deepidv Logo

For store owners and developers

How to accept AI payments in your store

You accept AI payments through the processor you already use, once it supports an agent protocol. Eligible Shopify stores already accept agent checkout with Shop Pay. Elsewhere, connect the Universal Commerce Protocol or the Agentic Commerce Protocol through your processor and accept Visa and Mastercard agent tokens. Then decide which agent orders need a verified person.

deepidv does not process payments. Your payment provider moves the money. deepidv proves who is on the other end: the agent, the person who authorized it, and whether they are allowed to buy.

What is an AI payment?

An AI payment is a purchase an AI agent completes on a person's behalf. Three things travel with it: proof of which agent is acting, proof of what the person authorized (a mandate, such as a cart and spending limit), and a payment credential scoped to that agent. None of the three gives you a checked ID or a live face check.

The AI payment protocols, in plain English

Seven standards and network programs set out how an agent identifies itself, finds your products, proves what the person approved and pays you. None of them checks the person's ID or face for you.

Agent commerce standards merchants meet in 2026
StandardFromWhat it does for a merchant
Universal Commerce Protocol (UCP)Google and Shopify, January 2026One way for any agent to discover products, build a cart and check out. Works with AP2, MCP and A2A.
Agent Payments Protocol (AP2)Google, September 2025; FIDO Alliance since April 2026Signed mandates proving what the person authorized: limits set in advance, or the exact checkout and payment.
Agentic Commerce Protocol (ACP)OpenAI and Stripe, September 2025Product feeds, carts, checkout sessions and secure payment credentials; the merchant stays the system of record. Latest spec 2026-04-17.
Trusted Agent ProtocolVisa, October 2025Agents sign requests (RFC 9421) with keys in Visa's directory, so you can tell an agent from a bot.
Agent PayMastercardAgentic tokens scoped to one agent and its spending rules; an agent flag in the authorization.
ACE developer kitAmerican Express, April 2026Specs for card enablement, purchase intent and tokenized payment credentials for Amex cards, open to select developers. Agent registration is still in development.
WebMCP checkoutShopify, September 2026Structured checkout tools for agents working in the buyer's browser.

Swipe the table to see every column.

How to accept payments from an AI agent API

You accept agent payments through your existing checkout and processor, then add a person check that runs only when your risk rules call for it. These seven steps cover a Shopify store or a custom stack.

  1. Expose checkout to agents. On Shopify, Agentic Storefronts and the Checkout MCP server do this. On a custom stack, implement UCP checkout sessions or the ACP checkout API, or use a plugin that does.
  2. Read the agent's identity. Log the agent profile on every request (Google sends a UCP-Agent profile header) and verify request signatures where the agent provides them.
  3. Accept tokenized credentials. Route agent payment tokens through your processor's payment handler. You never handle raw card data.
  4. Run your risk rules before you capture. Value, first order, product type, agent reputation.
  5. Verify the person when a rule fires. Create a deepidv session and send the verification link back through the agent or to the customer directly. The request is a POST to https://api.deepidv.com/v1/sessions with your x-api-key header and the workflowId of a workflow built from steps such as ID_VERIFICATION, FACE_LIVENESS and AGE_ESTIMATION. The response includes the session_url; set sendEmailInvite and sendPhoneInvite to false when the agent delivers the link.
  6. Fulfill on the webhook. Ship when the session.status.verified webhook arrives; hold on session.status.rejected or session.status.failed.
  7. Store the evidence. Keep the mandate and the verification receipt with the order.
Create a session for a link the agent delivers, as shown in the deepidv docs. Field names also work in snake_case.
curl -X POST https://api.deepidv.com/v1/sessions \
  -H "Content-Type: application/json" \
  -H "x-api-key: YOUR_API_KEY" \
  -d '{
    "firstName": "Jane",
    "lastName": "Smith",
    "email": "jane.smith@example.com",
    "phone": "+14165557890",
    "sendEmailInvite": false,
    "sendPhoneInvite": false,
    "workflowId": "your-workflow-id"
  }'

Who carries the risk when an agent pays?

Mostly you. A dispute on an agent order still counts against your chargeback ratio, and a customer can claim the agent bought something they never wanted. Some retailers now say in their terms that a purchase by an authorized agent counts as the customer's own purchase. Network mandates help prove what was authorized; a verification receipt proves who authorized it.

Verification turns an agent payment into a known customer

An agent order with a verified person behind it is a customer you know. deepidv verifies once with ID and a live face check, then reuses that result on later orders, so repeat agent purchases stay fast. A 1:N face match stops one person running many agents across many accounts.

Add verification to your Shopify store

The deepidv app for Shopify adds verification to your store without code. Choose when it runs: first orders, orders above a value you set, limited releases, age-restricted products, or agent orders your rules flag. Customers verify once with ID and a live face check, and their later orders, including those placed by their AI agent, reuse the result. Every check produces a signed receipt you keep with the order.

  • ID and face verification
  • One person, one account
  • Age checks without an ID upload
  • A receipt for every check
Two phones showing deepidv verification: a completed ID and face check, and the signed verification receipt with its attestation ID

Frequently asked questions

How do I accept AI payments in my store?

Use a processor that supports an agent protocol. Eligible Shopify stores accept agent checkout with Shop Pay already. Other stores connect UCP or ACP through their processor or a plugin, and accept Visa and Mastercard agent tokens.

What is the difference between UCP and ACP?

UCP, from Google and Shopify, covers the full journey from discovery through checkout to post-purchase support, and powers checkout in Google's AI Mode and Gemini. ACP, from OpenAI and Stripe, covers product feeds, carts, checkout sessions and payment credentials, and lets merchants share their catalogs with ChatGPT. Many stores support both through their platform.

Can I accept payments from an AI agent through an API?

Yes. Implement UCP or ACP checkout endpoints, accept tokenized credentials through your processor, and confirm orders by webhook. Add a verification step that runs before capture when your risk rules fire.

Does ChatGPT still have Instant Checkout?

Not as a standalone feature. OpenAI moved away from Instant Checkout in March 2026 to focus on product discovery. ChatGPT now sends shoppers to merchants' own checkouts, while ACP continues as an open specification.

Who is liable if an AI agent makes a purchase the customer disputes?

Usually the merchant takes the chargeback, though Visa's rules hold the cardholder responsible for purchases made by an agent registered with Visa. Keep the agent's mandate and a verification receipt with every high-risk order to defend the dispute.

Do AI payment protocols verify the customer's identity?

Only in part. Visa and Mastercard check the cardholder before an agent can use a card, and the protocols prove which agent is acting and what the person approved. None of them checks the person's ID and face for you, or tells you whether they are allowed to buy. That is the job of a verification step.

Verify the person behind the orders that matter, and keep a record of every check.

Sources