{"data":[{"id":"ap2","name":"AP2","plainRole":"Signed mandate and accountability layer for agent commerce","protocolSupport":["ap2","mcp"],"controlSurfaces":["agent","wallet","merchant","credential-provider"],"settlementRails":["card","stablecoin","bank","deferred"],"authorizationModel":["signed-mandate","proof-of-intent","merchant-authorization"],"custodyModel":"rail-dependent","autonomyLevel":3,"mandateLoggingRisk":"medium","revocationQuality":"partial","metadataPath":["user","agent","intent mandate","merchant","payment credential","wallet or payment rail","receipt"],"privacyWarning":"AP2 is useful for proving user intent. It is not privacy by itself: mandates, merchants, wallets, issuers, and receipts can still describe what the user wanted and bought.","bestUse":"Commerce where the agent should prove authority without receiving broad card or wallet control.","sourceLinks":[{"label":"Google AP2 announcement","href":"https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol"},{"label":"AP2 protocol docs","href":"https://ap2-protocol.org/"},{"label":"AP2 GitHub","href":"https://github.com/google-agentic-commerce/AP2"}],"lastReviewed":"2026-08-21"},{"id":"mcp","name":"MCP","plainRole":"Tool protocol that can expose payment or card controls to an AI client","protocolSupport":["mcp"],"controlSurfaces":["mcp-server","mcp-client","tool-call"],"settlementRails":["card","crypto","bank","gift-card","unknown"],"authorizationModel":["account-permission","api-key","tool-grant","human-approval"],"custodyModel":"tool-dependent","autonomyLevel":3,"mandateLoggingRisk":"high","revocationQuality":"partial","metadataPath":["AI host","MCP client","MCP server","provider API","payment rail","tool-call logs"],"privacyWarning":"MCP is not a payment rail. It is a tool surface. When that tool controls cards or wallets, prompts, tool-call logs, account scopes, and provider API logs become part of the money trail.","bestUse":"Operator-approved card or account controls where tool scopes are narrow and revocation is tested.","sourceLinks":[{"label":"Anthropic MCP announcement","href":"https://www.anthropic.com/news/model-context-protocol"},{"label":"MCP specification","href":"https://modelcontextprotocol.io/specification/2025-06-18"},{"label":"Privacy.com MCP","href":"https://www.privacy.com/blog/privacy-mcp-connect-ai-assistant-privacy-account"}],"lastReviewed":"2026-08-21"},{"id":"mpp","name":"MPP","plainRole":"Machine Payments Protocol for payment in the same HTTP request","protocolSupport":["mpp","x402"],"controlSurfaces":["http","agent","payment-session"],"settlementRails":["card","stablecoin","lightning","deferred"],"authorizationModel":["payment-authentication-scheme","session-budget","wallet-or-processor-approval"],"custodyModel":"processor-or-wallet-dependent","autonomyLevel":4,"mandateLoggingRisk":"high","revocationQuality":"partial","metadataPath":["agent/client","paid service","MPP payment header","processor or wallet","settlement rail","service access log"],"privacyWarning":"MPP is rail-agnostic and useful for agent payments, but sessions and paid requests can still create a precise machine-use history.","bestUse":"Pay-as-you-go or streaming agent services with tiny balances, isolated clients, and short sessions.","sourceLinks":[{"label":"Stripe MPP announcement","href":"https://stripe.com/blog/machine-payments-protocol"},{"label":"MPP overview","href":"https://mpp.dev/overview"},{"label":"Cloudflare MPP docs","href":"https://developers.cloudflare.com/agents/tools/payments/mpp/"}],"lastReviewed":"2026-08-21"},{"id":"tap","name":"TAP","plainRole":"Trusted agent identity signal for agent commerce","protocolSupport":["tap"],"controlSurfaces":["agent","merchant","visa-network"],"settlementRails":["card"],"authorizationModel":["agent-signature"],"custodyModel":"rail-dependent","autonomyLevel":3,"mandateLoggingRisk":"high","revocationQuality":"partial","metadataPath":["agent","agent-specific cryptographic signature","merchant","consumer recognition","optional payment information","Visa network or merchant records"],"privacyWarning":"TAP can help merchants distinguish agents from ordinary browsers. Its agent signature, consumer-recognition data, and optional payment information can still become a durable agent-commerce record.","bestUse":"Merchant acceptance and agent-verification workflows where agent identity is needed and user privacy cost is understood.","sourceLinks":[{"label":"Visa TAP announcement","href":"https://corporate.visa.com/en/sites/visa-perspectives/newsroom/visa-unveils-trusted-agent-protocol-for-ai-commerce.html"}],"lastReviewed":"2026-08-21"},{"id":"x402","name":"x402","plainRole":"HTTP 402 payment challenge and retry flow","protocolSupport":["x402"],"controlSurfaces":["http","sdk","facilitator"],"settlementRails":["stablecoin","crypto"],"authorizationModel":["payment-challenge","wallet-signature","facilitator-verification"],"custodyModel":"wallet-dependent","autonomyLevel":4,"mandateLoggingRisk":"high","revocationQuality":"weak","metadataPath":["agent/client","paid endpoint","402 challenge","wallet","facilitator","chain or settlement network","merchant access log"],"privacyWarning":"x402 can make paid API access clean, but every paid request can expose endpoint, amount, recipient, timing, wallet, facilitator, retry, and access-log metadata.","bestUse":"Low-balance, task-specific API or crawler access where the wallet is not reused across identities.","sourceLinks":[{"label":"x402 protocol site","href":"https://www.x402.org/"},{"label":"Coinbase x402 docs","href":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Coinbase facilitator docs","href":"https://docs.cdp.coinbase.com/x402/seller/facilitator"}],"lastReviewed":"2026-08-21"}],"meta":{"total":5,"api_version":"1.2","powered_by":"cunicula.com","documentation_url":"https://cunicula.com/en/api-docs","machine_index_url":"https://cunicula.com/llms.txt","license":"LicenseRef-Cunicula-Attribution-1.0","license_url":"https://cunicula.com/en/cite","attribution":"Cunicula, \"{name}\", cunicula.com, reviewed {reviewed}, retrieved {retrieved}, {url}","cite_guide_url":"https://cunicula.com/en/cite","dataset_url":"https://cunicula.com/api/v1/dataset","schema_version":"1.1.0","filters":{}}}