Agent Identity, Authorization & Payments

Parent: AI Agent Ecosystems · researched 2026-06-03T23:02:42.930Z· 42 sources · 12 concepts · skill agent-identity-authz-payments

The trust / permission / value layer for autonomous AI agents acting with

Agent Identity, Authorization & Payments

When to use / Skip

Why agents need their own identity

Delegation primitives (the standards)

Scoped, least-privilege, short-lived tokens (the discipline)

MCP authorization (agent -> MCP server) — spec rev 2025-06-18

Token vaulting / credential brokering

Agentic payments & commerce

Google AP2 (Agent Payments Protocol) — open spec, v0.2 (DRAFT)

Coinbase x402 — HTTP-native stablecoin payments (spec v2, 2025-12-09)

Agentic Commerce Protocol (ACP) — OpenAI + Stripe (+ Meta), open, BETA

Card-network programs (ANNOUNCEMENTS / pilots, Apr 2025+)

Agent-native / crypto startups

Integration patterns

Anti-patterns & failure modes

2025-2026 frontier & maturity flags

Sources

Children

Frontier under this node: AP2 mandates (Intent / Checkout / Payment, SD-JWT), Agentic Commerce Protocol & delegated payment / Shared Payment Token, Confused-deputy & prompt-injection authority hijack, Delegation chains & act/may_act claims, Human-in-the-loop consent & async authorization, MCP authorization & resource-server pattern (RFC 9728/8707), Non-human identity (NHI) for agents, OAuth 2.1 on-behalf-of / token exchange (RFC 8693), Scoped least-privilege short-lived agent tokens, Spend caps, allowances & agent payment audit trails, Token vaulting & credential brokering, x402 HTTP-402 stablecoin settlement

← the whole tree · 3D view· how to read this page