OceanAltOceanAlt

Google AP2 · Agent Payments Protocol

L1Public information

授权 / mandate 协议层

A Google-led agent payments protocol. It binds a payment to a user-signed authorized intent using verifiable credentials and 'mandates' (intent mandate, cart mandate), and is payment-method agnostic (cards, stablecoins, etc.). It mainly answers: does this agent have authority to pay, and is it paying the user's real intent.

https://ap2-protocol.org

Share:XLinkedInFacebookTelegramWhatsAppWeibo

Conflict-of-interest disclosure

OceanAlt is itself building a compliance and trust layer for agent payments (the RAP framework + the mcp-pay reference implementation), which places it in a competing position at the 'compliance layer' relative to this protocol. This rating addresses only the protocol's public design boundaries and is based on public specs and reporting; please note we have a stake in the view that 'the protocol leaves compliance open,' and verify against the original spec yourself.

Pillar scores

Weighted score 44/100

0–3 per pillar. The total is a sorting aid only; the grade is set by human review. See the methodology

  • Mandate & limits2weight 21
  • Attribution1weight 26
  • AML screening0weight 16
  • Firewall1weight 21
  • Privacy2weight 4
  • Interoperability2weight 6
  • Auditability2weight 11

L1 = LimitedIdentity or compliance is claimed, but enforcement is weak

Strengths & gaps

Strengths

  • +Mandate/intent authorization is the core — it can cryptographically prove the payment matches what was authorized (strong on authorization)
  • +Verifiable credentials give an auditable authorization trail
  • +Payment-method agnostic; not locked to one rail

Gaps

  • No pre-settlement compliance firewall (no AML/sanctions screening = 0)
  • Attribution answers 'was it authorized', but the accountable entity/KYA still relies on an upstream identity system
  • Open spec, but Google-led — governance neutrality remains to be seen

What we actually verified

协议层(非合规主体):本评级仅反映协议设计能力,不构成合规等级。协议在授权/意图侧表现较强,但结算前合规与 AML 模块留白。分数供横向参考,需人工核验。

  • ·E2 · AP2 public spec and reference implementation (GitHub)
  • ·E4 · Launch and ecosystem coverage is secondary
  • ·Scores are OceanAlt's preliminary read of public docs; not tested by us (no E1)

The subject's response

We have not received a response. If you represent this party, you may submit a factual dispute or supporting material; we will re-review and publish your reply verbatim here. Submit a response →

Rating history

First rating; no changes yet. Every subsequent grade change will be logged here with the before, the after and the reason. Past ratings are never erased.

Last updated 2026-08-18|Methodology v0.3

This profile is a preliminary assessment. It is not legal, compliance or investment advice, and it is not a final verdict on this party. If you find a factual error or stale data, request a re-review — the outcome will be published.