Payments used to require a human. That’s changing. Agent-based payment transactions involve an AI agent acting as the buyer. People are the decision-makers or authorities, and agents are the implementers.
In traditional e-commerce, every payment has a human at the center. A person searches for a product, adds it to a cart, enters their card details, and clicks Buy. The payment happens because a human decided to make it happen.
On the other hand, agentic payments are different. The AI agent makes the payment. No human click. No card entry. No manual approval at the moment of purchase.
And this isn’t a futuristic concept anymore. Amazon’s Rufus AI handles hundreds of millions of shopping interactions. ChatGPT processes 50 million shopping queries every day. Amazon launched Shop Direct – a feature that lets AI agents discover and surface products from across the web, directly in the Amazon Shopping app. These are live products, running right now.
But agentic payments raise real questions. How does the AI know what it’s allowed to buy? How does it pay without exposing card details? How does the merchant know the transaction is legitimate and secure, not a bot attack? What happens when something goes wrong?
These questions are arising among e-commerce owners. And I am writing this blog to answer all of that. We’ll explain what agentic payments are, how the payment infrastructure works, what security frameworks are in place, and what merchants and payment teams should be building for right now.
What Are Agentic Payments?
Agentic payments are financial transactions that are initiated, approved, and executed by AI agents without the need for human approval at any stage.
A traditional payment requires human action at every stage. However, an agentic payment doesn’t. The agent operates within a predefined set of rules and spending boundaries. When those conditions are met, the agent executes the transaction itself.
And don’t confuse it with automated payments, like a recurring subscription charge on the first of the month. Because a subscription follows a fixed schedule. But an agentic payment involves real-time decision-making. The AI agent, a shopper uses evaluates the current situation, determines that a payment should be made, and executes it. And, behind the scenes, AI follows some pre-defined logic, not a calendar.
Here are some examples of agentic payments:
- A shopper tells an AI: “Buy me running shoes if the price drops below $100.” The agent monitors prices and buys automatically when the condition is met.
- A business tells an agent: “Reorder our weekly office supplies when stock drops below threshold.” The agent monitors inventory and places the order autonomously.
- An enterprise agent validates a vendor against an approved list and issues a purchase order, with no human in the loop.
The common thread: a human sets the goal and the guardrails. The AI executes within them.
How Agentic Payments Ecosystem Works
Agentic payments involve four parties and two separate protocols.
Understanding how the pieces fit together helps clarify why agentic payments are more secure than they might initially sound.
Here are the four parties in the Agentic Payment System

1. The Buyer (Human User): Sets the intent, defines spending limits, and approves the authorization upfront. They’re not present at the moment of purchase, but they defined everything the agent is allowed to do.
2. The Agent (AI Platform): Interprets the buyer’s intent, evaluates product options, manages the checkout session, and requests payment authorization. ChatGPT, Gemini, and Microsoft Copilot are examples.
3. The Seller (Merchant): Calculates prices, taxes, shipping, and inventory. Receives the payment token. Creates the order. Remains the Merchant of Record throughout.
4. The Payment Service Provider (PSP): Tokenizes the buyer’s payment credentials under strict spending constraints and processes the final charge. Stripe, Adyen, and Google Pay are examples.
Here are two protocols AI needs to follow for Agentic payments:
Two open specifications govern how agentic payments are authorized and executed:
Agentic Checkout API (Agent ↔ Seller): Manages the stateful checkout session. Handles cart creation, tax and shipping calculations, real-time updates, and order confirmation. This is the communication layer between the AI agent and the merchant’s backend.
Delegate Payment API (Agent ↔ PSP): Allows the agent to tokenize the buyer’s saved payment credentials while enforcing spending constraints. This is how the agent gets permission to pay – without ever seeing raw card details.
In short, the agent never handles raw payment credentials. It only ever receives a time-limited, amount-limited, merchant-scoped token. This is the core security design of agentic payments
Shared Payment Tokens: How the Money Actually Moves
Instead of passing card numbers, agentic payments use Shared Payment Tokens which is a cryptographically constrained proxies.
This is the most important concept to understand. It’s what makes agentic payments secure enough to work without a human present.
When a buyer authorizes a purchase through an AI agent, the Payment Service Provider creates a Shared Payment Token (SPT). This token is not a card number. It’s a cryptographic proxy that carries three hard constraints to make a secure payment system:
1. Seller-scoped
The token is bound to a specific merchant’s identifier. If any other merchant tries to use it, the transaction fails. The agent can’t accidentally or maliciously use it at a different store.
2. Amount-scoped
The token has a maximum charge limit. If the merchant tries to charge even one cent more than that limit, Stripe (or the relevant PSP) rejects it automatically. There’s no way to override the predefined amount. The limit is enforced at the infrastructure level.
3. Time-scoped
Every token has an expiration timestamp. Once it expires, the token becomes cryptographically inactive. Plus, it cannot be reused, extended, or recycled.
On the merchant’s side, accepting an agentic payment is simple. Developers swap one parameter in their existing payment code – replacing the traditional payment method ID with the SPT token ID. The rest of their payment infrastructure stays exactly the same.
The good news is that, if a merchant is already on Stripe, then they can accept agentic payments by changing a single line of code. Here, the merchant needs to pass the SPT token ID into your standard PaymentIntent instead of a traditional payment method. Further, everything else, like tax, fulfillment, refunds, and disputes, works exactly as it always has.
Security: Why Agentic Payments Aren’t as Risky as They Sound
The biggest concern people have about agentic payments is security. Here’s why the infrastructure addresses that. And, it’s evolving and improving every day, as large shareholders of agentic payments are actively working on security measures.
Let’s learn about some important things that create a strong and secure foundation for ‘agentic payments’.
Digital mandates: the cryptographic record of consent
Before an AI agent can make a purchase, the buyer must create a digital mandate. This is a cryptographically signed, tamper-proof record that defines exactly what the agent is allowed to do.
The mandate is written in plain English. Both the buyer and the merchant can read it. It specifies:
- Which merchants the agent can buy from
- The maximum spending limit per transaction
- Which product categories are authorized
- The time window during which the authorization is valid
The mandate cannot be changed after it’s created. There’s no loophole. No retroactive modification. If the agent tries to exceed those boundaries, the payment infrastructure blocks it.
The fraud detection problem and how it’s being solved
Traditional fraud systems look for human behavioral signals: mouse movement patterns, typing speed, browsing history. AI agents don’t have those signals. They click fast. They operate at unusual hours. They behave nothing like a human shopper.
This means legacy fraud systems often flag legitimate agent transactions as bot attacks. It’s a real commercial problem.
The solution is to shift fraud detection from behavioral signals to payment-level signals. When an AI agent provisions a payment token, it passes a set of risk signals alongside it:
- Buyer IP address
- User-agent string
- Device fingerprint
- Session identifiers
- Card-testing risk scores
Stripe Radar, for example, uses these signals to assess the fraud risk, not behavioral patterns. It can distinguish between a legitimate AI agent acting on behalf of a real buyer and a malicious bot trying to test stolen card numbers.
The three principles of trustworthy agentic payments
Whether you are a merchant, PSP, or platform, any agentic payment system should be built around three design features:
Informative: The agent must report what financial actions it’s taking and what the payment gateway returned. Not silently. Actively.
Queryable: Human operators must be able to ask why a specific transaction was made and inspect the underlying data. Every decision should be explainable.
Interruptible: Humans must be able to pause or override an agent’s payment execution at any point. The kill switch must be real and accessible.
“In payments, eventually something always goes wrong. The question is whether you’ve built the infrastructure to catch it before it escalates.”— Soha Hohnecker, Global Leader for Amazon Agentic Payments, AWS re:Invent 2025
Agentic Payment Use Cases
Let’s see some real-world examples where agentic payments are already working. And most importantly, where they’re heading.
🛒 Consumer Shopping (Bounded Purchases)
The most common live use case today. A shopper sets parameters like “buy running shoes under $150 from this brand,” and the agent executes when those conditions are met. Amazon’s Shop Direct, ChatGPT’s product recommendations, and Google’s Universal Cart are all live examples of this in practice. This works best for low-cost, well-defined purchases where the buyer’s preferences are clear.
🔄 Automated Reordering and Subscription Management
Agents monitor usage or consumption and place reorders automatically. Weekly groceries, office supplies, and recurring product restocks are natural fits. The agent knows the shopper’s preferences, checks real-time pricing and inventory, and executes the order. This is one of the highest-ROI use cases for consumers and merchants alike.
⏰ Time-Sensitive and Conditional Purchases
The best examples of these categories are events like price-drop triggers, limited-edition releases, and ticket sales. The agent monitors conditions and executes the moment they’re met. And the best thing is that this way is faster than any human could react. Conditional purchasing (“buy only if the price drops below X”) is powered by digital mandates that define the criteria precisely.
🏢 B2B Procurement and Supply Chain
Organizations and enterprise who are using AI agents to automate supplier verification, issue purchase orders with the correct payment terms (like net 30, net 60), automatically apply tax deductions, and find alternative suppliers during times of crisis.
This removes days from procurement cycles while maintaining full auditability. ACP’s enterprise extensions include native support for PO numbers, cost center allocation, and company tax IDs.
💼 Agent-to-Agent Commerce
This type of use case involves multi-agent workflows where one AI pays another for a service, data query, or compute resource. These microtransactions happen at high frequency and need instant settlement. Stablecoins are emerging as the preferred settlement layer here. They settle in seconds, work across borders, and support programmable payment logic that agents can reason about natively.
📦 Post-Purchase Lifecycle Management
Agentic payments don’t stop at checkout. Merchants send order lifecycle events (shipped, delivered, delayed, refunded) to the AI platform via signed webhooks. The agent stays synchronized with real-time fulfillment data. When the buyer asks ‘where is my order? the agent can answer appropriately. WISMO (Where Is My Order) queries can be handled entirely in the original purchase conversation, without the buyer contacting customer support.
Challenges of Merchants in Agentic Payments
Agentic payments are live. The infrastructure is real. But there are genuine challenges the industry is still working through.
At AWS re:Invent 2025, Soha Hohnecker – Amazon’s Global Leader for Agentic Payments — was refreshingly direct about where the gaps are. Below, I have discussed on what she said, and why it matters for merchants.
1. Traditional fraud models flag agent transactions
Agents click quickly, operate at unusual hours, and show none of the hesitation patterns human shoppers have. Legacy fraud systems misread this as malicious behavior.
The possible fix here is to shift from behavioral fraud signals to payment-level risk signals (device fingerprint, IP, card-testing scores). This requires updating fraud models at the industry level. A merchant simply can’t solve this by just adding a new payment method.
2. Authentication flows block agents
CAPTCHA, SMS one-time passwords, 3D Secure pop-ups – all of these are designed for humans with phones in their hands. They interrupt agentic flows completely.
The solution is capability negotiation: the agent and merchant agree upfront what authentication methods are supported. If the merchant requires 3DS but the agent can’t render it, the session provides a fallback URL so the buyer can complete authentication in a browser. It’s not elegant yet, but it’s functional.
3. Cross-merchant agent shopping doesn’t have a common standard yet
Today, if a consumer wants an AI agent to compare prices and buy from whichever retailer is cheapest, the agent needs separate authorizations from each merchant. However, there isn’t any universal cross-merchant authorization framework yet.
This is an industry-wide gap, not a specific merchant’s problem. UCP (Universal Commerce Protocol) is working toward this, but it’s still being built.
4. Settlement and reconciliation weren’t built for machines
Current systems produce PDF receipts for humans to read. Agents need structured data they can parse. The order event format, the webhook payload, the refund record- all of this needs to be machine-readable. Most existing infrastructure wasn’t built that way.
5. Disputes and chargebacks have no standard framework
When a human disputes a purchase, the process is clear. When an AI agent makes a purchase that the buyer later disputes – who’s responsible? The buyer who set the mandate? The agent that executed it? The merchant that fulfilled it?
AP2’s digital mandates provide the audit trail. But industry-wide standards for dispute resolution in agentic commerce are still being developed.
“The merchants who are winning are the ones who treat trust as a product. It’s not a feature. It’s a product. The technology is moving fast. The standards will catch up. But the trust infrastructure — the customer relationships, the networks — those take years to build.”— Soha Hohnecker, Amazon Agentic Payments, AWS re:Invent 2025
Merchants Best Practices for Agentic Payments Compliance
The merchants who are building the foundation now are the ones who will capture the value when agent-driven volume scales.
Soha Hohnecker’s advice at re:Invent was direct: don’t get ahead of yourself with sophisticated use cases. Build the foundation first.
Below are the steps that merchants should consider and follow to benefit from the ongoing development of ‘agentic payments’.
1. Expose structured product data via APIs
Agents need to query your catalog programmatically. Not via screen scraping. Not via your HTML product pages. This has to be processed via clean, structured APIs that return accurate pricing, inventory status, specifications, and shipping options in real time.
Most existing merchant systems were not built this way. Therefore, fixing it is the most important preparation step and also the most work.
2. Remove friction from payment flows
CAPTCHA and 3D Secure pop-ups that interrupt the agent flow are conversion killers. Start with simple, low-value, low-risk transaction types. Learn what works. Remove friction iteratively.
Don’t open up high-value transactions to agents on day one. Amazon’s Soha Hohnecker was explicit: the infrastructure for high-value agentic purchases isn’t fully there yet. Start small.
3. Start with contained, low-risk use cases
Subscription optimization. Reorder automation. Basket building for repeat customers. These are predictable, low-friction, high-value use cases that don’t require solving the hard problems first.
Don’t try to solve cross-merchant agent shopping on day one. Pick one use case. Deploy it. Learn from it. Expand.
4. Implement webhook infrastructure for post-purchase sync
If you support agentic checkout through ACP, you need to send order lifecycle events to the AI platform via signed webhooks. This is what keeps the agent synchronized with your fulfillment system.
Every event (order created, shipped, delivered, refunded) must be sent as a full-snapshot payload – not incremental updates. The AI platform needs the complete, current state of the order on every event.
5. Treat trust as a product, not a feature
This was Amazon’s single most important piece of advice. The early experiences shoppers have with agentic payments will determine whether they trust this model going forward. A bad experience such as the wrong product, the wrong price, and something that can’t be returned can break trust in a way that’s hard to recover from.
Build the accountability structures. Maintain the audit trail. Make your dispute and return processes work cleanly for agent-initiated transactions. The merchants who build trust early will hold it.
Frequently Asked Questions
What are agentic payments?
How are agentic payments different from automated payments?
What is a Shared Payment Token (SPT)?
Are agentic payments secure?
What is the Agent Payments Protocol (AP2)?
What are Shared Payment Tokens used for in agentic commerce?
How does post-purchase work in agentic commerce?
What use cases should merchants start with for agentic payments?
Do merchants need to rebuild their payment infrastructure for agentic commerce?
What’s the biggest challenge with agentic payments right now?
Wrap Up!
Agentic payments are not coming. They’re already here.
Amazon, OpenAI, Google, Stripe, and Visa are all building the infrastructure right now. Rufus is live. ChatGPT shopping is live. Shop Direct is live. Shopify merchants are already receiving AI-attributed orders at 15x the volume of a year ago.
The question for merchants and payment teams is not whether to engage with agentic payments. It’s when and in what order.
The answer from the people building this at Amazon and AWS is consistent: start with the foundation. Get your product data structured and API-accessible. Run clean, simple payment flows for low-risk transaction types. Build the post-purchase webhook infrastructure. Start small, learn fast, and expand from a position of trust.
Agentic payments shift the human’s role from operator to authorizer. The buyer still makes the decision. Actually, they just make it at the beginning, not the end. That’s a small change in the buyer’s experience. It’s a large change in your payment infrastructure requirements.
The merchants who build that infrastructure now will be ready when agentic payment volume reaches the scale that traditional web checkout commands today. That transition is already underway.

Leave a Reply