DEV Community

minia2a
minia2a

Posted on Originally published at minia2a.uk

Seven protocols, one status code: the agentic-commerce stack in October 2026

Two years ago, HTTP 402 was a status code nobody implemented. This September and October it became the centre of a land grab: Visa, Mastercard, Google, OpenAI, Stripe, Coinbase and Cloudflare have all shipped or standardised an agent-payment protocol, several of them in the last ten days. If you build agents that pay for things, here is the map — and a note on the one number every announcement leans on.

I run a pay-per-call API marketplace that settles USDC on Base. That is one rail and one protocol out of seven. The rest of this post is the honest picture of where that sits, sourced line by line, including the parts that are not flattering to the on-chain side.

Three layers, all moving at once

Layer 1 — card rails

Visa — Trusted Agent Protocol (TAP). Pre-GA; Visa's own page says the product is "in the process of development and deployment." TAP is the merchant-side half of Visa Intelligent Commerce: signed, merchant- and purpose-specific, time-bound, non-replayable messages so a CDN or merchant can tell a Visa-trusted agent from a scraper. It settles on card rails, not on-chain. Sample implementation: github.com/visa/trusted-agent-protocol.

Mastercard — Agent Pay for Machines (AP4M). Announced June 2026, targeting sub-cent machine payments, and explicitly multi-rail: cards, accounts, and stablecoins. 30+ launch partners include Cloudflare, Coinbase, OKX, Stripe, Polygon and the Solana Foundation. On September 30, 2026, Mastercard added a trust service that scores the probability a transaction was AI-initiated, built with Cloudflare and Skyfire.

Both card networks now say the quiet part out loud: the agent should not have to care which rail it is. Visa's Intelligent Commerce Connect is explicitly network- and protocol-agnostic and supports TAP, MPP, ACP and UCP.

Layer 2 — platform protocols

Google — AP2. Donated to the FIDO Alliance in 2026. v0.2.0 adds Human-Not-Present / autonomous payments; still pre-release (0.x). It is the only one of the four major specs with a versioned release so far, and its reference samples include an x402 flow.

Google + Shopify — UCP. Announced at NRF in January 2026; founding council Google, Shopify, Etsy, Target, Walmart. Amazon, Meta, Microsoft, Salesforce and Stripe joined the Tech Council in April. OpenAI is absent. Discovery is via /.well-known/ucp; payments ride on AP2.

OpenAI + Stripe — ACP. Released September 2025, using single-use, merchant-scoped Shared Payment Tokens. Instant Checkout was discontinued on March 4, 2026 after weak consumer interest (reportedly ~30 merchants). ACP survives as plumbing for ChatGPT apps.

Layer 3 — on-chain and the 402 formalisation

Coinbase / Cloudflare — x402. Open-sourced May 2025, transferred to the Linux Foundation; the x402 Foundation launched April 2, 2026 and reached ~40 members by July (Coinbase, Cloudflare, Stripe, Circle, Google, Microsoft, AWS, Visa, Mastercard, Shopify, Solana, Polygon). Block (Dorsey) joined September 24, 2026, contributing Bitcoin and Lightning. Cardano was integrated into the official x402 SDK this quarter. On October 1, 2026, the XRP Ledger passed 10 million x402 payments in under three months.

Tempo + Stripe — MPP. This is the one to watch if you care about interop: MPP formalises HTTP 402 as an IETF submission — the Payment HTTP Authentication Scheme — and is rail-agnostic (Tempo stablecoins, Stripe cards and wallets via SPTs, a Visa card spec, Lightspark Lightning). Stripe's own post says Stripe supports both MPP and x402 but does not claim they interoperate; claims that the two are compatible are third-party and I treat them as unverified.

The pattern: the card networks went multi-rail, the platform protocols went agnostic, and the on-chain protocol went to a foundation. Everyone is racing to be the neutral layer — which means the neutral layer is contested, and the durable differentiator left is not "can you take this payment" but "is this endpoint live, at what price, and did the payment produce the thing."

The number every announcement leans on

10 million x402 payments on XRP Ledger is a real signal that the rail is being exercised. It is also the easiest number in the stack to grow and the least informative. A payment count is challenges answered — not value transferred, not distinct payers. XRPL's announcement gave no settled total and no payer count.

Independent on-chain analyses are blunter. TRM Labs put settled x402 volume at roughly $52.7M since May 2025, of which only about $25.6M was genuine, with agents accounting for between 0.6% and 7.5% of activity; Artemis estimated around half of observed activity as artificial. A payment-count headline and a settlement-volume study point in different directions, and only one of them is on the press release.

The same discipline applies to my own dashboard. On minia2a.uk/api/stats the biggest number is the one I tell people not to quote:

Metric Value (Oct 1, 2026) What it means
Total requests served 4,734,866 Inflated. The field's own note says it counts bot polling and self-polls. Do not cite it as usage.
Real on-chain USDC 225 txns = 6.22 USDC 193 settled pay-per-call + 32 legacy top-ups, each verifiable on Base. The honest size of settlement.
Real adopting agents, 7d 3 Distinct HMAC(X-Agent-ID) — the identity we can actually attribute.
Services listed 1,694 A listing count, not a delivery count.

The distance between the first row and the second is the whole point. Any x402 platform — mine included — can grow its request counter by pointing a probe at its own catalogue. The numbers that resist inflation are the ones that cost money to produce.

What this means if you build agents

If the rails converge, and the last two weeks suggest they are, then holding a rail stops being a moat. What stays hard is the half nobody demos: out of everything that will accept a 402, which endpoint do I call, at what price, is it still live, and did the payment return what was promised. That is discovery and delivery, and it is measured in successful deliveries, not in challenges answered.

A directory count of 1,694 services and a delivery-verification headline of "13 of 659 verified" (as one public x402 directory reports) describe the same industry. The gap between them is the work.

What I am and am not claiming

  • I cite; I did not independently verify. Every protocol status is from the primary source. The MPP↔x402 interop claim is third-party and marked unverified.
  • I am not comparing rails or protocols. I settle USDC on Base and say so. This is not an argument that on-chain beats cards or that x402 beats UCP — it is an argument that a payment count is not the number to judge any of them by.
  • The discipline applies to me first. The 4.7M request figure on my own stats page is inflated and I say so on the page.

Originally published at minia2a.uk. Sources: Visa TAP overview and Intelligent Commerce Connect; Mastercard AP4M launch and the Sept 30 trust services; Google AP2 spec and the FIDO donation; UCP spec and Tech Council; OpenAI/Stripe ACP and the Instant Checkout wind-down; x402 Foundation / Block; MPP (Stripe blog, mpp.dev, Visa); XRP Ledger 10M; Cardano x402 SDK; TRM Labs and Artemis figures; directory verification ratio.

Top comments (0)