Agentic commerce is no longer a distant concept. AI agents are already executing tasks on behalf of users, researching, comparing, and in some cases, transacting. But when an agent checks out for a user, you need to know it was authorized.
Truvera’s digital identity infrastructure lets you issue and verify AP2 mandates that provide verifiable proof of what an AI agent was authorized to do on a user’s behalf.
Contact the Truvera team to discuss how AP2 can create the most value in your agentic commerce strategy.
Why Agentic Commerce Needs AP2
Today's payment infrastructure was designed with a human at the keyboard. Take the human away and put an agent in the seat, and three questions suddenly have no good answer:
Authorization: How can a merchant verify that the user granted the agent authority for this purchase? Standing instructions do not create a cryptographically verifiable link between the user’s intent and the agent’s action.
Authenticity: How can anyone confirm the agent's request reflects the user's actual intent and not a hallucination, error, or manipulated instruction? Traditional payment infrastructure does not carry standardized evidence of the instructions given to an AI agent.
Accountability: If a transaction is disputed, how can the parties establish what the user authorized and what the agent did? Without a shared protocol, there may be no common, interoperable record that all parties can verify.
AP2 is designed to address these gaps by creating cryptographically verifiable evidence of what the user authorized, what the agent attempted to purchase and how the payment was executed.
At its core, AP2 v0.2 uses two types of mandate credentials:
Checkout Mandate: captures what the agent is authorized to buy and under what conditions.
Payment Mandate: captures how the agent is authorized to pay, including conditions such as the payment method, amount and timing.
When the user is not present, they approve constraints in advance, such as the permitted merchant, items, payment method, spending limit or time period. The agent can then complete a purchase only when it meets those constraints.
Together with Checkout and Payment Receipts, the mandates create verifiable evidence of what the user authorized and how the transaction was processed.
How Truvera Supports AP2
Whether you're running a merchant platform, operating as a payment provider, building a wallet, or shipping agents, Truvera gives you the tools to play in agentic commerce without building the hard part yourself.
AP2 mandate issuance via MCP: Truvera handles the creation and signing of open and closed Checkout and Payment Mandates, including selective disclosure and the cryptographic links between the user’s authorization, checkout and payment. You can begin issuing AP2 mandates within minutes of MCP onboarding, not months.
Real-time verification: Through Truvera's API or MCP, you can verify mandate signatures and the integrity of the full mandate chain. In autonomous flows, it also validates that the mandate is bound to the authorized agent and that the final checkout and payment match the constraints approved by the user.
JavaScript tooling for AP2 receipts: Truvera provides an npm package for creating and working with signed AP2 receipts, making it easier for JavaScript applications to integrate receipt handling into agentic-commerce flows.
Native MCP integration: Truvera exposes AP2 mandate issuance and verification as MCP tools. Once connected, MCP-compatible agents can use these capabilities directly within their workflows, without requiring a separate custom integration for each agent.
Spec tracking built in: As AP2 and the FIDO Alliance’s emerging agentic-commerce specifications evolve, Truvera updates its tooling to support new versions, reducing the need for teams to track and implement every change themselves.
Why Build on Truvera Instead of Doing It Yourself
Building AP2 v0.2 support involves more than issuing a standard credential. You must manage mandate signing, selective disclosure, agent authorization, transaction binding, constraint evaluation, versioning and signed receipts.
Or you plug into Truvera's MCP servers and start issuing AP2 mandates in minutes
You get to a working flow faster, you learn how AP2 actually behaves in the wild, and you're building on infrastructure made for production, instead of burning months rebuilding plumbing that already exists.
Get Started
Truvera's AP2 mandate support is available now. We’ve spent months building support for AP2 and understanding how its mandates, constraints and verification flows work in practice. We can help you assess how it fits into your strategy and where it can create the most value.
The trust layer for agentic commerce is being built now. The infrastructure to start testing is ready.
A Note on Where AP2 Stands
AP2 is still evolving, but its direction is becoming clearer.
Google has contributed AP2 to the FIDO Alliance, where it will be developed alongside Mastercard’s Verifiable Intent framework. If you are building with AP2 now, v0.2 is best treated as an implementation baseline rather than a finished industry standard. It provides a practical foundation for testing how authorization, checkout and payment could work when a person is not present.
But you do not need to wait for the specification to be finalized. Implementing AP2 v0.2 allows you to test agentic commerce flows, understand the mandate lifecycle and prepare for the standards that ultimately emerge.






