Skip to content
Ai And Automation 7 min read

ACP, UCP, AP2 and Visa TAP: Four Different Agentic Commerce Jobs

Compare what ACP, UCP, AP2 and Visa Trusted Agent Protocol actually specify: product discovery, checkout, delegated authority and agent recognition.

PB
By Shaun Toh
TL;DR

ACP, UCP, AP2 and Visa TAP are often put in one agent-payments bucket, but they answer different integration questions. A merchant may need commerce data, checkout, proof of user intent and trusted-agent recognition separately.

Operator Summary

OpenAI's ACP landing page foregrounds structured product data for discovery in ChatGPT; checkout has separate documentation and eligibility. Google's UCP describes discoverable business capabilities including checkout and separate payment instruments and handlers. Google's AP2 describes signed mandates as evidence of delegated purchase authority. Visa TAP specifies signed agent-to-merchant requests so a merchant can recognize a trusted agent. None is, by itself, an entire payment and fulfilment system, and support for one does not establish support for the others.

A merchant hears four acronyms and asks which one to integrate. That is the wrong first question. These specifications describe different parts of a purchase. The useful decision is which evidence or capability your current flow is missing.

SpecificationDocumented jobWhat a merchant could verify or exchangeNot established by that step alone
OpenAI ACPCatalog data and product discovery; separately documented checkoutProduct and inventory information in the current developer flowCheckout eligibility, user consent or a successful payment from a feed alone.
Google UCPDiscoverable commerce capabilities, including checkoutBusiness capabilities and checkout state; supported payment instruments and handlersThat every handler or transport is available at every merchant.
Google AP2Evidence of delegated authoritySigned intent and cart mandates for the relevant purchase flowMerchant fulfilment or payment settlement.
Visa TAPRecognition of agent-to-merchant requestsSigned HTTP request, agent key and freshness dataThat the customer approved this exact basket.

The table compares the published material checked on 1 October 2026. It is a map of roles, not a claim that the specifications are interoperable or all generally deployed.

ACP: discovery is the documented starting point

OpenAI's current ACP developer entry point foregrounds structured merchant catalog data, inventory and product presentation inside ChatGPT, while its documentation also links to checkout material. A feed makes content legible to a shopping agent; it does not mean every merchant supplying a feed can accept an in-chat checkout. Older announcements about Instant Checkout and the current developer entry point describe different scopes; an operator should verify actual merchant eligibility and the specific checkout integration before promising a payment journey.

The practical test: can your catalog expose accurate availability, price, variants and attribution? Then ask separately where the order is placed and which payment provider reports the final outcome.

UCP: checkout capability and payment choice

Google's UCP architecture walkthrough shows a business publishing its supported capabilities at /.well-known/ucp. Checkout is one such capability. Its example separates the instrument a customer uses from the handler processing the payment, and describes API, MCP and A2A bindings. This is more than a product feed, but a manifest is only a declaration of what an implementation supports. A sample checkout does not prove a merchant's production connection, a payment method's approval or delivery of the goods. The agent checkout lifecycle follows the separate order, payment and post-purchase records once a checkout is attempted.

The practical test: which capabilities, transports and payment handlers does your business actually expose, and what happens when a requested feature is absent?

AP2: proof of the instruction

Google's AP2 announcement describes cryptographically signed mandates. With a human present, an Intent Mandate records the task and a Cart Mandate captures the approved exact items and price. In a delegated task, the user may sign detailed conditions in advance and the agent can form a cart within them. The point is evidence linking a user's permission to a later purchase request, including the case where the user is absent at checkout.

The practical test: who signs which mandate, how are changed prices or substitutions handled, and can the payment credential be linked back to the approved cart? A mandate is not a bank settlement record.

Visa TAP: is the request from a trusted agent?

Visa's Trusted Agent Protocol specification describes signed HTTP requests at product browsing and checkout. The merchant validates a signature, key, timestamp and nonce to assess whether the request came from a trusted agent and has not been altered or replayed. The specification also describes consumer-recognition and payment-container data for its Visa Intelligent Commerce flow.

The practical test: which keys do you trust, how do you reject expired or replayed requests, and how do you treat a failed signature? Even a valid agent signature must be joined to the customer's authority, the order and the payment result.

Choose the missing control, then test the full journey

If your gap is being found, inspect ACP's catalog path. If it is machine-readable checkout, examine UCP capabilities. If it is proof of permission, study AP2 mandates. If it is recognizing an agent at your site, study TAP. Most operators will need several of these functions, plus ordinary order, payment, refund and dispute handling. The agentic payments overview shows those handoffs; the controls guide covers bounded authority and revocation.

Sources & methodology (4)

OpenAI currently describes ACP as a connective layer that ingests structured catalog data and surfaces relevant products in ChatGPT; the referenced developer entry point does not itself promise checkout availability to every merchant

Checked:

Source types explained in our Methodology.

Shaun Toh By Shaun Toh · Director, Digital Payments · Razer

More Ai And Automation briefings