← Back to blog

How do AI agents actually pay publishers?

Four competing standards now exist for letting software pay for a resource without a human at the checkout: Google's AP2, OpenAI and Stripe's ACP, Stripe and Tempo's MPP, and x402. Only one of them settles in public, and blockchain analysts at TRM Labs found that agents move roughly 5,000 to 11,000 US dollars a month across it. The plumbing is real. The money is not there yet.


Picture the exchange a publisher is being asked to prepare for. A piece of software requests a page. The server answers not with the page but with an HTTP 402 status, a price and instructions for paying it. The software signs an authorisation, sends the request again with proof attached, an intermediary verifies the proof and broadcasts the settlement, and the page is released. No card, no invoice, no person. That handshake is what every agent payment standard is trying to formalise, and the reason publishers should care about the detail is that the four leading versions of it disagree about who authorises the payment, what it settles in, and whether the publisher ever learns who paid.

The four standards competing to move money between machines

TRM Labs, the blockchain intelligence firm, set out the field in a technical analysis published on 9 September 2026, and its four-way split is the clearest map available.

AP2, Google's Agent Payments Protocol, is the authorisation layer. It gives an agent a cryptographically signed mandate from a human before it can spend on that human's behalf. Google announced it on 16 September 2025 with more than sixty payments and technology partners including PayPal, Mastercard, American Express, Adyen and Coinbase. On 28 April 2026 Google donated the protocol to the FIDO Alliance and released version 0.2, which adds "Human Not Present" transactions, meaning an agent can execute a pre-authorised payment with nobody in the loop at the moment of purchase. The FIDO Alliance stood up two technical working groups the same day, one on agentic authentication and one on payments.

ACP, the Agentic Commerce Protocol from OpenAI and Stripe, connects assistants to merchants so a purchase completes inside a conversation. It is aimed at retail checkout rather than at content.

MPP, the Machine Payments Protocol from Stripe and Tempo, launched on 18 March 2026 alongside the Tempo mainnet, a payments blockchain built with Paradigm. Its distinguishing idea is a sessions primitive: an agent authorises a spending limit once and then streams micropayments against it without an on-chain transaction for every interaction. Businesses accept MPP payments through Stripe's existing PaymentIntents API, in stablecoins or in fiat.

x402 is the one described at the top of this article. It revives the dormant 402 Payment Required status code and makes payment part of the web request itself. Its governance moved to the Linux Foundation, whose x402 Foundation launched operationally on 14 July 2026 with 40 member organisations. Adyen, Amazon Web Services, American Express, Circle, Cloudflare, Coinbase, Fiserv, Google, Mastercard, Ripple, Shopify, Stripe and Visa sit in the premier tier.

For a publisher, only x402 and MPP are designed for the transaction that matters, which is paying for a piece of content or an API call rather than buying a physical product. AP2 sits underneath any of them as an authorisation format.

What the only visible rail shows about real agent spending

x402 is the one standard whose entire volume is observable, because it settles on public blockchains. That makes it the only place where the promise of agentic commerce can be checked against the record, and TRM Labs checked it.

Across Base, Solana and Polygon, TRM identified roughly 52.7 million US dollars across 198.9 million settlement transactions mediated by known x402 facilitators since May 2025. That headline is the number usually quoted. The analysis then does something more useful with it.

Nothing in the protocol requires an agent. As TRM puts it, "Scheduled jobs, load tests, self-dealing, and ordinary automation all look the same as an agent from the chain's point of view." So the firm applied three screens: remove addresses paying themselves, remove bulk flows from one or two payers, and remove sellers with fewer than ten distinct buyers. About half the volume fell away, leaving 25.62 million US dollars of screened commerce.

Against that screened figure, TRM ran a permissive test and a strict test for whether a payer was plausibly an agent. The share that appears agentic came out at between 0.6 and 7.5 per cent. The firm is candid that the modelling may understate the population, because its test treats an address repeating a fixed price as a script rather than an agent, and many real agents today are single-purpose.

The most concrete number in the analysis is the smallest one. The count of agents transacting on x402 rose through spring 2026 to a mid-year peak and then fell back, "while the volume they move has stayed small, roughly USD 5,000-11,000 a month". That is total monthly agent spending across the most widely adopted agent payment rail on the internet. It is not a publisher-addressable market.

One further finding matters for anyone building a treasury process around this. Of 52.68 million US dollars settled, 52.47 million, or 99.6 per cent, settled in USDC, and nearly every merchant in TRM's catalogue names USDC as the asset it wants to receive. The agent payment economy on public rails is currently a stablecoin economy, whatever the fiat bridges promise.

What the infrastructure vendors have actually shipped

The gap between announcement and availability is wide, and publishers evaluating these products should read the tense of the marketing carefully.

Cloudflare announced its Monetization Gateway on 1 July 2026, opening a waitlist rather than a product. It lets a Cloudflare customer charge for pages, datasets, APIs or MCP tools, with payments settling in stablecoins over x402 and funds landing in the seller's wallet rather than routing through a processor. Cloudflare has not published pricing or a general availability date. Treat it as a preview.

Cloudflare announced Wallets on 4 August 2026, during its Agents Week. The design is sensible: an Account Wallet held by a human delegates capped spend to Virtual Wallets operated by agents through API keys, governed by "an allowance, an allow list, and a maximum transaction size", with anomalous spending escalating to a human for review. An optional cloudflare.pay handle lets an agent identify which account it acts for, layered over Web Bot Auth keypairs. But almost all of it is written in the future tense. What went live that day was the ability to claim a handle. Cloudflare's own words are that "Soon, you will be able to set up and use your Cloudflare Wallet to pay for APIs and content." The post names no stablecoin, no chain, no supported geographies, no launch partner and no date, and it gates self-funding to "eligible users".

Cloudflare's own framing of the division of labour is the clearest statement of what a two-sided agent economy requires: the Monetization Gateway is how sellers get paid without building payment infrastructure, Wallets are how buyers pay headlessly, and identity is how merchants decide whom to transact with. All three have to exist at once. Today the seller side is a waitlist and the buyer side is a handle.

Why a publisher may never learn who paid

TRM's section on attribution is the part publishers should read twice, because it describes a control environment that does not yet exist.

Ownership claims are unverified. On-chain agent registries let a person declare ownership of an agent address, but the declaration is voluntary and, in TRM's assessment, "currently not utilized by the majority of participants". No human approves the payment: the agent signs, a facilitator broadcasts, and there is no review step in between, so any control that assumes a human decision has nowhere to sit. And value and volume decouple, because these payments fall below nearly every value threshold and above nearly every count threshold at once.

The practical consequence for a publisher is that an agent payment arrives as a settlement from an address, not as revenue from a named counterparty. A publisher cannot invoice it, cannot apply differential pricing to it by buyer, cannot exclude a buyer it has a licensing dispute with, and cannot reconcile it against a contract. Everything the industry has built for knowing who it is selling to assumes a named commercial relationship. Crawler identity verification through Web Bot Auth helps at the access layer, but it is a separate mechanism from the payment and the two are not yet joined.

What a publisher needs in place to be payable

The single most useful line in TRM's analysis is aimed at merchants rather than at the crypto industry: "For a merchant, the headline volume of an agent-payment channel is mostly not customers, and attracting agent traffic takes a different design. It needs to be machine-readable and have per-call pricing on an endpoint a buyer can discover without a human ever seeing the page."

Read as a publisher checklist, that is four requirements, and none of them is a wallet.

A discoverable endpoint. An agent that cannot find a priced resource without rendering a page will not buy one. That means the price and the terms have to be expressed in the response, not on a rate card behind a sales team.

Per-call pricing. Not an annual licence, not a negotiated minimum, but a price attached to the unit being fetched.

Machine-readable terms. The buyer is software and will not read a PDF.

An identity and settlement path you can reconcile. This is the one no current rail supplies.

Everything above is an access-layer decision, which is why the rails question sits downstream of the pricing question rather than replacing it. Setting a price per crawl is the prior problem, and choosing the unit you sell determines what you can even ask a rail to settle.

Why none of this answers the revenue question yet

There is a temptation to read four standards, a Linux Foundation, a FIDO Alliance working group and thirteen premier members of the payments industry as evidence that money is about to arrive. The record says otherwise. The most adopted rail is moving five figures a month in genuinely agentic volume. The seller-side products at the largest CDN are on a waitlist. The only settled asset is a stablecoin most publisher finance teams cannot yet hold.

That does not make the work pointless. Rails get built before volume, and a publisher that makes its content machine-discoverable and per-call priced has done work that pays off under any of the four standards. But it does mean agent payment rails should be treated as an option being prepared rather than a line in next year's budget.

It also explains why the monetisation approaches that already clear money do not touch these rails at all. blankspace settles on the publisher's own logs: an impression served into the retrieval moment at the CDN edge, recorded where the publisher can count it, paid for by an advertiser through the existing advertising settlement chain. No wallet, no stablecoin, no unidentified counterparty. That is a different transaction from selling access to a crawler and it does not substitute for a licensing position. It is simply one that does not depend on the buyer having a funded agent.

Frequently asked questions

What is x402?

x402 is an open payment standard that puts a price into an ordinary web request. When software asks for a resource, the server can answer with the HTTP 402 Payment Required status code, a price and payment instructions. The buyer retries with a signed authorisation, a facilitator verifies it and broadcasts the settlement on-chain, and the server releases the resource. Governance sits with the x402 Foundation, which launched operationally under the Linux Foundation on 14 July 2026 with 40 members.

How much are AI agents actually spending?

Very little, on the evidence available. TRM Labs analysed all x402 settlements across Base, Solana and Polygon since May 2025, roughly 52.7 million US dollars across 198.9 million transactions, and estimated that between 0.6 and 7.5 per cent of screened commerce appears genuinely agentic. Monthly volume attributable to agents ran at roughly 5,000 to 11,000 US dollars. Most of the headline figure is ordinary automation, self-payment or speculation rather than agents buying things.

What is the difference between AP2 and x402?

They solve different problems and can be used together. AP2 is an authorisation format: it proves that a human gave an agent permission to spend, and to what limit. x402 is a settlement mechanism: it moves the money as part of the web request. AP2 answers "is this agent allowed to pay", x402 answers "how does the payment reach the seller". Google donated AP2 to the FIDO Alliance on 28 April 2026.

Can a publisher accept agent payments today?

Only in a limited way. Cloudflare's Monetization Gateway, which would let a site charge for any resource behind Cloudflare via x402, opened a waitlist on 1 July 2026 and has no published general availability date or pricing. Cloudflare Wallets, announced on 4 August 2026, currently allows a customer to claim a payment handle, with the wallet itself described as coming soon. A technically capable publisher can implement x402 directly, but it will need somewhere to hold stablecoins.

Will agent payments replace advertising revenue for publishers?

Nothing in the current data supports that. Agent payment rails address a different transaction, which is charging a machine for access to a resource, and the total money moving through the most adopted rail is smaller than a single mid-sized publisher's monthly advertising revenue. The realistic near-term position is that agent payments become one line among several, alongside licensing, advertising into AI retrieval, and conventional display, rather than a replacement for any of them.