In a single week in September 2026, agentic commerce went from “watch this space” to “this is shipping”. On 9 September, Ant International, Visa and Mastercard announced a joint Know Your Agent interoperability framework. Days earlier, Cloudflare began reserving cloudflare.pay handles for a wallet fusing persistent agent identity with capped stablecoin spending.
Mastercard’s Agent Pay, Visa’s Trusted Agent Protocol, Stripe’s Machine Payments Protocol and Coinbase’s x402 are live or imminent, yet no regulator or network has codified who eats the loss when an autonomous purchase goes wrong. It starts with why conventional card rails strain.
This is a decision map: five sections, each routing you to the detail.
In this series
- What Agentic Commerce Means for Traditional Payment Rails: the definition and why cards break when software pays.
- x402, Machine Payments Protocol and the Card Versus Stablecoin Debate: how machine rails settle and which fits where.
- Know Your Agent, Competing Identity Standards and the Liability Vacuum: identity, trust, and who owns the loss.
- Agent Wallets, Scoped Credentials and the Build or Buy Decision: the control layer, budgets and scopes.
- Agentic Payment Adoption, Readiness and the Trust Versus Demand Question: what’s live, what’s hype, and trust versus demand.
What is agentic commerce, and why do conventional card rails strain?
Agentic commerce is software, an AI agent, researching, deciding on and completing purchases within limits you set, with no human at the checkout. It strains card rails because cards assume human authorisation, batch settlement and human-speed disputes, while machine traffic needs programmatic authorisation, per-request granularity and no minimum ticket. Sub-dollar payments collide with interchange and chargeback machinery, which is why stablecoin rails and metered pricing are emerging.
It is delegated spending: you set the limits, and the agent discovers, decides and pays, so intent and authorisation happen before any human sees a UI. The macro side, an agent booking a flight for a person, sits on today’s rails; the micro side, sub-dollar software-to-software payments, is where the economics break.
It is early, but the appetite is real: Nuvei puts agentic purchases at 1.5% of US spend, while Stripe’s Australian data shows 62% open to agents helping with purchases. See the shift from human to machine checkout; how those sub-dollar payments settle is next.
How do x402 and the machine payment rails actually settle a payment?
The machine rails settle payments inline. x402 revives the dormant HTTP 402 “Payment Required” code: a server requests payment, the agent pays, and the resource is delivered in one request, typically over stablecoins like USDC. Stripe’s Machine Payments Protocol standardises the same idea across payment methods. Your evaluation turns on settlement substrate, where identity attaches, and how disputes are handled — not on which vendor ships first.
x402 is a pay-per-request handshake: the server states what it accepts, the client attaches a signed payload, and the server settles before returning the resource. HTTP 402 sat dormant since 1997 because nobody could settle inline cheaply. With tickets around US$0.20, x402 settles in stablecoins, mostly observable on Base, Solana and Polygon.
Stripe’s Machine Payments Protocol is the counterpart: payment-method-agnostic, happy with cards and stablecoins, with identity and intent handled differently. A wallet decides authority; a rail decides how a payment is priced and settled. See how x402 actually settles a payment.
How are agents identified, verified and held accountable?
Agent identity is converging on a Know Your Agent (KYA) model, the machine-era counterpart to KYC, but the standards still compete. Visa’s Trusted Agent Protocol, Mastercard’s Agent Pay and Ant’s Agentic Mobile Protocol each verify identity and consent differently. None yet settles the harder question: who absorbs the loss when an agent pays wrongly. Capability has outrun accountability, so price identity and liability into adoption risk.
The liability vacuum is the core problem. No network rule, chargeback reason code or regulator has assigned responsibility for a non-fraudulent agent error, and chargeback machinery cannot parse agent intent. The UK’s Financial Services AI Adoption Plan names liability, consent and fraud as material adoption barriers, which the wallet controls in the next section contain. Who is accountable when an agent pays wrongly is the question to sit with.
How does an agent wallet control identity, budget and spending?
An agent wallet is where the control layer lives: persistent agent identity, an attached budget, and enforceable controls like caps, allow lists, and scoped credentials such as a Shared Payment Token that keep raw card details out of the agent’s hands. When you evaluate a wallet, ask how tightly you can scope each spend and whether the credential is revocable.
Break it into identity, budget and controls. A Shared Payment Token is scoped by amount, currency and merchant, so the agent buys without ever seeing raw card details. Cloudflare’s cloudflare.pay is a clear example: identity fused with capped stablecoin spending. Stripe Issuing for agents is a card-issuing program you build on; Link’s wallet for agents is a ready-made wallet.
Build-versus-buy turns on time-to-market, control, compliance and liability exposure. Hold any provider to scoping, caps and revocation; the wallet sits apart from the rail it settles on. The agent wallet control layer is where your evaluation time goes.
Is agentic commerce real, ready and trusted — or still hype?
The primitives are genuinely live or imminent: x402, Stripe’s Machine Payments Protocol, Mastercard Agent Pay, Visa’s Trusted Agent Protocol and Cloudflare’s cloudflare.pay settle today, while the identity and liability layers sit just behind. Yet the evidence is still contested, and the binding constraint looks like trust, not demand, so watch tester-to-payer conversion and wallet retention rather than raw transaction counts.
TRM Labs found roughly half of the US$52.7 million in measured x402 settlement disappears once self-payments and bulk flows are stripped out. Bernstein puts agentic commerce below 1% of e-commerce today, clearing US$0.5 to 1 million a month, and Visa’s consumer survey found just 23% trust agents to pay. Whether trust or demand is the real constraint decides your timing.
Resource hub
Understand the shift
- What Agentic Commerce Means for Traditional Payment Rails: the macro-versus-micro split and why cards strain.
- x402, Machine Payments Protocol and the Card Versus Stablecoin Debate: how machine rails move a payment and which fits where.
The control layer and risk
- Know Your Agent, Competing Identity Standards and the Liability Vacuum: how agents are identified, and why nobody owns the loss.
- Agent Wallets, Scoped Credentials and the Build or Buy Decision: how a wallet holds identity, budget and controls.
Adoption, readiness and trust
- Agentic Payment Adoption, Readiness and the Trust Versus Demand Question: what is live, how to spot hype, and trust versus demand.
Where to start
Understand the shift: begin with what agentic commerce actually is, then move to the rails.
Compare the rails and the control layer: go to which machine payment rail fits which use case, then the build-or-buy decision for agent wallets.
Judge the trust and adoption question: start with the liability vacuum behind agent identity, then the trust-versus-demand question.
The rails are ready. The trust layer is not. Work out which one blocks your roadmap before you build.
Frequently Asked Questions
Is an AI agent wallet the same thing as a crypto wallet?
No. An AI agent wallet is a control layer that holds persistent agent identity, a budget and enforceable spending rules; it is not primarily a place to store crypto. Many agent wallets do settle over stablecoins, as Cloudflare’s cloudflare.pay does above Coinbase’s x402 rail, but the wallet and the rail are separate. Judge a wallet on how tightly it scopes and revokes each spend, not on its token holdings.
Is agentic commerce just using a chatbot to shop?
No. A chatbot helps you browse; agentic commerce is delegated spending, where software researches, decides and completes a purchase within limits you set, with no human at the checkout. Intent and authorisation happen before any UI appears. The macro version sits on today’s card rails, but the micro version, sub-dollar software-to-software payments, is where the economics change.
Do you need cryptocurrency to make an agentic payment?
Not always, but it helps at the micro end. Stablecoin rails like x402 settle sub-dollar payments in USDC because card rails carry a fixed-fee minimum ticket that destroys the economics. Stripe’s Machine Payments Protocol is deliberately payment-method-agnostic, so card and stablecoin can coexist. The deciding factor is settlement substrate, not ideology.
How do I stop an AI agent from overspending?
Caps, allow lists and scoped credentials. A well-designed agent wallet lets you set a ceiling per transaction and per period, restrict which merchants the agent can pay, and issue a credential scoped by amount and currency. Check that the credential is revocable, so you can shut the agent down mid-flight rather than waiting for the next statement.
What is a Shared Payment Token, and why does it matter?
A Shared Payment Token is a scoped credential that lets an agent complete a purchase without ever seeing raw card details. Stripe’s version is scoped by amount, currency and merchant, so the token can only be spent where and how you intend. It matters because it keeps sensitive card data out of the agent’s hands while still enabling autonomous payment.
What happens if an agent wallet or its credentials are compromised?
Scope is your best defence. A Shared Payment Token capped by amount, currency and merchant can only be abused within those bounds, and revocation closes the exposure immediately. Short-lived credentials, per-transaction ceilings and merchant allow lists limit the blast radius far more than the wallet’s brand does. Treat every credential as revocable, and test that revocation actually works.
Can an AI agent pay another AI agent?
Yes, and it changes the risk profile. Machine-to-machine payments settle software-to-software over stablecoin rails like x402, often at sub-dollar amounts, with no human on either side. Because both endpoints are autonomous, scoping, identity and revocation matter more, not less, since a compromised agent can transact with another agent in milliseconds.
Can AI agents manage subscriptions and recurring payments?
Not well yet. Today’s machine rails are built for one-off, per-request settlement, which suits pay-per-call APIs and micro-transactions rather than standing subscriptions. Recurring billing needs persistent consent, mandate management and failed-payment recovery, none of which the current agent identity standards settle. For now, keep subscriptions on traditional mandate rails and use agent payments for variable, metered spend.
How much does a typical machine payment cost?
Tiny, and that is the point. An average x402 ticket runs around US$0.20, which is why it settles in USDC across Base, Solana and Polygon rather than on cards. At that size, a fixed card fee plus a minimum ticket wipes out the margin. Metered, per-request pricing only works when settlement is cheap enough to clear sub-dollar amounts.
Is it true that AI agents will replace credit cards?
No, not for macro purchases. An agent booking a flight for a person still sits comfortably on today’s card rails, where authorised, dispute-backed payments are an advantage. The shift is at the micro end, sub-dollar software-to-software payments, where stablecoin rails and metered pricing win. Expect coexistence and routing, not replacement.
What is the difference between an agent wallet and a payment rail?
An agent wallet is the control layer; a payment rail is the settlement layer. The wallet holds identity, budget and scopes, and decides what the agent may spend. The rail moves the money, whether that is a card network or a stablecoin network like x402. Cloudflare’s cloudflare.pay is a wallet sitting above Coinbase’s x402 rail, which shows the two are separate.
Are AI agents allowed to spend without human approval?
Yes, within the limits you set, and that is the point of delegated spending. You authorise the bounds in advance, covering budget, merchants and scope, and the agent then acts inside them without a checkout prompt. Human approval moves from the point of sale to the policy you set, which is why scoping and revocation carry so much weight.