# ACP, AP2 and x402 are three layers of one stack, not three rivals

Published: 2026-08-30T19:00:58.825Z · Source: Agentic Commerce Protocol (https://www.agenticcommerce.dev/)
Source date: 2026-08-30
Flags: wire analysis of the protocols' own published documentation, fetched 2026-08-30 — adoption figures are self-reported by each project
Entities: openai, google, cloudflare

An agent arriving at a site raises three questions in order: who are you, may you read this, and may you buy. Each has acquired its own protocol, its own backer, and — in the third case — a reputation for a standards war that the documentation does not support.

Who are you. Web Bot Auth is the identity layer, and its status is the most interesting thing about it. The IETF working group is active with an approved charter and no adopted documents; its deliverables are targeted at the IESG for April and August 2026. Meanwhile the signatures are already being verified in production at the edge. It is shipping ahead of the standard rather than after it, which is the reverse of how this usually goes and worth watching, because a de facto implementation that predates the spec tends to become the spec.

May you read this. This is the layer the wire has covered closely. Cloudflare's three classifications — Search, Agent, Training, defined by behavior rather than by company — become defaults on September 15 for new domains, blocking Training and Agent on ad-bearing pages.

May you buy. Here are the three that get written up as rivals. Their own documentation says otherwise.

ACP — the Agentic Commerce Protocol, developed by Stripe and OpenAI, Apache 2.0 — standardizes checkout initiation: how an agent starts a purchase with a merchant, across physical goods, digital goods, subscriptions and asynchronous purchases. ChatGPT is the first AI platform to implement it; Stripe is the first compatible payment service provider, via a Shared Payment Token.

AP2 — the Agent Payments Protocol, published by Google, Apache 2.0 — standardizes authorization and accountability. Its stated problems are verifying that a user actually authorized the agent, establishing that a request is authentic, and fixing accountability across participants when something goes wrong. Standardization work continues through the FIDO Alliance's Agentic Authentication and Payments working groups, and its documentation situates itself alongside A2A, the Universal Commerce Protocol and MCP rather than against them.

x402 — published by the x402 Foundation — standardizes settlement, by using the HTTP status code that has sat reserved since 1997. A server that receives a request without payment answers 402 Payment Required with a price, and the client pays and retries. Its site reports 75.41M transactions, $24.24M in volume, 94.06K buyers and 22K sellers over the preceding thirty days, and lists adopters including AWS, Cloudflare, Stripe and Vercel.

Checkout, authorization, settlement. Three problems, three protocols, one transaction. The clearest evidence that they compose rather than compete is that Stripe co-authors ACP and also appears on x402's own list of adopters. A merchant is not choosing between them in the way "standards war" implies.

Two cautions on the numbers. Every adoption figure above is self-reported by the project publishing it, and none has been independently audited. And AP2's own documentation names no commercial partners at all — secondary coverage citing sixty-plus named backers is not sourced to anything AP2 publishes. Where a protocol's own site is silent, this item is silent.

Why this has been missing from the record. The wire has covered the answer layer — who gets cited, and by which engine — item by item for months. The agent layer has been almost absent, and the gap is not academic: the same companies already on this beat are writing the rails that decide whether an agent can identify itself, reach a page, or pay for what it finds. Cloudflare's Agent Readiness diagnostic names fifteen standards in this territory. This item covers four of them.

Why it matters: The wire has covered the answer layer — who gets cited — thoroughly, and the agent layer barely at all, while the protocols deciding whether an agent may identify itself, read a page, or pay for it were being written and shipped.

## What this answers

**What is the difference between ACP, AP2 and x402?**

They solve different problems in the same transaction. ACP (Stripe and OpenAI, Apache 2.0) standardizes how an agent initiates checkout with a merchant. AP2 (Google, Apache 2.0) standardizes authorization — proving a user actually authorized the agent, and establishing accountability. x402 (x402 Foundation) standardizes settlement, using HTTP's 402 Payment Required so a server can answer with a price instead of a rejection.

**Are the agentic commerce protocols competing standards?**

Not on their own documentation. They sit at different layers of one stack — checkout, authorization, settlement — and compose rather than exclude. Stripe co-authors ACP and also appears on x402's list of adopters, which is the clearest evidence they are not alternatives.

**Is Web Bot Auth a standard yet?**

No. The IETF working group is active and its charter is approved, but it has no adopted documents and its deliverables are targeted at the IESG for April and August 2026. It is already being verified in production by major infrastructure providers, so it is shipping ahead of the standard rather than after it.


Canonical: https://anythingengineoptimization.com/item/2026-08-30-acp-ap2-and-x402-are-three-layers-of-one-stack-not-three-rivals/
From Anything Engine Optimization (AEO Wire) — https://anythingengineoptimization.com/ · Standards: https://anythingengineoptimization.com/standards/
