Agentic Commerce Protocols Explained: ACP, UCP, AP2 and Agent Payments
A business guide to the agentic commerce protocol stack in 2026: what OpenAI's ACP and Google's UCP do, where agent payments fit, who backs each, and what your catalog must provide.
By Alberto Barberis, Founder and CEO, AndromedAI · Updated October 2026
The short answer
Agentic commerce protocols are open standards that let an AI agent find a merchant's products, open a checkout, pay, and follow the order through one shared integration instead of a custom build per agent. The main ones are OpenAI and Stripe's Agentic Commerce Protocol (ACP), Google's Universal Commerce Protocol (UCP), and the Agent Payments Protocol (AP2). All of them run on structured, complete product data.
Agentic commerce protocols in 30 seconds
An agentic commerce protocol is a shared set of rules that lets an AI agent read your catalog, build a cart, pay and track the order without a custom integration for every agent. In 2026, ACP and UCP handle the shopping; AP2 and the card networks' agent programs handle the money.
- 01
ACP (Agentic Commerce Protocol) is the open standard from OpenAI and Stripe behind ChatGPT shopping. Since March 2026 it carries product feeds for discovery too.
- 02
UCP (Universal Commerce Protocol) is Google's counterpart, co-developed with retailers and platforms including Shopify and Walmart. It powers checkout in AI Mode and Gemini.
- 03
Agent payment programs (AP2 plus the card network and wallet schemes) answer a narrower question: did a trusted agent pay with the shopper's permission.
- 04
Every protocol starts from the same input, a structured product catalog. If an agent can't match your product to the request, nothing downstream gets called.
- 05
Most merchants won't build protocol endpoints. Their platform or payment provider exposes them (Shopify, Stripe, PayPal, Salesforce, Merchant Center). Your job is the product data.
Why AI agents need commerce protocols
A website checkout assumes a person clicking buttons. An agent needs machine-readable answers to four questions: what's for sale, what this cart costs, how to pay safely, and what happened to the order. Protocols standardize those answers so one integration works across many agents.
US B2C retail revenue that AI agents could orchestrate by 2030; $3T to $5T globally
Every platform wants to own these railsSource: McKinseyyear-on-year rise in AI-driven traffic to US retail websites (Adobe data, 2025)
Agent shoppers already reach your storeSource: Digital Transactions citing Adobethe time Stripe says a custom agentic integration can take for each new AI agent
That per-agent cost is the reason protocols existSource: Stripecompanies that endorsed UCP at launch, including Visa, Mastercard, Stripe, Adyen, Best Buy and Zalando
Google didn't launch this aloneSource: Googleorganizations Google worked with on AP2, including Mastercard, PayPal, American Express and Adyen
An industry-wide projectSource: Google Cloudrequired fields in OpenAI's product feed spec, from `item_id` to `price`
The entry ticket is product dataSource: OpenAIThe four layers of an agent purchase
A shopper asks Gemini for "a waterproof trail running shoe for wide feet, under $150".
Look at what the agent cited. Width, membrane, lugs, price, stock, each from a field somebody filled in. Four layers have to work before money changes hands, and most products drop out at the first.
Discovery
A structured view of products with live prices and stock. ACP feeds, Merchant Center feeds and UCP catalog search.
Checkout
A session with real tax and shipping that the agent confirms before committing. ACP's Checkout API and UCP checkout.
Payment
Paying without raw card numbers, inside the shopper's limits. Shared Payment Tokens, AP2 mandates or network agent tokens.
Trust and post-purchase
Verifying the agent, then order updates such as tracking or refunds. Visa's Trusted Agent Protocol plus order webhooks.
McKinsey lands in the same place: make catalogs agent-readable, build well-documented APIs and avoid depending on a single AI platform.
Protocols move the bottleneck. Once checkout and payment are standardized, the deciding factor is whether an agent picks your product at all, and product data decides that. The wider picture is in the agentic commerce guide, and terms like mandate, agent token and merchant of record are defined in our agentic commerce glossary.
What is the Agentic Commerce Protocol (ACP)?
The Agentic Commerce Protocol (ACP) is an open standard, co-developed by OpenAI and Stripe and released on September 29, 2025, that defines how AI agents and merchants exchange product feeds, checkout sessions, payment credentials and order updates. It's Apache 2.0 licensed and powers shopping in ChatGPT.
Who backs ACP and how it evolved
OpenAI and Stripe are the founding maintainers. The spec lives on GitHub under Apache 2.0, uses date-based versions and is still labeled beta. It launched alongside Instant Checkout in ChatGPT, first for US Etsy sellers, with Shopify merchants such as Glossier, Vuori, Spanx and SKIMS announced next (Stripe). You don't need Stripe as your processor to adopt it.
The 2026-04-17 release added cart, feed, orders, authentication and MCP support (ACP repository).
Then the checkout story changed. On March 24, 2026, OpenAI said the first version of Instant Checkout "did not offer the level of flexibility" it wanted. Merchants can now use their own checkout experiences, and ACP was extended to power product discovery (OpenAI). Feeds and promotions go through ACP directly or via providers such as Salesforce and Stripe; Shopify merchants are covered by Shopify Catalog. OpenAI named Target, Sephora, Nordstrom, Lowe's, Best Buy, The Home Depot and Wayfair as retailers integrated for discovery.
That reversal is why we'd hold off on a hand-built ACP checkout unless you have a payments team. Discovery is the part that touches every merchant.
How ACP works, step by step
- 1
Product feed
You share a structured catalog. Required fields are
item_id,title,description,url,brand,seller_name,image_url,availabilityandprice. Flags such asis_eligible_searchandis_eligible_checkoutcontrol where each product can appear. - 2
Agentic checkout
You expose REST endpoints:
POST /checkout_sessionscreates a session,POST /checkout_sessions/{id}updates it,POST /checkout_sessions/{id}/completecompletes it, with optional cancel and retrieve. Every response returns the full cart state (taxes, shipping, discounts, totals). - 3
Delegated payment
The agent passes a scoped credential instead of a card number. Stripe's Shared Payment Token is limited to one merchant and one cart total, and you can still charge through your own payment provider.
- 4
Order updates
You publish lifecycle events such as
order.createdandorder.updatedto a webhook, so the agent can keep the shopper posted.
What do merchants need to support ACP?
Discovery needs a feed that meets OpenAI's feed spec. The rules we see broken most often in audits:
| Field | Rule in the OpenAI spec | What goes wrong in practice |
|---|---|---|
title | Aim for 150 characters or fewer | ERP names like "TRK-GTX-BLK-105" with no product type or key attribute |
description | Plain text, up to 5,000 characters | Shopify body_html exported raw, with HTML tags and inline styles left in |
gtin | 8, 12, 13 or 14 digits with a valid check digit | Excel strips the leading zero from UPCs, or every variant shares the parent's GTIN |
price | Amount plus currency, for example 79.99 USD | Sale ends on site, feed keeps the old price |
availability | in_stock, out_of_stock, pre_order, backorder or unknown | Feed runs nightly while stock changes hourly |
material | Optional, principal materials | Left empty, so a prompt like "merino base layer" never matches |
OpenAI's checkout spec requires signed, authenticated HTTPS requests (Authorization, Signature, Timestamp, Idempotency-Key) plus conformance checks covering schemas and error codes as well as webhooks. Don't skip the idempotency handling. Agents retry on timeouts, and a handler that ignores the key creates a second order. Products opted into checkout also need privacy policy and terms URLs.
Most merchants reach ACP through a platform: Shopify, Stripe's Agentic Commerce Suite, PayPal or Salesforce. The full playbook is in how to get your products recommended by ChatGPT.
Google Universal Commerce Protocol (UCP)
The Universal Commerce Protocol (UCP) is an open standard Google announced on January 11, 2026, covering everything from discovery to checkout and post-purchase support. It powers direct buying in AI Mode in Google Search and the Gemini app, and the merchant stays the seller of record.
Who backs UCP
Google co-developed UCP with Shopify, Etsy, Wayfair, Target and Walmart. More than 20 companies endorsed it at launch, among them Adyen, American Express, Best Buy, Flipkart, Macy's, Mastercard, Stripe, The Home Depot, Visa and Zalando (Google). The project site ucp.dev now lists Amazon, Microsoft, Meta, Salesforce and Stripe as shopping co-developers too.
What UCP covers
Catalog and cart
Product search and browsing, batch lookup, and multi-item carts that can be handed to the merchant site or checked out in place.
Checkout
Unified checkout sessions that handle pricing and tax, including complex cart logic. Native checkout is the default; an iframe-based embedded checkout exists for approved merchants with custom flows.
Identity and orders
OAuth 2.0 identity linking so agents act without sharing credentials, plus order management (confirmation, tracking, returns, refunds) via webhooks.
UCP offers REST and JSON-RPC transports with MCP bindings, and it's designed to work with AP2, A2A and MCP (Google for Developers). Shoppers pay with Google Pay using details saved in Google Wallet. PayPal support is announced as coming.
What does Google UCP require from merchants?
Google's implementation guide lists the native checkout steps. Prepare Merchant Center (shipping, returns, product feed), join the waitlist and wait for approval. Then publish a UCP profile with your public keys, secure your API endpoints, implement native checkout, integrate the Google Pay payment handler and push order updates. Identity linking and promo codes are optional extensions.
Inside Merchant Center, three feed attributes matter (Google for Developers):
native_commerce(checkout_eligibility): a boolean that opts a product into checkout. Missing means ineligible; teams often assume the reverse.consumer_notice: required for products with legal disclaimers, safety warnings or Prop 65 notices.merchant_item_id: maps the Merchant Center product to the ID your checkout API expects. Needed when the feed uses generated offer IDs (Shopify's Google channel prefixes them withshopify_US_) but orders use SKUs.
Google recommends a supplemental data source for them. Some products must stay ineligible: subscriptions, personalized items, used goods, final-sale items, pre-orders and age-restricted products. A return policy (cost, window, link) and a customer support contact are mandatory.
UCP sits on top of the feed you already have
UCP uses your existing Merchant Center shopping feed. Google also announced dozens of new Merchant Center attributes built for conversational surfaces, covering answers to common product questions as well as compatible accessories and substitutes (Google). So the title, description, product_type, color, size and material values that drive Shopping ads now decide AI Mode visibility as well.
With a clean Merchant Center account, UCP is the cheaper protocol to prepare for. The Google Merchant Center guide and Google AI Mode shopping cover how products get picked.
Agentic payments: AP2, Visa, Mastercard, PayPal and Stripe
Agentic payments are payments an AI agent initiates on a shopper's behalf, using tokenized credentials and signed proof of the shopper's intent instead of a raw card number. AP2 defines the proof. Visa and Mastercard supply agent tokens and verification; PayPal and Stripe bring wallets and merchant-side processing.
Payments get the most press and, for a typical merchant, the least work. Your PSP absorbs most of it.
Google frames the open questions as authorization, authenticity and accountability (Google Cloud). In plain terms, a merchant needs proof that the shopper approved, proof that the purchase matches what they asked for, and a clear answer on who is liable when something goes wrong.
Who launched what
| Program | Backer | What it does | Launched |
|---|---|---|---|
| AP2 (Agent Payments Protocol) | Google with 60+ partners | Signed mandates that link the shopper's intent, the approved cart and the payment into an audit trail; payment-agnostic (cards, bank transfers, stablecoins) | September 2025 |
| Shared Payment Token | Stripe | A scoped token limited to one merchant and an amount, valid for a set time window, used in ACP checkouts | September 2025 |
| Agent Pay | Mastercard | Agentic Tokens built on Mastercard tokenization; agents must be registered and verified before paying | April 2025 |
| Trusted Agent Protocol | Visa with Cloudflare | Cryptographic signatures that let merchants tell trusted agents from bots, part of Visa Intelligent Commerce | October 2025 |
| PayPal on ACP | PayPal | PayPal wallet in ChatGPT checkout, plus an ACP server that brings PayPal merchants' catalogs to ChatGPT | October 2025 |
How AP2 mandates work
AP2 uses two signed digital contracts. The Intent Mandate records what the shopper asked for and the limits they set, say "buy this jacket in green if it drops below $180". The Cart Mandate records the exact items and price that were approved, by the shopper or by the agent within those limits. Google calls the result a non-repudiable chain from intent to cart to payment (Google Cloud). AP2 extends the A2A protocol, works with MCP, and has an x402 extension for crypto payments built with Coinbase.
One practical catch: "in green" only resolves if the variant has a color value an agent can read. A swatch named "Moss" won't do it.
Card networks: tokens and agent identity
Mastercard Agent Pay extends card tokenization to agents. Partners include Microsoft and IBM, plus processors Braintree and Checkout.com. Visa's Trusted Agent Protocol is built on Cloudflare's Web Bot Auth. Mastercard and American Express use it too.
This is where merchants get burned. Bot rules built to stop scrapers will block a paying agent too. Check with whoever owns your CDN or WAF settings that signed agents get through.
PayPal and Stripe on the merchant side
PayPal adopted ACP in October 2025 and said that from 2026 its merchants' catalogs would reach ChatGPT through PayPal's ACP server. Stripe's Agentic Commerce Suite hosts an ACP endpoint for product data with price and availability and processes Shared Payment Tokens. In both cases you stay merchant of record.
ACP vs UCP: differences and which to support
ACP is the OpenAI and Stripe standard behind ChatGPT shopping. UCP is the Google-led standard behind checkout in AI Mode and Gemini. Same problem, different agent ecosystems. Most merchants will end up on both, usually through their commerce platform.
| ACP | UCP | What it means for you | |
|---|---|---|---|
| Led by | OpenAI and Stripe | Google, co-developed with Shopify, Etsy, Wayfair, Target, Walmart | Both are open standards with multi-company backing |
| First release | September 29, 2025 | January 11, 2026 | ACP has more release history; UCP launched with a broader co-developer list |
| Main surfaces | ChatGPT | AI Mode in Google Search, Gemini app | Go where your shoppers ask |
| Discovery input | ACP product feed (JSONL, CSV, TSV) or a provider such as Shopify Catalog, Stripe, PayPal, Salesforce | Existing Google Merchant Center feed plus checkout attributes | Feed quality decides visibility on both |
| Checkout | Merchant REST endpoints; since March 2026 merchants can also use their own checkout | Native checkout by default, embedded checkout for approved merchants | You remain seller of record in both |
| Payments | Delegated payment spec, Stripe Shared Payment Token, PayPal | Payment handlers, Google Pay, built to work with AP2 | Your PSP stays in place in both |
| Access | Feed and checkout through approved partners and providers | Waitlist and Google approval; checkout launched for US shoppers | Expect gated, phased rollouts |
Which agentic commerce protocol should merchants support?
Most "ACP vs UCP" articles frame this as a choice. For the typical brand it isn't. Your platform decides, and you inherit both. What you do own is the quality of the catalog both will carry.
Shopify merchants
Start with Shopify Catalog and agentic storefronts, which syndicate products to ChatGPT, Perplexity and Microsoft Copilot from the admin. Your work is the attributes and metafields, plus policies and FAQs. No endpoints.
Brands and retailers on Merchant Center
Put UCP first. Clean up the feed, add return policies and support contacts, then join the waitlist. Send an ACP version of the same catalog through your PSP or platform.
Enterprise retailers
Plan for both. Expose one well-documented checkout API, map it to ACP and UCP, and keep one source of product truth so the feeds never disagree.
With Shopify's agentic storefronts, you define a product schema with standard attributes and metafields. Then you add policies and toggle each AI channel on. The protocol work is done for you; the data work isn't. A trap we see repeatedly: attributes kept in custom metafields that nothing maps to the schema, so they never reach an agent.
Whichever protocol you support, it reads the same thing first: your product catalog.
Agentic checkout: what merchants must implement
To be bought by an AI agent, you need four things: an agent-ready product feed, a checkout path the agent can call (direct or through a platform), a tokenized payment method and clear policies. Product data is the only one of the four no platform can fill in for you.
The merchant checklist
- Complete product feed
Core fields on every product (
title,description,brand,gtin,price,availability, images) plus variant attributes likecolororsize. - Consistent data everywhere
Price and stock match on the PDP and in every feed or marketplace listing. So do specs.
- Checkout eligibility flags
is_eligible_checkoutin ACP feeds andnative_commerce(checkout_eligibility)in Merchant Center, set only on products that qualify. - Return policy and support contact
Return cost, window, link, plus a website, email or phone contact. Both appear in agent checkout.
- Tokenized payments
A PSP that accepts agent tokens or Google Pay, so cards are never exposed.
- Order webhooks
Order events (created, updated, shipped, refunded) sent back to the agent.
- Agent-friendly fraud rules
Bot management that recognizes signed, trusted agents instead of blocking them.
- Attribution
AI channel attribution in order data, to measure agent revenue.
We'd rank the first two above everything else. Checkout failures are loud. Bad product data fails silently, and the agent recommends someone else.
Where product data fits in every protocol
Protocols define the pipes, not what flows through them, and an agent can only recommend what it can read. Google's new conversational attributes and OpenAI's feed best practices point the same way: more structured attributes, plain-text descriptions and accurate variants.
The shoe from earlier, before and after a proper pass:
title
BeforeTrek GTX Black 10.5
AfterRidgeline Trek GTX Men's Waterproof Trail Running Shoe, Wide (2E), Black
description
BeforeOur toughest trail shoe yet. Built for adventure.
AfterWaterproof trail running shoe on a 2E wide last for runners with wide feet. The 5 mm lugged outsole grips mud and loose rock.
product_type
BeforeShoes
AfterFootwear > Running > Trail Running Shoes
product_highlight
Before(empty)
After2E wide fit; Waterproof membrane; 5 mm lugs for mud
attributes
Beforecolor: black
Aftercolor: black; size: 10.5; gender: male; material: recycled mesh upper, rubber outsole
The usual advice is to write longer descriptions for AI. Length isn't what changed; every claim an agent needs is now a quotable fact.
Attributes
Can the agent match the product to the request?
Material, size, fit, dimensions, compatibility, GTIN, category
Descriptions
Can the agent understand and justify it?
Plain-language text with specs and benefits, plus comparisons
Use cases and intents
Can the agent connect it to the shopper's situation?
Who it's for, when to use it, what problem it solves, FAQ
Feeds
Is the data delivered and current?
ACP feed, Merchant Center feed, prices, stock, policies
One catalog feeds search and Shopping ads, and every agent protocol
That's the work of Agentic Commerce Optimization. Start with product feed optimization, then add on-page markup from structured data for ecommerce.
Agentic commerce protocols with AndromedAI
AndromedAI doesn't replace ACP, UCP or your payment provider. It fixes the product data those protocols carry and publishes it back to your store and feeds.
We've optimized 500+ catalogs. Every SKU gets an AI Readiness Score across four dimensions (Product Data Completeness, Keyword Coverage, Customer Intent Match, Shopping Metadata), and the platform fixes what agents can't read. Brand Kit rules and AI checks with approval workflows keep each change on-brand.
| Protocol requirement | AndromedAI | What it does |
|---|---|---|
| Know which products are not agent-ready | AI Readiness Audit | Scores product pages on the four dimensions and shows which attributes, keywords or intents are missing |
| Complete pages for every SKU | Creator | Creates full product pages from brand or supplier data, in 12 languages |
| Agent-readable copy and attributes | Optimizer | Rewrites titles, descriptions, bullets and FAQ, extracts attributes, adds use cases and intents |
| Category coverage for broad prompts | Category Page Optimizer | Builds category pages (PLPs) around real shopper demand |
| Merchant Center conversational attributes | Optimizer | Generates Merchant Center conversational attributes for AI Mode and Gemini |
| Consistent data in every feed | Integrations | Imports from CSV, Google Sheets, Shopify, Akeneo, SAP, PDF spec sheets, XML/JSON feeds and REST API; publishes to Shopify, Google Merchant Center, Salesforce Commerce Cloud, Adobe Commerce, Shopware, Akeneo, Plytix and WooCommerce |
The improved data flows into the sources that Shopify Catalog and ACP or UCP providers read. Fix the catalog once and every channel picks up the change.
clicks from AI chats such as ChatGPT, Gemini and AI Mode
Bomboogieto the first sales from ChatGPT, with catalog generation costs down 95%
Matassasales and +160% organic traffic, with 483 hours saved
SemprefarmaciaFAQ
The Agentic Commerce Protocol (ACP) is an open standard co-developed by OpenAI and Stripe and released in September 2025. It defines how AI agents and merchants exchange product feeds, checkout sessions, delegated payment credentials and order updates. It powers shopping in ChatGPT.
ACP is led by OpenAI and Stripe and serves shopping in ChatGPT. UCP is led by Google and powers checkout in AI Mode in Google Search and the Gemini app. Both keep the merchant as seller of record and both start from a product feed: an ACP feed for ChatGPT, the Merchant Center feed for UCP.
An ACP product feed with the nine required fields (item_id, title, description, url, brand, seller_name, image_url, availability, price) and current prices and stock. For checkout you also need privacy and terms URLs plus signed HTTPS checkout endpoints, or a provider that hosts them, such as Shopify, Stripe, PayPal or Salesforce.
UCP is an open standard Google announced in January 2026 for agent shopping from discovery through checkout and post-purchase. It reuses the existing Merchant Center feed, adds checkout eligibility attributes, and supports native checkout in AI Mode and Gemini with Google Pay. Access goes through a waitlist and Google approval.
Agentic payments are payments an AI agent makes on a shopper's behalf, using tokenized credentials and proof of the shopper's intent instead of a raw card number. Examples include Google's AP2 mandates, Stripe's Shared Payment Token, Mastercard Agent Pay, Visa Intelligent Commerce with the Trusted Agent Protocol, and PayPal's wallet in ChatGPT.
ChatGPT shopping still works, but the checkout model changed. In March 2026 OpenAI said the first version of Instant Checkout did not offer the flexibility it wanted. Merchants can now use their own checkout experiences, and ACP was extended to power product discovery, so the product feed matters more than the checkout endpoint for most merchants.
It depends on your platform. If you're on Shopify, start with Shopify Catalog and agentic storefronts, which handle the protocol work. If you run Google Merchant Center, prepare for UCP and reach ChatGPT through an ACP provider such as Stripe, PayPal or Salesforce. Either way, fix your product data first, because every protocol reads it.
Glossary
- Agentic commerce
- Shopping where AI agents search and compare products for a shopper, and sometimes buy them
- ACP
- Agentic Commerce Protocol, the open standard by OpenAI and Stripe that covers product feeds and checkout, including delegated payments
- UCP
- Universal Commerce Protocol, the Google-led open standard for agent shopping and checkout in AI Mode and Gemini
- AP2
- Agent Payments Protocol, Google's open protocol that uses signed mandates to prove a shopper authorized an agent payment
- Shared Payment Token
- A Stripe payment credential scoped to one merchant and one amount, valid for a limited time
- Agentic token
- A tokenized card credential issued for AI agents (Mastercard Agent Pay, Visa Intelligent Commerce)
- Merchant of record
- The business legally responsible for the sale and payment, including taxes and returns; in ACP and UCP this stays the merchant
- MCP
- Model Context Protocol, a standard that lets AI models connect to external tools and data; both ACP and UCP support it
Keep reading
How AI agents search, compare and buy, and what brands should do now
GuideAgentic Commerce Glossary: 60 Terms ExplainedPlain definitions of ACP, UCP, AP2, mandates, agent tokens and more
GuideHow to Get Your Products Recommended by ChatGPTThe ChatGPT shopping playbook, from ACP feeds to product data
GuideGoogle AI Mode Shopping: How Products Get Picked in AI Mode and GeminiHow Google chooses products in AI Mode and where UCP fits
Sources (17)
- Stripe: Stripe powers Instant Checkout in ChatGPT and releases the Agentic Commerce Protocol
- OpenAI: Powering product discovery in ChatGPT
- Agentic Commerce Protocol specification (GitHub)
- OpenAI: Agentic checkout spec
- OpenAI: Product feed spec
- Universal Commerce Protocol (ucp.dev)
- Google for Developers: Universal Commerce Protocol
- Google for Developers: UCP implementation guide
- Google for Developers: UCP Merchant Center setup
- Google: New tech and tools for retailers to succeed in an agentic shopping era
- Google Cloud: Announcing the Agent Payments Protocol (AP2)
- Digital Transactions: Visa launches Trusted Agent Protocol
- Mastercard: Mastercard unveils Agent Pay
- McKinsey: The agentic commerce opportunity
- PayPal: OpenAI and PayPal team up on agentic commerce in ChatGPT
- Shopify: Agentic storefronts (Winter '26 Edition)
- Stripe: Introducing the Agentic Commerce Suite
Featured in








