Agentic Payments: The Agent Pays, You Still Pick
Cicero Campelo, CISSP
October 6, 2026 · 14 min read
Part of our guide to AI for startups.

Table of contents
- Agentic shopping and agentic payments are two different bets
- Why the payment half is the one with room
- How an agent actually pays: HTTP 402 and the Machine Payments Protocol
- Payments has no consolation prizes: critical mass or nothing
- The blocker is trust, and trust has a shape
- Grocery delivery already normalized delegated buying
- Where an agentic payments startup gets a wedge
- What to do this week
- Sources
- Frequently asked questions
Most agentic commerce demos answer a question nobody has a trust problem with. They show an agent picking a product. The hard part was never the picking.
Agentic payments are transactions an AI agent initiates and authorizes on your behalf, instead of you completing them at a checkout screen. That is a different bet from agentic shopping, which is an agent deciding what to buy, and only one of the two is close to working.
That is the argument two people who have each spent more than two decades building payments companies made on a16z's podcast, and it cuts against most of what is currently being funded. Max Levchin co-founded PayPal, served as its chief technology officer until eBay bought it in 2002, and is now founder, chairman and chief executive of Affirm. Alex Rampell co-founded Affirm with him, co-founded TrialPay before that (Visa announced it was acquiring TrialPay in February 2015), and is now a general partner at Andreessen Horowitz.
Their split is clean, and Levchin states it in one line: he is "probably less optimistic about agentic shopping" and very optimistic about agentic payments.
Agentic shopping and agentic payments are two different bets
Levchin's case against the shopping half is about what people actually want to delegate.
the notion of robots will buy our Friday night outfits is misguided. We want to know what we look like long before the robot delivers it to your door.
His own example is bike parts. He says he spends far too long comparing two nearly identical components, because he wants to participate in that purchase. The agent adds nothing there.
The payment step is the opposite:
the best user interface ever created is the credit card. This may actually be finally up for renegotiation because agents are in fact smarter than pieces of plastic
Rampell pushes back partway, and the refinement is the useful part. He splits the flow at the point where you know the SKU. Before that, AI is one input among several, no different from asking a friend. After that, you have the exact part number and you do not care which of 19 sellers you get it from. His framing of the two customers: "you have people that care more about money than time. You have people that care more about time than money." The first group already does this work by hand on price-tracking sites. The agentic version is "Go buy it for me at the lowest cost."
So the delegable zone sits between "I know what I want" and "it is paid for". That is a narrow slice, and it is also the slice with the clearest instruction set, which is why it is the one that works first. If you are designing for agents as users of your product rather than just as buyers, the broader surface is covered in agent experience.
Why the payment half is the one with room
Three observations from the conversation explain why this slice is worth a company.
The first is Levchin's: there is no small niche in payments. Every subdivision of it that looks like a toy turns out to be worth more than 100 billion dollars. He calls that the most surprising thing he has seen in the industry.
The second is Rampell's inversion, and it is the one founders get backwards: "once you go really big, the numbers get small, which is strange." The revenue is not where the dollars are. It is where the transactions are:
there's a lot of volume, but the large volume revenue opportunities and payments tend to be the smaller dollar amounts
Nobody earns 2 percent on a 40 trillion dollar wire. They earn it on coffee. And the behavioral rule that governs the coffee end is Levchin's:
convenience just trumps everything else as the total amount you're trying to send goes down
Put those three together and the target gets specific. High frequency, low ticket, convenience-dominated flows. Which is exactly the shape of what an agent does: many small purchases, repeatedly, where the friction removed matters more than the price optimized.
How an agent actually pays: HTTP 402 and the Machine Payments Protocol
The rails for this are not a thought experiment any more, but they are new enough that most people arguing about agentic commerce have not read them.
Will Gaybrick, Stripe's president of technology and business, described the state of play on the same show with a16z general partner David George, and he is notably unwilling to oversell it. His summary: "we're sort of at the missing primitives phase."
What has shipped is worth knowing by name. Stripe and Tempo published the Machine Payments Protocol in March 2026. It uses HTTP 402 Payment Required, a status code that sat unused in the spec for decades. An agent asks for a resource, the server returns 402 with what it costs and how to pay, the agent authorizes and retries with a credential. Gaybrick's description of the server side is the clearest statement of the design: you return a 402 and "it just says like here's how you buy me." The protocol supports pre-authorized session spending limits, so an agent running a long task does not settle every request individually, and its rails include stablecoins on Tempo, fiat through shared payment tokens, and Bitcoin Lightning. Coinbase's x402 covers adjacent ground, and Cloudflare documents both for agents running on its platform.
Gaybrick separates two versions of agent checkout. The skeuomorphic one has agents crawling human checkout forms with browser automation, which works and is brittle. The native one is the protocol. He expects the human artifact to disappear either way: "checkout pages shouldn't exist for humans."
His other claim is the one most likely to be ignored, and it points away from consumer. He volunteers business to business as one of the places Stripe is most excited, and the examples are not retail: an agent provisioning hosting or a browser-automation service without a human visiting the vendor's site. George said the same thesis now shapes a16z's investing in developer tools, where the test is to "assume that the agents are going to be the shoppers in the future" and ask whether yours is the one they will pick.
That is the live disagreement between the two conversations, and it is a real one rather than a framing difference. Levchin is looking at consumer convenience flows and says the blocker is trust. Gaybrick is looking at machine-to-machine provisioning and says the blocker is primitives. Both are right about their own half, and only one of them describes a market you can sell into this quarter. A B2B agent has no habit to break and no feelings about its wallet. That window is also when category defaults get set, which is the argument in the AI agent economy.
Payments has no consolation prizes: critical mass or nothing
Here is the part that should change how you plan, not just how you think.
Levchin's lesson from watching payment innovations fail is that the outcome distribution has no middle. You either reach critical mass, where everyone needs your thing, or you are gone. There is no modest success.
His examples are specific. A wand on your keychain that paid at the fuel pump, which he saw and assumed would replace credit cards. DigiCash, whose bankruptcy party he attended on Stanford grounds, and whose blind-signature scheme he describes as genuinely brilliant. His own PayPal presentation at a cryptography conference, where he says he was booed off the stage because the design was neither as secure nor as anonymous as what the room wanted. PayPal's actual insight, by his account, was deciding that nobody cared about anonymity.
Why the wand lost is the lesson: it was a little bit faster than the card already in your pocket, not a lot faster. That is the bar.
Add a fresh data point they raise themselves. Amazon's palm-scanning payment, which the people on the podcast say they personally liked and used, is gone: Amazon ended Amazon One for retail including Whole Foods in June 2026, citing limited customer adoption, and deleted the associated biometric data. The on-air post-mortem is funnier and more accurate than most: it was not even faster, it was just fun.
If your agentic payments plan has a scenario where you capture 3 percent of transactions and build a nice business, delete it. That scenario does not exist in this market.
The blocker is trust, and trust has a shape
Levchin's diagnosis of what is actually holding this back is worth sitting with, because it is not a capability claim:
you haven't yet trusted your agent to do as good a job as you would
He is explicit that the AI may already be good enough. The missing piece is that you cannot yet predict how it will handle the judgment calls, like whether to buy the cheapest listing from a seller you have never heard of, and his instinct in that case is to pick the reputable seller over the cheap one.
"Trust" is a vague product requirement, so here is the concrete version. A delegated payment is a delegation of spending authority, and the controls that make any delegated authority safe are well understood:
- A scoped mandate. What the agent may buy, from which categories of seller, within what window. Not an open credential.
- A hard ceiling, per transaction and per period. The protocol work supports this directly through pre-authorized session limits, which is the single most useful thing in it.
- A credential that is not the instrument. A revocable token scoped to the agent, not your card number sitting in a context window. Rotation and revocation have to be one action.
- A receipt that names the agent, and a dispute path. Who authorized this, under which mandate, and how a person undoes it.
The last one is not hypothetical. On Y Combinator's Root Access, the founders of Raindrop, an agent-observability company, gave a failure mode that lands squarely on money: a customer support agent tries to issue a refund, the tool call fails, and the agent reports "Issued your refund." The action did not happen and the transcript says it did. Their stated operating premise is that agents keep getting more capable and the cost of their mistakes keeps rising, and they note that once agentic coding started genuinely working, the guardrails and the permissions came off.
Apply that to payments and the conclusion is blunt: an agent's own report of a transaction is not evidence that the transaction happened. You need the receipt from the rail. Build the ledger before you build the agent. Building that reconciliation loop is the same discipline as AI fraud detection, pointed at your own agent rather than at an attacker.
Grocery delivery already normalized delegated buying
The optimistic half of Levchin's case is an observation nobody markets as AI, and it is the most useful thing in the conversation:
grocery shopping is 100% agentic
You tell an Instacart shopper to bring milk. They substitute a different brand of whole milk and tell you. You say fine. His point:
we are already conditioned to allow some of these purchases to be fully outsourced
The intelligence in that loop is a person rather than a model, and the delegation pattern is identical: a loose instruction, a judgment call on a substitution, a disclosure after the fact, and a correction path. The difference from the Friday night outfit is that milk carries no taste judgment, which is the actual dividing line: low-taste, repeat, substitutable purchases already get delegated end to end. That pattern already has consumer consent. Nobody had to be convinced.
Which does not mean the transfer is fast. Rampell's account of how contactless cards actually won is the correction to anyone modelling smooth adoption, and his premise is that "it's very hard to change consumer behavior in general." Taps did not win because tapping is nicer. A liability shift forced US merchants to replace their terminals or eat the fraud losses, the replacement terminals happened to include contactless, and nobody used the feature at first. His own list of the forces that finally moved the behavior is that terminal swap, the pandemic, and the smartphone in everyone's hand. Not one of the three was aimed at making you tap.
Levchin adds the technical reason the card networks have not moved further. He says Visa and Mastercard operate a hard two-and-a-half-second budget for the round trip between network, issuing bank, merchant and acquirer, which leaves almost no room for anything clever: "once your card is presented two and a half seconds that's all you got." That figure is his, from inside the industry rather than from a published spec. What Apple Pay and Google Pay did, in his telling, was time-shift the work into a secure enclave on the phone so the interesting computation happens before the clock starts. His open complaint is that the networks have still not relaxed the window to allow, for example, multiple issuers to bid on better terms mid-transaction.
For an agentic payments founder that is both a constraint and an opening: the deadline is why agent-native rails are being designed outside the card networks rather than inside them. It also sets the adoption clock, and consumer AI covers where the consumer trust to reset it actually comes from.
Where an agentic payments startup gets a wedge
The most transferable lesson in the whole conversation is about Affirm's own path to product-market fit, and it has nothing to do with payments technology.
Affirm's early product let shoppers pay later. At 1-800-Flowers, where they ran one of the first integrations, it went nowhere: the merchant told them they were cannibalizing credit card volume at a higher rate, which is a fair complaint. Then a cosmetics retailer, Beautylish, changed one thing. Instead of offering the option at checkout, they told shoppers about it while they were still choosing products. Levchin's description of the result:
that had an instant 30% increase in conversion
Same capability, same rail, same economics. Moved earlier in the flow. That is when they understood the product was not solving the problem of your card being in another room, it was solving the problem of a budget.
For anyone building agentic payments, the equivalent question is where in the agent's loop the payment decision surfaces. If the agent asks for authorization at the moment it is about to transact, you are building a checkout button. If the constraint arrives before the agent starts searching, as a budget and a mandate, you are shaping the whole task. Those are different products with the same plumbing.
One more structural note from Rampell, because it changes who you sell to. He argues Affirm's unusual property is negative customer acquisition cost, and that it works because the merchant actively wants Affirm to own the customer relationship. Zynga and Netflix did not want TrialPay owning theirs, by his account. A lender that sends the late-payment notices so the brand does not have to is doing the brand a favor. Ask the same question about your agentic payments product: does the party integrating you want you visible to their customer, or hidden? The answer determines your distribution and your margin. The wider frame for running a company on these decisions is our pillar on AI for startups.
What to do this week
- Classify your use case as shopping or payments. Write one sentence naming which judgment stays with the human. If that sentence ends with the agent deciding what to buy, you are betting against both of the people above, and you should know that you are.
- Read the Machine Payments Protocol docs and return a 402 from one endpoint. An afternoon. You will learn more about what agent checkout needs from one 402 handshake than from a month of reading commentary.
- Write down your four delegation controls. Mandate, ceiling, credential, receipt. Any of the four you are planning to add later is the one that will stop an enterprise deal.
- Compute your frequency, not your volume. Transactions per user per month, and average ticket. If the ticket is large and the frequency is low, Rampell's inversion says your revenue opportunity is smaller than your gross volume suggests.
- Find your B2B version. Name one machine-to-machine purchase your product could make or receive without a human present. That path has no consumer habit to break, and the fintech distribution playbook behind it is in Henrique Dubugras.
- Instrument the ledger before the agent. Reconcile every agent-initiated payment against the rail's own receipt, not the agent's transcript. Assume at least one agent will report a payment it did not make.
- Pressure-test the critical-mass question honestly. Ask what forces adoption rather than what makes adoption pleasant. If the best answer is that your flow is somewhat faster, you are building the fuel-pump wand.
The course is the structured version of this: AI Operating System for Startups covers how to scope what an agent is allowed to do, instrument it, and decide which judgment calls stay with a person.
Sources
- Why AI Agents Could Finally Reinvent the Credit Card (a16z), the conversation between Max Levchin and Alex Rampell that this article distills.
- Tokens Are the New Dollars (a16z), for Will Gaybrick on the missing primitives, HTTP 402, checkout pages and why Stripe's agentic enthusiasm points at business to business, with David George on agents as the shoppers.
- Building the Safety Layer for AI Agents (Y Combinator's Root Access), for the refund failure mode and the premise that the cost of agent mistakes rises with capability.
- Machine Payments Protocol (Stripe), the primary documentation for the 402 flow, session spending limits and settlement options, and Cloudflare's agentic payments docs for the comparison with x402.
- Amazon One's retail shutdown: GeekWire and The Verge.
- Visa's announcement of the TrialPay acquisition (February 2015).
- Profiles: Max Levchin on Wikipedia, Alex Rampell at Andreessen Horowitz, Will Gaybrick at Stripe, and Raindrop on Y Combinator, for current roles and background.
Frequently asked questions
What are agentic payments?
Agentic payments are transactions an AI agent initiates and authorizes on your behalf, rather than ones you complete yourself at a checkout screen. The distinction that matters is against agentic shopping, which is an agent deciding what to buy. Affirm founder and CEO Max Levchin, who co-founded PayPal before that, draws the line between the two explicitly and says he is "probably less optimistic about agentic shopping" and optimistic about the payments half: the taste judgment stays with the person, and the part that gets handed to software is the authorization, the credential and the settlement. In practice that means an agent holding a scoped, revocable spending mandate with a ceiling, not an agent holding your card number.
How do AI agents actually pay for things today?
An AI agent pays one of two ways today, and they are not equally mature. The skeuomorphic route is browser automation: the agent drives a human checkout form with stored credentials, which works and is fragile. The native route is a protocol. Stripe and Tempo published the Machine Payments Protocol in March 2026, which uses the long-dormant HTTP 402 Payment Required status code: an agent requests a resource, the server answers 402 with its payment terms, the agent authorizes and retries. It supports pre-authorized session spending limits so an agent does not settle every request separately, and its rails include stablecoins, fiat through shared payment tokens, and Bitcoin Lightning. Coinbase's x402 covers similar ground. Stripe's president of technology and business Will Gaybrick is candid that this is early, describing the industry as being at "the missing primitives phase."
Why have agentic payments not taken off yet?
Capability is not the constraint. Levchin's read is that the models may already be good enough and the gap is confidence: "you haven't yet trusted your agent to do as good a job as you would." Payments history supports treating that as the hard part rather than a detail. He points out that a new payment method has no middle outcome, it either reaches critical mass or disappears, and the graveyard is full of things that worked technically: contactless key fobs for fuel, DigiCash's anonymous digital cash, and most recently Amazon's palm scanners, which Amazon pulled from Whole Foods and its other retail locations in June 2026 after limited adoption. Being a little bit faster than the thing already in your pocket does not move a habit.
Where can a startup compete in agentic payments?
In three places: business-to-business and machine-to-machine flows, the delegation control plane, and where in the agent's loop the payment decision surfaces. Not against the card networks, and not on building a better shopper. First, business to business and machine to machine flows, which Gaybrick names as one of the places Stripe is most excited, because an agent provisioning hosting or a browser-automation service has no habit to break. Second, the control plane: scoped mandates, spend ceilings, revocation, agent-identified receipts and a dispute path, which every delegated-spend deployment needs and almost nobody ships well. Third, placement rather than rails. Affirm's own product-market fit came from moving its offer earlier in the shopping flow, not from a better checkout button, and where in an agent's loop the payment decision surfaces is the same class of design decision.
Build your AI Operating System
A practical course to grow with AI, build internal tools, and operate safely. Join the waitlist and you'll be first in when the course opens.