Agentic commerce for small business is no longer a conference slogan. It is the name payment networks, processors, and storefront platforms are using for a specific change: an AI agent can discover a product, assemble a cart, and pay—with the shopper’s permission—without pasting a full card number into a chat window.
If you run a US store, a booking app, or a custom checkout, the useful question is not “will agents replace websites?” It is: can a trusted agent complete a purchase on your terms, and can you still own the customer, the fraud decision, and the refund?
This article maps the rails that actually shipped in 2025–2026—Visa Intelligent Commerce, Mastercard Agent Pay, Stripe Shared Payment Tokens, Google’s Agent Payments Protocol, and Shopify’s Universal Commerce Protocol—and translates them into a 90-day plan for founders and ops leads. It is not another AI-agents-for-business explainer. Softix builds custom web applications and SaaS products for teams that need checkout and catalog work to match how buyers actually arrive.
What actually shipped (and what did not)
Three layers moved at once. Treat them as complementary, not competing products you must buy separately.
1. Network tokens: Visa and Mastercard
On 8 April 2026, Visa announced Intelligent Commerce Connect, part of Visa Intelligent Commerce. Visa describes it as a single integration—via the Visa Acceptance Platform—that is agnostic to network, protocol, and token vault. It is meant to let agents pay and merchants accept agent-initiated transactions without a one-off build for every chat surface.
Visa’s own list of supported agent protocols includes Trusted Agent Protocol, Machine Payments Protocol (MPP), Agentic Commerce Protocol (ACP), and Universal Commerce Protocol (UCP). The same release says the product can help merchants make catalogs discoverable on AI platforms and that Visa can handle orchestration and PCI scope for enablers processing on a merchant’s behalf. Visa listed a pilot set of partners (Aldar, AWS, Diddo, Highnote, Mesh, Payabli, Sumvin) and said it would roll out to more partners during 2026. That is a pilot, not a claim that every SMB acquirer is live.
On 10 June 2026, at Visa Payments Forum, Visa added merchant-facing tools around the same portfolio: Agent Score (a readiness check for whether agents can navigate and complete tasks on a site) and an Agentic Directory of Visa-verified agents and merchants, plus richer token data and a token assurance signal based on provisioning and behavioral history (Visa forum announcement). The same Visa Payments Forum cycle also described tokenized credentials with spend limits, merchant-category controls, and required approvals as the intended control model for agent-initiated Visa payments. Confirm current partner availability with Visa or your acquirer; do not treat the forum announcement as a guarantee that every OpenAI or chat surface is live on your MID.
Mastercard’s Agent Pay program (2025) defined how trusted agents participate on Mastercard rails. On 10 June 2026 it added Agent Pay for Machines (AP4M) for high-frequency, low-value, machine-to-machine payments—cards, bank accounts, and stablecoins—aimed at background automation rather than a shopper chatting “buy this jacket.” Mastercard named Stripe among the firms validating use cases. Treat AP4M as adjacent infrastructure (agents paying other services), not as your consumer checkout toggle.
2. Processor primitive: Stripe Shared Payment Tokens
Stripe’s Shared Payment Tokens (SPTs) are a processor-level primitive: an agent can initiate a payment with the customer’s permission and preferred method without seeing the underlying credential. Stripe says it launched SPTs in 2025 and that Etsy and URBN (Anthropologie, Free People, Urban Outfitters) adopted them.
The 2026 expansion matters for SMBs already on Stripe: SPT support now includes Mastercard Agent Pay and Visa Intelligent Commerce network tokens, plus Affirm and Klarna BNPL tokens. Stripe’s claim is that sellers already processing on Stripe automatically support these methods for agentic transactions, and that Stripe is the first provider to put both agentic network tokens and BNPL tokens behind one primitive. That is Stripe’s positioning; confirm enablement in your Dashboard and with your account manager before you tell finance it is “on.”
Stripe also reports that BNPL accounts for over $300 billion in transactions worldwide and that businesses on Stripe can see up to a 14% increase in revenue on BNPL-eligible sessions. Those figures are Stripe’s, not an independent audit. Use them as a reason to offer BNPL in agent flows if you already offer it on the website—not as a forecast of your lift.
3. Commerce protocol + storefront path: UCP and Shopify
Discovery and checkout still have to agree on carts, tax, shipping, and who is merchant of record. Shopify and Google co-developed the Universal Commerce Protocol, an open standard for how agents transact with any merchant. Shopify lists backing from Amazon, American Express, Etsy, Mastercard, Meta, Microsoft, Salesforce, Stripe, Target, Walmart, and Visa.
Shopify’s 18 June 2026 guide, Agentic Commerce on Shopify: How It Works, is the clearest merchant-facing primary source:
- Shopify Catalog structures and syndicates product data to connected AI platforms.
- Agentic Storefronts is a sales channel in admin (Settings → Sales Channels → Agentic Storefronts).
- ChatGPT: live for merchants in Catalog who sell to US buyers (store location can be outside the US); checkout completes on the merchant’s online store via an in-app browser.
- Microsoft Copilot: Catalog discovery; eligible merchants can sell via Copilot Checkout powered by UCP.
- Google AI Mode and Gemini: available to select US-based shops selling to US buyers, with broader rollout underway.
- The merchant remains merchant of record. Orders land in Shopify admin with AI-channel attribution.
- Purchasing on these channels is currently US-buyer only.
- Shopify’s Agentic Plan lets brands on other platforms (custom ERP, SAP, other commerce) syndicate into Catalog without a full replatform; Shopify says there is no monthly subscription—standard payment rates apply when Shopify Checkout is used.
Shopify reports that in Q1 2026, AI-driven traffic to Shopify stores grew 8 times year over year and orders from AI-powered searches increased nearly 13 times. Those are platform metrics. They do not tell you your category will convert at that multiple.
How the pieces fit (without the jargon pile-up)
Think in three contracts, not seven acronyms.
| Layer | Job | What you actually touch |
|---|---|---|
| Intent / mandate | Prove the human authorized this purchase | AP2 “mandates” (Intent + Cart) are cryptographically signed instructions. Google announced AP2 on 16 September 2025 with more than 60 organizations. The AP2 spec sits beside UCP; it does not replace your PSP. |
| Instrument | What gets charged, without exposing PAN | Visa / Mastercard agentic network tokens; Stripe SPTs; BNPL tokens. |
| Commerce session | Cart, tax, shipping, discounts, order | UCP / Shopify Checkout / your existing checkout. Embedded Checkout Protocol (ECP) is how a host (the agent UI) embeds your checkout when the session needs a human step. |
Google’s AP2 write-up is useful because it names the three questions every dispute desk will ask: authorization (did the user grant this purchase?), authenticity (does the cart match intent?), and accountability (who is on the hook if it is wrong?). Human-present flows sign a Cart Mandate after the shopper sees the cart. Human-not-present flows (ticket drop, restock) require a detailed Intent Mandate up front—price caps, timing, conditions.
If you already accept cards through a major PSP, you are closer than a greenfield “agent payments project” slide implies. Networks are designing this to ride existing acquirer relationships. Your work is catalog quality, policy, and exception handling—not inventing a new rail.
Shopify path vs custom stack
You do not need a new storefront to start. You do need an honest split.
If you are on Shopify (or can add Agentic Plan as a sidecar): turn on Agentic Storefronts, confirm Catalog completeness (title, options, live price, inventory, shipping), and decide per channel whether buyers check out inside the agent or bounce to your store. Keep brand, discounts, and fulfillment rules in admin—UCP is supposed to carry them. Do not assume every checkout customization survives every AI surface; Shopify says that varies by platform.
If you run a custom or headless storefront (including headless WordPress + Next.js storefronts), your job is different:
- Confirm your PSP’s agentic-token / SPT status in writing.
- Expose a machine-readable catalog (accurate price, inventory, variant IDs, shipping constraints)—scraped HTML is how agents quote yesterday’s price.
- Support a clean handoff URL for embedded or in-app-browser checkout so tax, discounts, and fraud tools stay yours.
- Log agent vs human channel in the order record. You will need it for refunds and ads attribution.
This is a build-vs-buy decision, not a branding exercise. Off-the-shelf wins if Shopify Catalog + your current PSP cover the channels your buyers use. Custom work wins when you have a non-Shopify cart, complex bundles, B2B price lists, or regulated goods that agents must not sell unsupervised.
What to do in the next 90 days
- Name the owner. Checkout, fraud, and catalog cannot sit in three Slack channels. One person owns “agent-initiated orders.”
- Ask your PSP three questions. Are Visa Intelligent Commerce / Mastercard Agent Pay tokens enabled on our MID? Are SPTs (or the equivalent) on? How are agent-initiated authorizations flagged in the authorization message and in disputes?
- Fix the catalog before the theme. Incomplete options, stale inventory, and “from $X” pricing will get you recommended wrongly or skipped. Shopify Catalog automates much of this for Shopify merchants; custom stacks need an explicit feed or API.
- Stay merchant of record unless you have a reason not to. Shopify’s model keeps the customer relationship with you. If a marketplace or agent platform wants to sit in the middle, price the data-and-refund cost, not just the take rate.
- Write the exception path. Address changes, age-gated SKUs, high-AOV orders, and first-time ship-to addresses should still escalate to a human or an embedded checkout—not silently auto-buy.
- Pilot one channel. If you are Shopify-eligible for ChatGPT or Copilot, enable one, watch attribution in admin for 30 days, then decide on Google AI Mode. Do not turn every toggle on the same afternoon.
- Update refund and chargeback macros. “Customer says they never clicked Buy” will become “my agent wasn’t supposed to buy that.” You need mandate / token evidence, not a screenshot of a chat.
Risks and limits (read these before you brief the board)
- Coverage is uneven. Visa Connect is still rolling out from a named pilot list. Google AI Mode / Gemini checkout is “select brands.” US-buyer-only is the current Shopify constraint. International SKUs may be discoverable and still not payable in-chat.
- Fraud and friendly fraud will look new. Tokenization reduces PAN leakage; it does not remove “I never authorized that SKU.” AP2’s value is an audit trail—if your stack actually keeps the mandate receipts.
- Liability language is not standardized in public merchant docs. Do not promise customers or your insurer that “Visa/Mastercard covers agent mistakes.” Get the current network and acquirer rules from counsel and your processor.
- Catalog errors become order errors at machine speed. A wrong variant ID is no longer one confused shopper; it is every agent that trusted your feed.
- BNPL in a chat UI can surprise finance. If you enable Klarna/Affirm in agent flows because Stripe made it easy, reconcile it the same way you reconcile website BNPL—returns, partial captures, and customer-service scripts included.
- This is not a CRM or sales-agent project. Wiring Claude to Salesforce is a different system. Mixing the two in one roadmap usually delays both.
When custom software is justified
Build or extend software when at least one of these is true:
- You are not on Shopify and a sidecar Catalog feed is not enough (custom pricing, inventory in an ERP, multi-warehouse promise dates).
- You sell configurations an agent cannot safely complete without your rules engine.
- You need agent payments into your own product (usage top-ups, licensed seats, B2B reorder) rather than a retail cart.
- You must keep PCI and PII in a specific region or system of record.
That work is web app and SaaS engineering: feeds, checkout session APIs, webhook-grade order ingest, and fraud hooks—not a chatbot skin.
FAQ
Do I have to replatform to accept agent payments?
Usually no. Visa, Mastercard, and Stripe are explicitly designing for existing acquirer and PSP relationships. Shopify merchants get a channel toggle. Custom carts need a PSP confirmation and a catalog/handoff, not a new storefront by default.
What is the difference between UCP and AP2?
UCP models the commerce conversation (discover, cart, checkout, payment negotiation). AP2 models proof of user intent and payment authorization. They are designed to work together; neither replaces Stripe or your merchant account.
Will this show up as a new fee line?
Expect standard card and BNPL processing first. Platform-specific take rates, if any, belong in your PSP and Shopify contracts—not in this article. Shopify states Agentic Storefronts add no transaction fees beyond standard processing, and Agentic Plan has no monthly subscription. Verify the current contract language before you model margin.
What to do next
If your buyers are already asking ChatGPT or Copilot to “find me X under $Y,” treat agentic checkout as a channel project this quarter: PSP enablement, catalog hygiene, one pilot surface, and a written exception policy.
Softix can review your current storefront or SaaS checkout against these rails and tell you what is configuration versus a build. Contact us with your stack (Shopify, custom, Stripe/Adyen/other) and the AI surfaces you care about first.
Share


