
Late last week, Block joined the x402 Foundation and wired Bitcoin’s Lightning Network into the protocol. The foundation’s member list now reads like a payments roll call – Visa, Mastercard, American Express, Adyen, Stripe, Google, AWS, Shopify, Circle – forty organizations, all voting to make one HTTP status code the billing layer of the agent economy.
If you are building something an autonomous agent is supposed to pay for, the temptation is to read that list as an answer. It is not. It is a symptom.
Conclusion first: six standards are on the table, and most comparisons of them are wrong, because they are not on the same layer. Two of them decide who is allowed to spend. The rest decide how the money moves. Rank them in one horse race and you will pick the wrong tool for the right reasons.
The hole being filled was dug in 1997
When someone tells you a new standard is going to be big, I have learned to ask a different question: whose hole is it filling, and when was that hole dug? A protocol that closes a gap left behind by an earlier generation of engineers is usually a real advance. A protocol invented to fill a hole that exists only in a pitch deck usually is not.
HTTP has carried a status code for this since the first HTTP/1.1 specification in 1997. 402 Payment Required. In RFC 9110, today’s version of the HTTP semantics document, it is still described as “reserved for future use.” Twenty-nine years of reserved.
The reason is not that engineers were lazy. It is that every payment flow on the web assumed a human at the other end. A human can be redirected to a checkout page, asked to type a card number, shown a CAPTCHA and made to accept terms. A program cannot – and, more importantly, should not be handed an API key that bills somebody else’s account without a limit.
What was missing was never the status code. It was a payer with no account, no signup, no KYC and no patience: an entity that can receive a 402, pay four-tenths of a cent, and retry the request in the same breath. That entity now exists, and we call it an agent.
So x402 is not a new idea someone invented at a conference last spring. It is the 1997 placeholder finally being cashed in. The server answers 402, the client pays in stablecoin – or, since Block’s change, over Lightning – and retries. That is the whole protocol, and how small it is remains the most interesting thing about it.

What each of the six actually is
Here is the lineup, sorted by what the thing does rather than by who is loudest about it.
| Standard | Who governs it | What it actually does | Money rail underneath |
|---|---|---|---|
| x402 | Linux Foundation (40 members, including Visa, Mastercard, Amex, Adyen, Stripe, Google, AWS, Shopify) | Pay-per-request over HTTP 402; a server can charge for any endpoint | Stablecoins on EVM chains and Solana; Lightning since last week; extensible to cards |
| AP2 (Agent Payments Protocol) | Google, with 60+ organizations; version 0.2 donated to the FIDO Alliance | Proves that a human authorized a specific purchase, via signed intent and cart mandates | Cards first; stablecoins and real-time bank transfers on the roadmap |
| ACP (Agentic Commerce Protocol) | Stripe, OpenAI and Meta, under Apache 2.0 | Agent-driven checkout sessions with delegated payment and authentication | Whatever processor the merchant already runs |
| UCP (Universal Commerce Protocol) | Google-led; Amazon, Meta, Microsoft, Salesforce and Stripe joined its technical council in April | Exposes catalogs and checkout surfaces to agents | The merchant’s existing stack |
| Trusted Agent Protocol + Agentic Directory | Visa | Identifies and allow-lists which agents may transact | Visa |
| Agent Suite / Agent Connect | Mastercard | Agent identity for merchants, plus a machine-to-machine protocol for agent micropayments | Mastercard |
Note the overlap. Visa and Mastercard are premier members of the x402 Foundation while shipping their own agent-trust schemes. That is not confusion, and it is not a contradiction to be scored. It is hedging, and hedges tell you where the margin is. The card networks can see the same thing everyone else can: if machine-to-machine traffic becomes a real billing layer, the party that owns identity and dispute resolution keeps the pricing power, and the party that only moves bytes does not.

The number that is not in the press release
x402.org publishes a rolling 30-day counter. Read this weekend, it showed 75.41 million transactions, $24.24 million of volume, 94,060 buyers and about 22,000 sellers. Divide the first two numbers and you get an average payment of roughly 32 cents.
That single figure tells you what this standard is for today. It is not retail checkout; a retail basket averages two orders of magnitude more than that. It is per-call metering. An agent pays for an API request, a data lookup, a page of inference, a market quote. Money at the resolution of a function call.
Which means every “x402 versus Visa” comparison you have read this month is a category error. Those two meet at the merchant’s cash register, not at the layer where this traffic actually lives.
It also means the forty-company membership list is worth roughly what you paid for it. A logo on a foundation page is not adoption. Visa does not need x402 to process a card payment. It joined because the settlement layer of agent traffic is worth owning if it turns out to matter, and a seat at the table is cheap. Watch the transaction counter, not the announcements.
Five questions before you wire anything
1. Which layer is your problem actually on?
Are you charging for a machine-readable service – a call, a query, a slice of inference? Then your problem is metering, and you belong on the settlement layer. Are you taking money for something a human will complain about later – a physical good, a subscription, a delivery that arrives damaged? Then your problem is authorization and accountability, and no payment channel will solve it for you. Do not ask one layer to fix the other’s problem; that is how you end up with signed mandates guarding a 30-cent API call nobody will ever dispute.
2. What does integration cost you in people?
x402’s pitch is one line of middleware. AP2 asks you to reason about signed intents, cart mandates and verifiable credentials. ACP asks you to expose a checkout session and delegate payment credentials to an agent you do not control. None of this is inherently right or wrong. The question is whether the guarantee you get back is worth the code you will now maintain for years. Software is 80% maintenance cost. If a standard needs a specialist defending field mappings until 2030, the standard failed – however elegant the cryptography.
3. Who governs it, and can you leave?
One of the six sits under vendor-neutral foundation governance with a formal process. One was donated to a standards body. Four are controlled by the company that benefits most from them. Neutral governance is not ideology; it is insurance. It is the difference between a protocol you can build a business on and a protocol whose terms and pricing can be rewritten in one board meeting.
And do not mistake a long member list for neutrality. Read who chairs the working groups. Members buy optionality; chairs set the defaults.
4. What does it cost you to change your mind in six months?
Standards this young will churn, and pretending otherwise is the expensive mistake. Design for it now: keep the “who gets paid, and how” decision behind one interface; implement two rails where the protocol makes it cheap, since x402’s accepts field is literally a list of networks and schemes you can extend; never let a checkout flow hard-depend on a single vendor’s session object. That is not architecture for its own sake. It is how you refuse to pay interest on a decision you are not yet equipped to make well.
5. Where do your users actually hold money?
Card networks are the default in North America and Europe. Stablecoins do real volume in markets where dollar access is scarce, which is a large share of the world that is not on your conference panel. The heuristic “global mainstream beats regional cleverness” is usually right – but only after you have defined mainstream for your own users rather than borrowing someone else’s definition.
You are not choosing one. You are choosing a layer.
The workable stack, today, is three separate decisions:
- Discovery and authorization: how an agent finds your offer and proves it carries a human’s mandate. UCP, AP2, ACP and the card networks’ agent directories all fight here, and this is where the payments politics live.
- Checkout and guarantees: who carries the dispute, the chargeback and the refund. For now, that answer is still mostly a card network or a processor, and it will stay that way until someone is willing to underwrite agent mistakes.
- Settlement: how value actually moves at the speed of the request. This is x402’s territory – stablecoins, Lightning, and, on paper, cards.
Decouple those three in your own code and you can change your mind one layer at a time. Try instead to support all six protocols behind one grand abstraction, and you will have built the worst version of all six. That is the classic outcome: you pay the full cost of inventing something, and collect none of the network effect of adopting it.

Where this reading could be wrong
Standards do not win on merit. VHS beat Betamax; the technically tidier option lost to the cheaper ecosystem. So take the confident part of this essay with the usual discount. My working guess is that the settlement layer grows with machine traffic, because machines do not care about brand, while the authorization layer consolidates around whoever can hand merchants a liability shield. Compliance budgets are larger than developer budgets, and that asymmetry usually decides these fights – which is an argument for AP2’s mandate model, not against it.
I am also, by temperament, a conservative reader of AI-era claims, so treat my skepticism as a bias rather than a finding. A year of agentic-commerce forecasts has produced an average payment of 32 cents. That is not nothing: 75 million of them in a month is a real workload, and real revenue for whoever is collecting it. But it is not the checkout revolution either, and any roadmap that assumes it will be by next quarter should be marked down hard.
The short checklist
- Name the layer you are solving for, and write it down before you evaluate any protocol.
- If you sell anything machine-readable, a 402 endpoint is the cheapest revenue experiment available to you this quarter. Meter first, argue later.
- Keep authorization and settlement behind separate interfaces, even if you only implement one today.
- Judge each standard by its governance and its exit cost, not by its member logos.
- Track transaction counters. When x402’s average payment climbs from 32 cents toward double digits, the retail fight has actually started – and the answer to question one will have changed.
Block plugging Lightning into someone else’s protocol is a good signal for exactly one reason: a company with its own payments network chose to interoperate instead of inventing a ninth standard. Lightning itself has been in production since 2018, and it is being adopted now not because it is new but because a payer finally showed up who wants what it is good at: tiny, fast, final.
Give this layer a year of real traffic before you give it your architecture. That is the whole advice, and it is the same advice that has worked through every standards war I have watched.






