Balancing risk and reward in tech is something that is done every day. “Do we do A and get outcome B, or do we risk it all on C hoping for outcome $$$? Which is the spot a lot of you find yourselves in as we careen towards a largely agentic commerce reality.
But not everything needs to be a bet. For now, maybe the right answer is, to quote the meme, “¿Por qué no los dos?”
At this point, Visa is routing four competing agentic commerce protocols through a single integration, built so merchants and agent platforms keep using the credential infrastructure they already have. ACP and UCP are two of the four.
Visa didn't pick a hand. It covered the whole board. Signing off on one protocol means betting your stack on a single card while the network that built the game stays even.
When the largest card network won't pick a winner, signing off on one protocol is making a bet the network itself declined to make.
ACP vs UCP: is there a clear winner?
The answer is fairly simple today: No. As of August, 2026, there is no settled winner among agent platforms or agentic commerce protocols. The most-integrated in-chat checkout in the market was retired five months after launch, a competing protocol arrived four months later with a different design, and the card networks have shipped infrastructure that deliberately supports all of them rather than picking one.
In March, 2026 OpenAI wrote that the initial version of Instant Checkout didn’t offer the flexibility it wanted to provide. It would let merchants use their own checkout experiences instead, while OpenAI focused on product discovery. Forbes reported that TD Cowen analysts called it a stunning admission, and that Booking.com and Expedia shares rose 8 percent and 13 percent on the news.
No one is trying to say that OpenAI has gone full-retreat mode. It’s just that anyone who built their checkout around that model didn’t get a vote.
Next came a second standard: Google announced UCP on January 11, 2026 at NRF, co-developed with Shopify, Etsy, Wayfair, Target, and Walmart, and endorsed by more than 20 companies including Adyen, American Express, Mastercard, and Stripe. ACP came first, from Stripe and OpenAI, on September 29, 2025. Two open standards in sixteen months with no sign of a merger.
Then, on April 8, 2026 Visa launched Intelligent Commerce Connect, describing it as a network, protocol, and token vault-agnostic on-ramp to agentic commerce. It accepts payments initiated through Trusted Agent Protocol, Machine Payments Protocol, ACP, and UCP through a single integration. According to Visa, agent platforms can plug into existing credential infrastructure instead of trying to adopt whichever vault or vendor a given protocol brings with it.
We’ve also got the camp that never shipped a checkout protocol at all. MCP standardizes how an agent reaches tools and data, and Anthropic donated it to the Linux Foundation's Agentic AI Foundation.
Lastly, Google's WebMCP proposal is running as a Chrome origin trial, letting a site hand its own functions to an agent in the browser.
Neither provisions a credential. Both assume the agent uses the checkout you already run.
You won’t find a global business building a translator across four protocols when one of them is winning. Visa spent a huge amount of engineering budget on the assumption that the standards war would be one of attrition, and on the assumption that the vault, not the protocol, is where a merchant's flexibility lives.
Meanwhile, neither MCP nor Google's WebMCP defines a checkout at all. Both point the agent at the rails you already run. That means if you can find orchestration where agentic payments infrastructure already exists, you’re well ahead of the game.
What are you actually betting when you pick a protocol?
Put simply, you’re making a bet on your payment credential path. ACP and UCP differ less in how an agent finds products than in where the credential comes from and who provisions it. That means that adopting a protocol imports a credential model whether or not anyone scoped it that way.
ACP is the path for a purchase that starts in ChatGPT. It passes a scoped token through the checkout conversation. OpenAI's Delegated Payment Spec shares payment details with the merchant or its designated PSP. The PSP or vault returns a token scoped to a maximum amount and expiry, and the merchant completes the charge on its own rails. Settlement, refunds, chargebacks, and compliance stay with the merchant, and OpenAI makes it very clear that they are not the merchant of record..
UCP is the path for a purchase that starts in Google's surfaces. It negotiates the credential as its own layer. Per Shopify's UCP engineering write-up, the merchant advertises which payment handlers it accepts, the agent declares what credentials it can provide, and the two negotiate per transaction. Available handlers shift by cart contents, buyer location, or amount, and new payment methods enter without a change to the core protocol.
UCP composes with AP2 for cryptographically verifiable payment authorization, and AP2 is agnostic to the payment instrument, with new instruments added by defining a type in the Payment Instrument object.
So ACP bundles the credential into the checkout conversation and UCP separates it and negotiates it. Neither one says where the credential lives when the agent goes away.

Should merchants support both ACP and UCP?
Yes, if your buyers' agents use both. Supporting two protocols protects you from picking the one that loses.
What it doesn’t do is protect your credentials. Neither protocol specifies where the card data is stored, so both leave that decision open. That decision, not the protocol, determines whether you can change your mind later.
What does neutrality actually require?
Real neutrality is decided by three questions that no protocol answers: where the payment credential is stored, who is allowed to move it, and whether it survives a change of protocol, processor, or agent platform. If you can answer all three, you can support one protocol, both, or a fifth one that ships next year and change course without a migration.
Where is the credential stored?
Consolidating credentials in one vault is not the risk. Consolidating them in a vault owned by a party that also competes for the transaction is, because that party then sets the terms of every future change you want to make. One vault you control turns the protocol question into a configuration question.
Who is allowed to move it?
Portability that requires a counterparty's cooperation is not portability. The test is whether you can export tokens on your own timeline, without a commercial negotiation attached to the request.
What breaks when you want to switch?
Name the specific failures: stored credentials that no longer authorize, subscriptions that have to re-collect card data, and reconciliation history that no longer maps. A credential layer you own turns all three into a routing change.
Visa makes the same argument from the other side of the table. It built vault-agnostic support specifically so merchants and agent platforms can keep the credential infrastructure they already chose. That is the same conclusion, from a party with no reason to argue Spreedly's case. The longer version is in Own the Tokens, Own the Agentic Commerce Customer.
How to stay neutral without stalling
Support the protocols your buyers' agents actually use, and keep the credential somewhere none of them own. That combination lets you move fast on the commerce layer precisely because the payments layer is not at risk.
Spreedly Vault holds the credential in a layer no single PSP, protocol, or agent platform owns, and Spreedly Connect is the integration surface in front of it. Spreedly made agentic commerce a live channel, with agent-initiated transactions flowing through existing PSP relationships while merchants stay merchant of record and routing logic stays intact.
CEO Justin Benson told PYMNTS that the industry is still in discovery mode, and that anyone claiming to have all the answers is not being very transparent. Uncertainty is the condition, so go ahead and build for it.
And if you came here to select a protocol, the good news is that, for now, you don’t have to.
What is the difference between ACP and UCP?
Both are open agentic commerce protocols, but they handle the payment credential differently. ACP passes a scoped, single-use token through the checkout conversation using OpenAI's Delegated Payment Spec. UCP negotiates the credential as its own layer: the merchant advertises accepted payment handlers, the agent declares what it can provide, and the two settle it per transaction. Neither protocol specifies where the credential is stored afterward.
Does supporting both ACP and UCP prevent vendor lock-in?
No. Dual integration hedges the interface, not the rails. Both protocols sit on top of a credential layer neither one defines, so a merchant can implement both and still be locked to whichever vault holds the card data. Lock-in is decided by where the credential lives and whether you can move it on your own timeline, not by how many protocols you support.
Who is the merchant of record in an agentic commerce transaction?
The merchant, under both protocols. OpenAI states it is not the merchant of record for ACP transactions, and UCP states businesses retain merchant of record status. Settlement, refunds, chargebacks, and compliance stay with the merchant and its PSP in either case. This is one of the few places the two protocols agree, which is worth knowing if you've been told they differ here.








