
- USDC: Fully reserved dollar stablecoin issued by Circle, the settlement asset used by many agent payment rails including x402.
- x402 Bazaar: Public catalog of x402 payment-gated services discovered by the CDP Facilitator; search by intent, browse resources or look up by merchant address.
- Coinbase CDP x402 Facilitator: Coinbase Developer Platform's x402 offering: a hosted facilitator that verifies and settles x402 payments, plus seller and buyer SDK quickstarts.
- Stripe Issuing for Agents: Issue cards and credentials that agents can use to purchase autonomously, with spend controls, real-time authorization decisioning and full visibility.
- Agentic Commerce Protocol (ACP): Open standard from OpenAI and Stripe for programmatic checkout flows between buyers, their AI agents and businesses.
- Universal Commerce Protocol (UCP): Open standard giving platforms (AI agents, apps), businesses, payment service providers and credential providers a common language for commerce.
- Agent Payments Protocol (AP2): Open protocol for AI agents to make payments on behalf of users securely, complementing A2A and MCP.
- Stripe Agentic Commerce: Stripe integrations for selling through agents and embedding commerce in AI interfaces, including Shared Payment Tokens for agent-initiated purchases.
- Machine Payments Protocol (MPP): Open standard for machine-to-machine payments over HTTP 402, co-developed by Tempo and Stripe; charge per API request, tool call or content.
- Browserbase: Hosted headless-browser infrastructure that gives agents access to the whole web.
- Langfuse: Open-source agent evals and observability platform: trace, evaluate and improve LLM applications and agents.
Related
- Pay for an API as an agent with x402 (Guide)
- Pay with x402 (Skill)
- Agent payment protocols compared (Comparison)
- Run agent-generated code safely in a sandbox (Guide)
Sources
- x402 Protocol Specification v2, accessed
- x402 docs, Quickstart for Buyers, accessed
- Coinbase CDP, Agentic Wallet overview, accessed
- x402 docs, Bazaar (Discovery Layer), accessed
- Stripe docs, Issuing for agents, accessed
- Agentic Commerce Protocol repository, accessed
- Universal Commerce Protocol repository, accessed
- AP2 documentation, accessed