PARAMETA

What Are Agentic Payments? What Must Be Proven First When AI Pays on Your Behalf

2026.09.30Insight
Blog — ArticleScroll

As AI agents, programs that handle tasks on a person's behalf, start taking on real work, 'agentic payments,' where AI pays on someone's behalf, have become a hot topic in the payments industry.

A '402 Payment Required' notice with the post title 'What Are Agentic Payments? What Must Be Proven First When AI Pays on Your Behalf'

Visa announced an AI payments service in April 2025, and in September of that year Google unveiled the Agent Payments Protocol (AP2), developed in collaboration with more than 60 organizations. In April 2026, the Linux Foundation set up the x402 Foundation to oversee x402, a web payment standard, with Google, Visa, Mastercard and others taking part in its founding. In July, the foundation began official operations with 40 members.

Timeline of agentic payments. April 2025: Visa announces an AI payments service. September 2025: Google unveils the Agent Payments Protocol (AP2). April 2026: the Linux Foundation establishes the x402 Foundation. July 2026: official operations begin with 40 members. September 2026: proof of concept by a Korean payments company

Things are moving in Korea too. Kakao Pay took part in founding the foundation, and in September it said it had completed a proof of concept for agentic payments on both the buying and the selling side. There were also reports that Kakao Group demonstrated this kind of payment at an event on September 28. The example Kakao Pay gave makes the scene easy to picture. An AI agent that needs weather information requests data from a seller. It pays in stablecoins, digital assets pegged to the value of a fiat currency, and takes the data. No one presses a payment button at any point in the process.

Kakao Pay CEO Shin Won-keun delivering a keynote at Next Finance Korea on September 28 (Photo: courtesy of Kakao Pay)

So what exactly is this kind of payment, and what is new about it? Let's start with the concept.

What Are Agentic Payments? Handing AI a Wallet With Set Limits

Agentic payments are payments an AI agent makes on a person's behalf. A user hands the agent a wallet with policies attached, such as purchase permissions and spending limits, and within those bounds the agent decides for itself what it needs, whether goods, services or data, and pays for it. Visa, too, has said that consumers set the spending limits and conditions, and that only consumers can instruct an agent on what to do and when to use their payment method.

Google's AP2 splits this setup into two scenarios. When the person is present, they might say "Find me white sneakers." The agent puts together a cart and shows it, and the person approves it with a signature.

When the person is away, they might hand off a task like "Buy the tickets the moment sales open," signing off in advance on conditions such as a price limit and timing. Once the conditions are met, the agent finalizes the cart on its own.

The only difference is whether a person is there at the final moment. But that one difference shakes a long-standing assumption behind payments.

If No One Presses the Pay Button, Who Proves the Payment Was Authorized?

Today's payments mostly rest on the assumption that a person presses "Buy" themselves, in front of a screen they can trust. Google wrote that autonomous agents break exactly this assumption.

Until now, the moment a person pressed the button was itself the sign that they had authorized the payment. When an agent pays instead, that sign has to be recorded some other way. That's why AP2 lists three things to consider in agentic payments.

Considerations for agentic payments. The three points raised by Google's AP2: authorization (proof that purchase authority was granted), authenticity (confirming the request matches what the user actually wants), and accountability (who is responsible when a transaction goes wrong)

① Authorization. What proves that the user gave the agent this purchase authority? If the agent bought beyond its limit, the first thing to settle is whether the purchase fell within the authorized scope.

② Authenticity. The seller needs to be able to confirm that an incoming request matches what the user really wants. After all, the agent may have misunderstood its instructions.

③ Accountability. If a transaction goes wrong or turns out to be fraudulent, who is responsible? If the wrong pair of shoes gets bought instead of white sneakers, it has to be settled in advance who covers the loss: the user, the company that built the agent, or the seller.

All three questions ask less about how money is sent than about who authorized what, and how far.

A Protocol Arrives to Fill the '402 Slot' a 1997 Spec Left Empty

HTTP is the set of rules that programs on the web use to exchange requests and responses. Servers reply with three-digit codes, the best known being "404," which shows up when a page doesn't exist. Among these codes, 402 has been in the spec since January 1997 under the name "Payment Required." Its entire description was "reserved for future use," and it stayed that way in the June 2022 revision. It was a slot with a name but no defined use.

x402 fills exactly this slot. It works a bit like being told at a shop door that an entry fee is required, paying, and then walking back in. If an agent makes a request without paying, the server answers with 402, and the agent pays and sends the same request again. The official x402 website says no account is needed for this process.

The six steps of the x402 payment flow. The user sets limits and permissions, the agent requests data, the server responds with 402 Payment Required, and the agent pays, sends the same request again and receives the data

If an agent pays every time it receives a single piece of data, payments become too small and too frequent for a person to press a button for each one. That is also why stablecoins come up alongside agentic payments: they are seen as a good fit for machines exchanging small amounts like these.

Visa Is Solving the Same Problem Within the Card Network

That doesn't mean agentic payments are the same thing as stablecoin payments.

Visa says Visa Intelligent Commerce makes AI-initiated transactions secure by adding controls, authentication and safeguards to payment information. It's an approach that layers limits and authentication on top of the card network people already use.

AP2, too, is designed to accept a range of payment methods, from cards to stablecoins to real-time bank transfers. Seen this way, stablecoins look more like one of several routes to agentic payments.

Comparison of agentic payment approaches. Visa layers limits and authentication on top of the card network, x402 handles small stablecoin payments, and Google's AP2 accepts cards, stablecoins and real-time bank transfers alike

Standards Don't Settle the Rules on Won Stablecoins or Liability

For AI to pay with Korean won stablecoins in Korea, the regulatory framework has to be in place first, and that discussion is still under way. Nor does the liability question get resolved just because a standard has arrived. Who pays when an agent makes a wrong payment is ultimately for regulation and contracts to decide. Only when there is a record of who authorized what, and which wallet was used for the transaction, is there even a starting point for working out liability.

Clues to the Three Questions Lie More in Identity Technology Than in Payments

All three questions are about recording, verifying and tracing the fact that someone gave permission. That's why AP2 records a user's instructions as a digital contract called a "Mandate" and signs it as a Verifiable Credential (VC) so it can't be forged or tampered with. Verifiable Credentials are a format defined by the web standards body W3C, and they are often used together with decentralized identifiers (DIDs). Here is how the identity technologies PARAMETA has been working on map to each of the three questions.

| AP2's question | What's needed | Related identity technology | |---|---|---| | ① Authorization | Proof that records the fact of authorization in a way that can't be altered | DID-based credential issuance and verification | | ② Authenticity | A setup in which the seller checks a signed credential but receives only as much user information as it needs | Credential verification, selective disclosure | | ③ Accountability | A record of who transacted with which wallet | Wallets, on-chain KYC |

Point ③ in particular, accountability, or who transacted with which wallet, is a problem PARAMETA has been addressing through on-chain KYC in ParaSta. On-chain KYC is customer verification carried out on the blockchain. The result of a KYC check completed by an authorized institution is issued as a VC, and the verified wallet address is registered on an identity list on the blockchain. At the moment a token is transferred, this list is checked so that only qualified wallets can transact. A result verified once can be reused across multiple services, and the original personal data is neither put on the blockchain nor collected and stored separately.

Even when payments are made by an agent holding a wallet, what needs checking in the end is the same: whose wallet is this, and is it qualified to transact?

One Analysis Says About Half of x402 Transactions Aren't Real Commerce

So how much is the 402 slot actually being used today? On March 11, 2026, CoinDesk reported that recent daily snapshots showed about 131,000 x402 transactions and roughly USD 28,000 in volume, or about 20 cents per payment on average.

On top of that, on-chain analytics firm Artemis judged roughly half of the observed x402 transactions to be artificial activity, such as self-dealing, where the same wallet buys and sells, or wash trading, where money the seller fronted comes back to it. CoinDesk noted that demand has yet to catch up.

x402 transaction volume as reported by CoinDesk on March 11, 2026: about 131,000 transactions and about USD 28,000 per day, roughly 20 cents per payment. Artemis judged about half of observed transactions to be artificial activity

Even if the numbers grow, it's possible that not every payment will be handed over to agents. AP2 itself leaves the signature that finalizes the cart to the person in its first scenario. For large payments, or payments where refunds and disputes are common, this route may be used more often. The more payments lose their button, the clearer it will become which payments keep the button to the very end.

Back to list