Google has donated its Agent Payments Protocol to the FIDO Alliance and released an updated version, including autonomous payment capabilities.

The move is intended to ensure AP2 remains platform-agnostic and open to broader industry participation. Through the process of placing the protocol under the FIDO Alliance’s stewardship, Google aims to accelerate adoption across the payments ecosystem and support interoperability between different platforms and providers.

Protocol update and autonomous transaction support

Alongside the transfer, Google has published AP2 v0.2 on GitHub, introducing new capabilities for autonomous transactions. A key addition is support for ‘Human Not Present’ payments, which enables AI agents to execute purchases independently, based on instructions pre-authorised by the user. The update is designed to address scenarios in which speed or timing is critical, such as purchasing limited-availability items as soon as they become available, without requiring real-time user interaction.

In addition, the release reflects the broader challenge of enabling AI agents to transact reliably and securely across commerce environments, particularly as autonomous systems take on a more active role in consumer and business workflows.


More

The Register: Death to one-time text codes: Passkeys are the new hotness in MFA

Whether you’re logging into your bank, health insurance, or even your email, most services today…

Read More →

Dark Reading: Enterprise FIDO Authentication: An Easy, 3-Step Plan

Enterprise passkey adoption has reached a tipping point. According to new data from HID and the…

Read More →

ID TECH: FIDO Alliance Tightens Authenticator Verification with Metadata Service Update

The FIDO Alliance has released a major update to its Metadata Service (MDS) that is intended to…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.