tp tate@programs AgentCore proof
tate@programs ~/tools/agentcore-payment-policy x402 / AgentCore / Pay.sh

amazon bedrock agentcore payments / x402 / may 2026

Prove the payment boundary before agents can spend.

AWS, Coinbase, Stripe, Fireblocks, Circle, and Visa are pushing agent payments out of demos and into enterprise payment infrastructure. Paid APIs, MCP servers, web content, and agent services now need spend caps, recipient allowlists, receipt rules, browser/CORS posture, metadata boundaries, and audit evidence before enterprise buyers let agents transact.

input
limits
output
policy JSON
privacy
browser only
Controls

launch posture

The policy should be boring enough to survive a real user.

sample report

cap

Loss is bounded before execution.

Session and per-call ceilings should be enforced outside the prompt so a model cannot talk its way into more spend.

payee

The recipient is explicit.

New payees, changed networks, large amounts, and unknown facilitators should deny or pause until a human confirms.

memo

Metadata stays small.

Payment records should carry compact purpose codes, not full prompts, support tickets, emails, or hidden query strings.

audit

Every decision has evidence.

Receipts, denials, retries, traces, and refunds should explain what happened without exposing private user context.

paid cutover proof

For teams selling into AgentCore Payments, the first buyer question is not whether x402 works. It is what can go wrong when it does.

request packet

$750

Outside Proof Packet

One public paid API, MCP server, content endpoint, or agent service mapped for discovery, 402 behavior, recipient binding, cache/CORS posture, receipt states, metadata leakage, and patch order.

$2.5k+

Cutover sprint

Authorized implementation help for one approved patch list: no-store responses, browser-readable challenges, OPTIONS policy, well-known discovery, receipt-store guardrails, or buyer-facing runbook language.

$4.5k/mo

Readiness monitor

Weekly outside checks for teams whose paid API, AgentCore, x402, MCP, UCP, or marketplace surfaces can drift after launch.

source ledger

Why this tool exists now.

aws

AgentCore Payments preview

AWS announced AgentCore Payments preview on May 7, 2026 with Coinbase and Stripe, including session spending limits, observability, x402 negotiation, and paid MCP/API access.

open AWS note

aws

Agents that transact

The AWS launch blog details paid resources, payment connections, x402 challenges, proof delivery, and transaction observability across agent runs.

open AWS blog

coinbase

x402 discovery and wallets

Coinbase describes x402 discovery and wallet infrastructure for agents that discover, pay for, and use paid services with enterprise controls.

open Coinbase note

fireblocks

Institutional agentic payments

Fireblocks joined the x402 Foundation and launched an Agentic Payments Suite for enterprise stablecoin payments, request integrity, and spend governance.

open release

market

Agent payment volume signal

CoinDesk reported Keyrock's estimate that AI agents settled more than $73 million across roughly 176 million blockchain transactions from May 2025 through April 2026.

open report

docs

Payment sessions and instruments

The AgentCore getting-started docs walk through credential providers, IAM roles, a payment manager and connector, a payment instrument, wallet funding, a payment session, and automatic payment processing.

open docs

docs

How AgentCore payments works

The Bedrock AgentCore docs describe x402 orchestration for agents paying APIs, MCP servers, and web content, including endpoint discoverability through Bazaar.

open docs

cloudflare

Agentic payments over 402

Cloudflare's Agents docs frame x402 and MPP as protocols for agents purchasing resources through HTTP 402 payment flows.

open docs

quicknode

Paid infrastructure without accounts

Quicknode documents x402 and MPP as wallet-based protocols for applications and agents accessing blockchain infrastructure.

open docs