Contents
Share this article
Key Takeaways
Since the start of the year, we’ve seen orders from AI-powered search on platforms like Shopify grow massively.
Specifically, traffic from AI-driven sources to Shopify stores grew 8 times year-over-year in the first quarter of 2026, and new buyers arriving through AI channels converted at nearly twice the rate of those arriving through other channels.
What this shows us all is that we’re right in the middle of an AI shopping agent moment. Unfortunately, the checkout layer hasn’t quite caught up yet.
Discovery and checkout are two different problems. After all, an AI that can recommend the right running shoe is useful, but different from an AI that can then purchase the right running shoe, choose the size, apply a promotional code, confirm the shipping address, and handle payment without redirecting the user to a browser tab is something else entirely.

The gap here sits in the payment infrastructure, which is being attacked from different angles by a variety of companies, including:
The checkout infrastructure these companies build now will carry an enormous volume of transactions later, so let’s take a look at what they are doing and the processes they are taking in their approach.
Having a skilled fintech developer on your team can help you make sense of the current developments, whether that’s to integrate them into your own project or identify market gaps your fintech could take advantage of.
We can help you find the right people for your project in as little as 3-5 days, placing fintech experts from our pre-vetted pool based on their production experience.
| Company | Checkout approach | Funding | Protocol support |
| Stripe | Shared Payment Tokens + ACP + Link Wallet | Public | ACP (co-developer) |
| Shopify | Agentic Storefronts + UCP + Shop Pay | Public | UCP (co-developer) |
| Klarna | BNPL via Stripe Shared Payment Tokens | Public | ACP (via Stripe); UCP (Google) |
| PayPal | ACP via Braintree; 400M+ wallet network | Public | ACP |
| Primer | AI orchestration (Primer Companion) across full payment stack | ~$162M | Multi-protocol via orchestration |
| Gr4vy | MCP-based Agentic Development Kit; single-tenant cloud instances | $27.2M total | AP2 (alpha MVP); multi-protocol |
| Payrails | Token vault + intelligent orchestration for credential independence | $52.8M total | Multi-PSP, multi-protocol agnostic |
| Bluerails | Agent readability + checkout execution + global settlement | Early stage/undisclosed | HTTP 402, ACP-compatible |
For a lot of people, when asked about agentic checkout, the first thing that comes to mind is ChatGPT Instant Checkout.
When OpenAI launched the feature in late 2025, Stripe handled the payment execution.
The underlying infrastructure, a product called Shared Payment Tokens (SPTs), solves the specific problem that had blocked agent-initiated purchases for years: how do you give an AI agent the ability to spend money without giving it your card number?
SPTs work as scoped authorizations. Each token is tied to a specific merchant, carries a time limit, has an amount cap, and can be revoked instantly. All of this means that the agent never touches raw card data.
When a purchase fires, the token validates against those parameters, Stripe's Radar fraud detection runs in the background, and the transaction either completes or fails with enough signal to diagnose why.
What’s particularly great is that the token can also be reused for subscriptions or repeat purchases within the defined scope, adding convenience for users who are familiar with those options, and perhaps expect them.
Stripe and OpenAI co-developed the Agentic Commerce Protocol (ACP) as an open standard on top of this infrastructure to define how AI agents discover merchant product catalogs, initiate checkout sessions, and receive confirmation.
In theory, the ACP can work across any agent platform that adopts it, not just ChatGPT.
Stripe also launched a Link Digital Wallet specifically for agentic contexts. This tool maintains the buyer's purchase history and spending limits across AI platforms rather than requiring re-authorization for each agent session, and also preserves customer identity across ChatGPT, Perplexity, and other shopping interfaces that adopt ACP.
ACP is currently the most widely deployed agentic checkout protocol in production, so if your team is building checkout flows for agent-facing products, they will need to understand SPT mechanics to architect the authorization layer correctly.
The revocation capability also provides a compliance-friendly answer to the question of what happens when an agent makes an unauthorized purchase.
Shopify's approach to agentic checkout starts before the transaction. The argument the company makes, and backs with data, is that product discoverability across AI shopping channels matters as much as the checkout experience once a buyer gets there.
In Q1 2026, they reported nearly 13x growth in orders from AI-powered searches. They also noted that new buyers arriving via AI channels were converting at close to twice the rate of other acquisition channels.
Agentic Storefronts, launched as part of Shopify's Spring '26 Edition, automates the distribution of merchant product catalogs to AI shopping platforms like ChatGPT, Microsoft Copilot, and Google AI Mode.
This means that someone with an existing Shopify store gets multi-channel AI distribution without needing to install any additional apps or build custom integrations. The Shopify Catalog API handles syndication and keeps product data current in real time.
Shopify co-developed the Universal Commerce Protocol (UCP) with Google to help standardize what happens once a buyer commits to a purchase through one of those channels, including preserving the merchant's discount rules, shipping terms, and legal requirements.
Shop Pay, Shopify's checkout product, handles the payment execution step within the UCP flow, benefiting from the fraud detection and conversion optimization Shopify has built around it over the past several years.
And, surprisingly, unlike OpenAI's 4% channel fee on ACP-based ChatGPT purchases, UCP does not carry the same fee structure. For high-volume merchants, the commercial terms can make a massive difference on profitability.
Fintech products that serve e-commerce merchants need to understand UCP mechanics to advise clients on agent readiness.
The Catalog API architecture also offers a model for how financial data could eventually be structured for agent consumption.
One big issue with agentic checkout is that buy now, pay later was getting left out.
Agents were purchasing using a saved card on file. BNPL operates on a separate authorization flow and requires its own approval step, which made it effectively invisible to agents.
Klarna's partnership with Stripe addresses exactly that gap.
The integration works through Stripe's Shared Payment Token, allowing a buyer to choose a preferred payment method, including options like Klarna.
SPTs can now represent a Klarna financing option, carrying the Klarna authorization, and the buyer's chosen payment method, including the installment schedule they previously selected, carries through without the agent needing to renegotiate the payment terms.
For US merchants already live on Klarna through Stripe, no new integration is required.
At the same time, Klarna has expanded into Google's UCP environment, partnering with Google to make flexible payment options available through Copilot and other AI shopping channels that run on the UCP standard.
The result has been that Klarna has positioned itself as the BNPL layer in both of the dominant agentic checkout protocols simultaneously.
Any fintech product that involves credit or financing embedded into a purchase flow will need to think through how its authorization model maps to SPT or UCP scoping.
Klarna's implementation could be the start of a pattern where the financing product needs to be representable as a token with defined limits.
PayPal's agentic commerce argument is all about distribution. The company already operates a network of over 400 million user wallets.
At the moment, when an AI shopping agent needs to complete a purchase, it has to navigate the authorization question largely from scratch for each merchant.
PayPal's position is that a buyer's existing PayPal wallet, already funded, already trusted by hundreds of thousands of merchants, already containing their preferred payment methods, should be the natural funding source for agent-initiated transactions.
The large company adopted the Agentic Commerce Protocol and built its integration through Braintree, its payment processing subsidiary, and the technical flow uses ACP's token-based checkout structure, supporting cards, Apple Pay, and Google Pay at the token level.
The merchant-of-record positioning matters a great deal here.
When an agent purchases from multiple merchants through PayPal's network, the buyer sees PayPal-branded checkout confirmation rather than merchant-specific confirmation, which may help with the trust problem that exists right now.
PayPal's 400M wallet network represents the largest existing pool of pre-authorized buyers in the ACP ecosystem.
For merchants evaluating which payment provider to prioritize in their agentic checkout integration, the existing buyer coverage argument is a real one.
Most payment orchestration products make routing decisions based on a small number of variables like transaction amount, card BIN, and acquirer uptime.
Primer's argument is that this is not nearly enough data to optimize intelligently, and the company has spent several years building infrastructure to prove it.
They now aggregate over 400 data points per transaction, across PSPs, acquirers, fraud signals, and historical outcomes, and handle approximately 95 percent of customer payment volume on average for their enterprise clients.
The current version of Primer Companion, launched in 2025, operates as an AI advisory layer, surfacing complex payment insights and anomalies in natural language.
The plan for the next phase is to shift it towards execution, running routing experiments, optimizing across channels, and retrying failed transactions through alternate paths within parameters the merchant defines in advance.
In the context of agentic checkout specifically, Primer's orchestration layer matters because agent-initiated transactions tend to fail at higher rates than human-initiated ones.
A lot of this can be attributed to the fact that agents lack the behavioral signals that fraud systems use to establish legitimacy.
For engineering teams building payment infrastructure where agent transactions will represent a significant share of volume, the data architecture question is important to address early.
Primer's aggregation approach, 400+ data points per transaction from multiple systems, sets a reference point for what payment intelligence actually requires at scale.
Gr4vy decided to use MCP servers as the interface between AI agents and the payment orchestration layer.
The Model Context Protocol, developed by Anthropic, has become a widely adopted standard for connecting AI models to external tools and data sources, and Gr4vy now deploys that protocol in single-tenant merchant instances, which keeps payment data isolated and PCI Level 1 compliant while giving agents a standardized way to initiate checkout flows.
The Agentic Development Kit (ADK) also lets merchants build storefronts that operate inside conversational interfaces like ChatGPT without rebuilding their existing payment infrastructure.
All a merchant needs to do is integrate with Gr4vy via a single API, and then they can either connect to their current payment stack or access more than 400 payment methods and PSPs through Gr4vy's network.
The ADK also adds real-time routing, custom fraud rules, and dynamic workflow logic on top of that connection, all observable through monitoring dashboards.
Gr4vy’s alpha MVP of agentic payment orchestration was built in collaboration with Google's Agent Payments Protocol (AP2), making it one of the first orchestration platforms with a working implementation of the AP2 standard alongside ACP and UCP.
Even if you have no plans to use Gr4vy, deploying MCP servers as the interface between agents and payment systems will likely appear across multiple payment infrastructure products as MCP adoption expands.
Understanding how that architecture handles PCI compliance and fraud rule isolation is going to be incredibly useful.
One of the less-discussed risks in agentic commerce is PSP lock-in through credential dependency.
Simply put, if a merchant's payment credentials live in Stripe's vault, switching PSPs or adding a new checkout channel means migrating card data, which is an expensive, slow, and compliance-heavy process. Payrails aims to encourage credential independence.
The token vault stores payment credentials independently from any specific PSP, and network tokenization keeps cards current as they are updated, renewed, or replaced.
When a checkout channel changes, whether that is adding an agent-initiated flow, enabling a new payment method, or switching acquirers to improve approval rates, the underlying credentials stay portable.
The orchestration layer routes transactions to the provider most likely to approve them, based on BIN, country, issuer, card type, and historical performance, and applies intelligent retry logic when a transaction declines.
Ask Payrails, the company's AI layer, has the additional benefit of adding automation to payment operations tasks that typically require human analysts. This includes things like reconciliation, dispute monitoring, and fee analysis across multiple PSP stacks.
For enterprise merchants running complex multi-market operations, those tasks consume significant engineering time that could otherwise go toward product development, increasing the potential savings.
The credential independence argument becomes more important as checkout channels multiply.
If those channels all require separate payment credential management, the operational complexity compounds quickly.
Payrails' vault architecture fixes that problem before it even starts.
Bluerails starts from the fact that over 99 percent of merchant websites are currently unreadable to AI agents.
They do not expose structured product data, they do not signal pricing in machine-interpretable formats, and they have no concept of agent-initiated checkout.
This means that any shopping agent arriving at one of these sites can scrape visible text, but it cannot reliably extract product specifications, verify availability, or initiate a transaction without triggering bot detection.
Bluerails offers a four-part infrastructure layer that addresses this before the checkout question even arises.
Agent Identity verifies whether an incoming agent is authorized and legitimate. Agent Readability structures site content through llms.txt files, schema markup, and HTTP 402 endpoints, making the site's product and pricing data consumable by AI without scraping.
Checkout Execution handles transaction completion for agents that have established identity and found a product to purchase. Global Settlement manages cross-currency payouts, including EUR accounts and SEPA support.
At the moment, Bluerails operates on a freemium model where basic agent readability setup starts free, with paid tiers for checkout execution and settlement. Funding details have not been disclosed. At this stage, the company is most relevant as a reference architecture for merchant-side agent readiness: the problems it solves (discoverability, identity, checkout, and settlement) are the same problems every merchant will need to solve regardless of which platform they ultimately use.
The agent readability layer Bluerails describes, structured signals that make a site's products and pricing interpretable by AI without scraping, is likely to become a hygiene requirement rather than a differentiator as agentic commerce scales. Engineering teams advising merchants on agent readiness will want a framework for evaluating these four layers: identity, readability, checkout, and settlement.
All of these companies, and anyone else trying to identify gaps in the market to build products of their own, need engineers who understand both sides of the agentic checkout problem.
The technical side involves token authorization flows, MCP server architecture, payment orchestration, acquirer routing, and PCI DSS compliance. On the product side, developers need to understand how these systems interact with consumer trust, with chargeback liability, and with the compliance frameworks that govern financial transactions.
Engineers with that combination are incredibly rare and expensive.
At Trio, we place pre-vetted senior fintech engineers from Latin America with teams building in regulated payment environments, typically within a week or two.
If your team needs backend engineers who have built payment authorization systems, API engineers familiar with the emerging agentic protocols, or ML engineers with experience in transaction-level fraud detection, we can help.
The practical steps merchants can take right now to prepare for agentic checkout can be divided into four areas. First, product data: ensure catalog data is structured, complete, and accessible via API or a format AI platforms can consume. Second, checkout infrastructure: evaluate whether your current payment stack can accept tokenized agent payments without friction. Third, fraud rules: work with your payment processor or orchestration layer to establish agent-specific routing and scoring rules. Fourth, liability: review chargeback policies for agent-initiated transactions with your PSP and legal team.
There are several compliance risks in agentic checkout, and not all of them are resolved. Liability for agent-initiated chargebacks sits in a gray area under current card network rules, which were written assuming a human cardholder authorized each transaction. Merchants tend to absorb these chargebacks by default until clearer frameworks emerge. Reg E protections for consumers, which govern unauthorized electronic fund transfers, were not designed with autonomous agent purchases in mind. AML and fraud detection systems also need retraining to handle machine-speed transaction volumes that look different from human behavioral patterns. Data privacy regulations, including GDPR and CCPA, apply to behavioral and preference data that agents use to personalize purchasing decisions, and the data flows involved in agent checkout do not always map cleanly to existing consent frameworks.
Many companies support both ACP and UCP. Klarna has integrated with both, making BNPL available through Stripe’s SPT infrastructure (ACP) and through Google’s UCP environment. PayPal supports ACP via Braintree and has signaled interest in broader protocol participation. Orchestration layers like Gr4vy, Primer, and Payrails are protocol-agnostic by design.
The primary mechanism through which AI agents make payments without accessing card credentials is tokenized payment authorization. Stripe’s Shared Payment Tokens (SPTs) are the most widely deployed example: a buyer grants an AI agent permission to spend on their behalf, and that permission is encoded as a token scoped to a specific merchant, with a time limit and amount cap. When the agent presents the token at checkout, the token validates against its parameters, and payment executes without the agent ever seeing the card number or expiration date.
ACP (Agentic Commerce Protocol) was co-developed by OpenAI and Stripe and focuses narrowly on the checkout transaction itself, specifically enabling AI agents to initiate purchases using Stripe’s Shared Payment Token infrastructure. It is currently live in ChatGPT Instant Checkout and supported by Etsy, Shopify merchants, and a growing list of platforms. UCP (Universal Commerce Protocol) was co-developed by Google and Shopify and covers a broader scope, from product discovery through checkout, with a coalition of over 20 companies including Etsy, Target, and Walmart.
Agentic checkout is the specific mechanism by which an AI agent autonomously completes a purchase, handling payment authorization, shipping selection, tax calculation, and order confirmation, without redirecting the user to a merchant website or asking for approval on each individual step.
Expertise
Subscribe to our newsletter
Related
Content
Continue Reading