Machine to Machine Transactions: How to Resolve Trust and Governance Gaps. 

FIDO, VC, AP2, Tokenization, Credential Issuance, Biometrics, …etc

Executive Summary

The transition to agentic, machine-to-machine (M2M) commerce creates a profound governance gap that existing technology-first standards cannot fill. Today, human-in-the-loop (HIL) transactions, whether at a point-of-sale or in eCommerce, are secured not by technology alone, but by the robust, contract-based governance and risk-allocation models of networks like Visa and Mastercard. As stated previously, V/MA are the identity infrastructure for the internet and identity is the core “shaping force” for all new payment schemes.

Continue reading

X402 Foundation

Short Blog

The x402 Foundation was publicly announced last week on September 23, 2025, as a joint initiative between Coinbase and Cloudflare. This effort aims to solve the governance issue in agentic. The design COULD SOLVE the governance issues outlined in Governance in Payments as well as last month’s Agentic Commerce Economics and Governance. As a refresh, my position is that monetization/governance is the Gordian knot preventing AI from moving to next stage of growth. 

While Google’s AP2 suffers from a dependency on settlement governance and the inability to expand trust beyond their own domain (see AP2 blog), x402 is just a standard that handles payment terms negotiations between two APIs (both price and method). The foundation turns x402 into a “network) with an operational model, active governance and economics. My example is that an existing customer would have payment managed with a current card on file and the merchant owning risk, whereas a new customer (or new machine request) could agree on a non-refundable stablecoin payment.  

Continue reading

Google Rolls out Agentic Payments Protocol (AP2) – Techie Blog

Yesterday Google rolled out AP2. Key summary bullets

  • I applaud Google’s efforts to advance AP with first focus on enabling a “Trusted Agent Economy”. AP2 (V0.1) on establishing the core architecture and enabling the most common use cases (cards, data payloads to support VC, human in the loop scenarios with step up). 
  • Long list of supporting participants including MA and Amex. However, no other AI platforms, nor Visa, Paze, or US Banks. 
  • Good detailed documentation on initial flows (see Github)
  • Introduction of Verifiable Credentials (VC) as the core of AP2 with a recognition that merchants (who own risk) may also need transaction fraud data. 
  • A twist on the identity provider of VC to become the [Payment] Credential provider, with initial focus on cards, Google has stated goal of designing AP2 to support stablecoin, push payment and other payment types. This “sets up” Visa and Mastercard to retain their roles as the authentication infrastructure for the internet, while also allowing for other networks (India UPI) and seperate identity providers (eID) to operate with the role.
  • My read is that Google has given up hope of making AP2 work in US, as Visa’s intelligent commerce framework is further along.  How tokens, Issuers and networks work within AP2 is not a big technical effort, but there are several things missing from AP2, for example the rule sets (3DS, DAF, TAF, …etc) which the credential (and transaction) operates under. 
  • The framework is solid, authentication will be a huge part of the challenge here.  Payment networks must control how authentication is performed by with their credentials. Visa and mastercard are the authentication infrastructure for the internet for a reason. Its not the technology, it is the governance, standards, enforcement and the operating rules which govern WHO OWNS THE RISK when authentication has broken. See Identity Models and Governance https://blog.starpointllp.com/?p=6470 
  • Of course stablecoins could work here, but guess who owns the risk when something happened that wasn’t authorized? There is no bank to complain to.. Your automated agent made a mistake and you (the consumer) have the loss.
  • AP2 will be successful as the communication protocol for between agents and stakeholders, but it requires credential providers with strong governance and operating rule constructs. Visa, MA, Amex, UPI/UIDAS and PayPal all fit that bill.  The challenge with this dependency is that the control points for progress are complex, as any change in a network requires buy in from existing stakeholders.
  • Expect Google to demonstrate the technical efficacy of AP2 with Stablecoin or Crypto first, and then look to adapt AP2 needs to credential providers
  • While the EU is the best market for Google to begin with, regulators are not keen on doing anything to help US big tech. My recommendation to Google is work on a US focus plan B that will involve US credential providers (ie Visa and Visa banks). AP2 can be the protocol, but most of it will need to operate within the authentication and rules of the credential provider.

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Agentic Commerce – I’ve Seen a Lot of “Revolutions”. This One Feels Different.

Hello from Alberta and the Columbia Ice Fields. During the drive I’ve put together a Case study in how Shopify is Building a key piece of the new model. Also drill down on monetization as the Gordian Knot that will determine how Agentic Commerce Operates.

I’ve been in the payments and retail space for almost three decades. I was there for the dot-com boom and bust, the shift from plastic to mobile wallets, the birth of amazon and Google, and the rise of the platform economy. I’ve seen enough hype cycles to fill a library. Each time, we were promised a revolution that would change everything. And while some of those shifts were significant, they were ultimately evolutionary. eCommerce added a channel, mobile created more shopping interactions and more points to influence,  but were mostly the same commercially. 

This time, I have to admit, it feels different. The rapid advancements in Artificial Intelligence aren’t just creating a new channel; they are actively dismantling the foundational economic bargain of the internet. The core paradigms I’ve operated on for my entire career is being invalidated in real-time.

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Genius Law – What to Expect?

Yesterday President Trump signed the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act into law, clearing the path for dollar-backed stablecoins. As I’ve argued before, the future of money is a new model of trust, and this legislation provides the regulatory certainty needed for that trust. 

The GENIUS Act is a landmark piece of legislation. It establishes a dual charter system, enabling both federal and state-regulated stablecoin issuers. The key provisions are precisely what the industry needed: a mandate for 1:1 reserves with high-quality liquid assets like cash and short-term treasuries, a prohibition on reusing those reserves, and the designation of issuers as financial institutions under the Bank Secrecy Act. This isn’t just about compliance; it’s about building a foundation of trust that can be exported globally.

Continue reading

Stablecoins: Bank Strategy – Just Another Rail

Bankers View: Stablecoins, Deposits, and the Future of Payments

Summarizing my 20 odd tweets yesterday. Note that I don’t necessarily agree with the banks’ strategy, but I do understand it. Given that most of the press is focused on how Stablecoins will destroy banking, I thought a banker’s view would be a useful counterbalance.

The buzz around stablecoins continues, often painting a picture of banks demise. As a former banker I thought I’d share my view on the topic and explain the bank strategy (as I see it). While stablecoins present novel tech, the notion that they will supplant established retail banking relationships is a bunch of “hooky”. Big banks aren’t just watching from the sidelines; they are best positioned to integrate this new rail, much like they’ve absorbed countless payment innovations before.

Continue reading

Retailer Actions in Agentic Commerce

Navigating a New Demand Paradigm and Its Two-Sided Imperative

The rise of agentic commerce, where AI agents could potentially execute purchases for consumers, signals more than an evolutionary step in e-commerce; it represents the emergence of a new type of demand: a direct customer buy order, theoretically complete with payment authorization. This presents a two-sided imperative for retailers. Firstly, ensuring your products are discoverable and favorably considered by these AI agents an “SEO for the agentic era.” Secondly, developing the organizational capacity to act on this demand, potentially bypassing traditional e-commerce pathways for direct fulfillment via APIs, with updates to fraud and risk screening.

Continue reading

TCH RfP is Live (for Consumers)

Big congrats to TCH, and the 3 banks live with RfP. This is a major accomplishment. As I’ve written RfP is the most important transaction set for RTP. 

© Starpoint LLP, 2024. No part of this site, blog.starpointllp.com, may be reproduced or retransmitted, in whole or in part, in any manner without the permission of the copyright owner. Also see our Legal/Disclaimer (this is a highly opinionated and partially informed blog).

To get a view of what this looks like see this consumer support page from

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Adios 3DS “Step up”.. Hello FIDO2

Short Blog

There are significant changes brewing in eCommerce authentication and authorization. Today’s blog is more of a headline summary of key points that I hope to break down over Thanksgiving. 

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us

Innovation in Networks – Part 4

The Strategic Innovation Era

© Starpoint LLP, 2022. No part of this site, blog.starpointllp.com, may be reproduced in whole or in part in any manner without the permission of the copyright owner.

This blog has been sitting at 80% for almost 3 months. Sorry for the delay. This was a 30 page blog that I slimmed down to 16. Thus the long summary section. This blog is focused on networks and their ability to: 1) internally charter their own evolution, 2) grow network of supporting stakeholders, 3) stimulate network growth, and 4) encourage investment/innovation. Why read this? Payment innovation is set to grow Global GDV by 50% (above baseline) over the next 5-7 yrs. Today’s blog is a basis for this hypothesis.

A very long blog with 3 page summary below

You need to be logged in to view the rest of the content. Please . Not a Member? Join Us