How AI agents pay: checkout, delegated tokens and x402
An AI agent can help a customer reach checkout, use a delegated payment credential, or pay for a software resource. The right approach depends on what you sell and who authorizes the purchase. Here is how to choose a payment flow and verify that it works.
Reviewed October 1, 2026 · 9 min read
On this page7 sections
- Customer purchases: hosted checkout and delegated tokens
- Software purchases: paying for an API call or resource
- Who controls the wallet and its spending?
- Choose the payment approach by the job
- Keep untrusted content away from spending authority
- What should your business do first?
- Verify the whole purchase, not just the charge
AI agents can initiate payments through existing checkout systems, delegated credentials or protocols such as x402. The agent is acting for a person or organization with a budget. Its ability to make a request does not, by itself, give it permission to spend.
For most retailers and service businesses, the starting point is familiar: an accurate total, a supported payment method and an order confirmation. Sellers of APIs or metered content may also need a way for software to purchase access automatically. These are different workflows, and they deserve different integration decisions.
OpenAI’s move toward merchant-owned checkout makes the distinction useful. An assistant can discover a product and send a buyer to your store without becoming the payment processor. A checkout handoff is progress, but it is not a completed sale.
Customer purchases: hosted checkout and delegated tokens#
In a hosted checkout, the customer completes payment through your existing provider. In a delegated flow, an authorized agent supplies a credential that your payment integration can use. Prefer scoped credentials over exposing payment secrets to the model, and check the provider’s actual restrictions rather than assuming every token is identical.
Stripe Shared Payment Tokens, for example, grant a seller access to a payment method with usage and expiration limits. AP2 addresses authorization through signed mandates, including purchases approved directly and purchases made within previously approved constraints. UCP and ACP describe commerce interactions; the supported payment integration still matters.
Before choosing an integration, establish three things:
- Who is responsible for the sale? Confirm the merchant of record, receipt sender, support owner and refund process in the platform agreement.
- What exactly did the customer authorize? Bind approval to the merchant, items, currency and total, with a clear expiry and a way to handle changes.
- What proves completion? Use your payment provider’s verified status and your order system’s record. A token, browser redirect or agent message alone is not proof of a paid order.
Test declined payments, expired credentials and changes to the final amount. If shipping raises a $90 basket above a customer’s $100 limit, the system should request fresh approval or stop. It should never silently reinterpret the budget.
Software purchases: paying for an API call or resource#
A software agent may need a paid dataset, an API response or a short compute job. Its owner can authorize a budget in advance, allowing routine purchases without approving every request. The owner still needs spending records and a way to revoke access.
Per-call card charges can be uneconomic for very small amounts. Existing alternatives include prepaid credits, subscriptions and metered usage billed in batches. Compare those with a machine-payment protocol before adding another currency, wallet or settlement system.
x402 defines a payment exchange around HTTP’s 402 Payment Required response. A service advertises its payment requirements, and a compatible client supplies a payment payload. A simplified flow looks like this:
- The client requests a resource.
- The server returns 402 with the accepted payment terms.
- The client checks those terms against its spending policy and prepares a signed payment payload.
- The client retries with the payload; the server verifies it and handles settlement, directly or through a facilitator.
- The service returns the resource and payment information according to the supported payment scheme.
This can remove a separate account signup from the purchase flow. It does not remove the need for an authorized budget, or prevent a service from requiring authentication for protected resources. A payment proves that payment conditions were met, not that the caller owns every record behind the endpoint.
Start with one resource whose price and delivery conditions are easy to explain. Record the payment reference alongside the request and result. Decide what happens if the payment succeeds but the response is lost before the client receives it.
Test recovery as carefully as payment
A successful demo is only the first check. Test duplicate requests, timeouts, failed settlement and refunds. Document whether a retry returns the original result or creates another charge. Your provider’s supported scheme and recovery features determine what you must implement.
Who controls the wallet and its spending?#
An agent wallet needs a responsible owner. Establish who can fund it, approve destinations, change limits and revoke its credentials. Keep those administrative powers separate from the credentials an agent uses for routine purchases.
For example, a research agent might have a $5 daily budget, a 10-cent limit per request and permission to buy from three data providers. Enforce those rules in the payment service or application, outside the model’s instructions.
Keep enough information to reconcile each charge: the requesting agent, the approved task, the payee, the amount, the payment reference and the delivery result. Avoid logging raw payment credentials or private customer data unnecessarily.
Custody is a separate question. A network, wallet interface, processor and bank perform different roles. Do not infer who holds funds from the logo on a checkout button.
Ask the provider who holds funds or signing keys, how withdrawals work, what fees apply, and what happens during a dispute or outage. Those answers are more useful than a broad promise that the payment is autonomous.
Choose the payment approach by the job#
| Approach | Typical use | What to verify |
|---|---|---|
| Hosted checkout | A customer completes an agent-assisted purchase | Correct basket, final total, payment status and receipt |
| Delegated payment token | An authorized agent initiates a supported purchase | Recipient, amount, expiry, revocation and failure handling |
| Metered billing or prepaid credits | Repeat software usage | Usage records, budget limits and billing reconciliation |
| x402 | Compatible software purchases a paid resource over HTTP | Accepted scheme, authorization, settlement and retry behavior |
| AP2 mandates | Evidence that a checkout and payment were authorized | Signatures, approved constraints and linkage to the transaction |
AP2 is included here as an authorization mechanism, not as a substitute for moving money. Likewise, choosing UCP or ACP does not settle every question about payment methods, geography or eligibility. Confirm the particular platform integration you plan to use.
Check whether buyers can reach the offer
The Nexez scanner checks public access and machine-readable business information. Use it to find discovery problems, then test payment separately through your provider and order system.
Scan your site freeKeep untrusted content away from spending authority#
An agent may read instructions embedded in a web page, document or API response. That content must not be allowed to change its budget, payee or task. A page saying that an extra payment is required is a claim to evaluate, not permission to make one.
Use limited credentials, approved destinations, transaction caps and independent approval for higher-risk actions. Enforce those controls in code or provider settings. A reminder in the agent’s prompt is not an adequate spending control on its own.
On the merchant side, verifying the agent’s identity answers who sent a request. Customer authentication, purchase authorization and payment confirmation answer different questions. Keep all four checks in the flow where they are needed.
What should your business do first?#
Choose the smallest integration that supports a real customer or software workflow:
- Retailers and service businesses: test your existing checkout or booking handoff, including the selected item, price and confirmation.
- Merchants joining a shopping platform: check eligibility and the required catalog, checkout and payment capabilities before building.
- API and data sellers: compare prepaid or metered billing with x402 using actual transaction sizes, fees and support requirements.
- Agent builders: implement spending limits, approval rules, revocation and an auditable transaction record before enabling purchases.
- Platforms and marketplaces: define responsibility for settlement, refunds, disputes and customer support in every supported flow.
Verify the whole purchase, not just the charge#
Run a successful purchase and the failures that are likely to happen in production. Check the order record, payment record and customer confirmation together. Then test a cancellation or refund and confirm that every system shows the same outcome.
Preserve the selected variant, quantity, currency and delivery details when handing off to checkout. Keep necessary authentication and approval steps, while making errors and recovery instructions clear enough for both a person and an agent to follow.
Accurate structured data, product feeds and supported MCP tools can help an agent find and act on the right offer. They complement the payment flow; they do not replace its authorization or confirmation checks.
Finally, measure discovery, referrals and completed orders separately. Server logs can reveal automated requests, while browser analytics and order records capture other parts of the journey. No single traffic count tells you whether an agent-assisted purchase succeeded.
Give agents a clear path to your offers
Nexez publishes business and offer information in formats agents can read, with supported checkout and scheduling links. See how those listings connect discovery to the next step.
See how it worksFrequently asked questions
Do I need a crypto wallet to sell to AI agents?
Usually not. A retailer or service business can receive agent-assisted purchases through its existing checkout. A wallet becomes relevant when you choose a payment flow that requires one, such as a supported x402 integration. Start with the customer journey and your provider’s requirements.
Does an AI agent ever see my customer’s card number?
It depends on the integration. Prefer provider-hosted payment collection and scoped credentials so raw payment secrets do not enter the model’s context. Stripe Shared Payment Tokens are one example of delegated access with usage and expiry limits. Do not assume every agent or checkout uses the same design.
What is x402 in plain terms?
x402 is a protocol for requesting payment for a resource over HTTP. The server responds with 402 and payment terms; a compatible client submits a payment payload, which the server verifies and settles using its supported scheme. The client still needs an authorized budget and appropriate access to the resource.
Who is the merchant of record when an agent buys?
That depends on the platform and commercial agreement. Some merchant-owned checkout integrations keep the seller as merchant of record. Verify who issues receipts, handles refunds and disputes, and owns customer support rather than assuming the presence of an agent determines those responsibilities.
What should I check before using an agent wallet?
Confirm who holds funds and keys, how spending limits are enforced, which destinations are allowed, and how credentials can be revoked. Also check fees, settlement, refunds and recovery after a failed request. Test these controls before giving the agent a production budget.
How is AP2 different from x402?
AP2 describes authorization evidence for a checkout and payment, including purchases made within constraints approved in advance. x402 describes a payment exchange for HTTP resources. They address different parts of a transaction; neither makes an agent’s spending exempt from its owner’s permission or budget.
Keep reading
What changed with ChatGPT Instant Checkout in 2026?
OpenAI changed its shopping direction in March 2026, emphasizing product discovery and merchant-owned checkout.
6 min readAgentic commerceDoes an AI agent need an account to buy from you?
An assistant cannot create an account or sign in. What sits behind your login is invisible to it.
7 min readAgentic commerceWhy an AI agent can order the same thing twice
A lost confirmation can turn one purchase into two orders. Your checkout needs to recognize a repeat.
7 min read