Payments for AI agents: open rails, one network
x402, MPP, AP2, ACP and stablecoin wallets: why agents should not have to know which rail their counterparty accepts, and how Tenzro settles them all.
Agents do not transact with one kind of counterparty. A research agent might pay an API per request in a stablecoin, pay a model provider per token, work within a spending mandate its owner signed, and buy from a merchant through an agent-commerce checkout, all in the same task.
No single payment protocol covers that. Tenzro supports the open rails agents use and settles them on one ledger, under one identity and one set of spending limits.
x402 and MPP: HTTP 402 for machines
Both protocols use HTTP 402 Payment Required as the gate. A model API, a compute endpoint or any other resource answers a request with 402 and a payment challenge. The agent's wallet signs a payment bound to its identity, retries the request, and gets the resource with a receipt.
- x402 is stateless and one-shot, which suits pay-per-request calls. Payments can use EIP-3009
transferWithAuthorization, so the payer signs and a facilitator submits. See x402. - MPP adds sessions on top of the challenge, credential and receipt flow, which suits streaming responses billed as they are produced. See MPP.
On Network 1 the OpenAI-compatible inference routes accept either an API key or payment per request over HTTP 402, so an agent with a funded wallet can call a model without signing up for anything.
AP2 mandates
AP2 adds structured commitments: a signed mandate that pre-authorises a specific purchase up to a maximum amount before an expiry. Before a mandate settles, three independent ceilings must pass:
- The mandate's own constraints, such as the items and the maximum amount.
- The delegation scope on the agent's identity: maximum value, allowed operations and a time bound.
- The runtime spending policy: per-transaction and rolling daily limits.
The mandate hash is bound to the agent's DID, and a nonce prevents replay.
Agent commerce with ACP
For purchases through agent-commerce checkouts, Tenzro implements the buyer side of ACP. An agent can complete a checkout on behalf of its owner, under the same delegation scope and spending limits as any other payment. See Agent commerce.
Stablecoins and gas
Agents and the businesses behind them often hold stablecoins. Stablecoin payments run through Bridge.xyz wallets, x402 and MPP, and gas can be paid in stablecoins through the same rails, so an agent does not need to hold TNZO just to transact. TNZO remains the token that pays network fees and settlement underneath. See Stablecoin payments.
Metered settlement, channels and escrow
Settling every token of an inference response on chain one at a time would be wasteful. Settlement on Network 1 is metered per use by default: the network records what was consumed and settles it, so buyers pay for exactly what they used.
For high-volume flows between two parties, micropayment channels let the payer and provider exchange signed balance updates off chain and close the channel to the ledger with the latest signed state. For higher-value coordination, such as bonds and expiring offers, the ledger provides an escrow primitive that only the payer can release or refund. See Settlement.
Defence in depth
Every payment passes through independent limits: the protocol's own constraints, the delegation scope on the agent's identity, and the runtime spending policy. On top of that, ERC-7579 validator modules on the agent's smart account check each operation at signing time, so an agent that skips an off-chain check is still stopped on chain. And anything that moves money needs a signature from the account that pays.