MCP, A2A, UCP, ACP, AP2—what lets an agent advise, what lets it act, and why neither leaves a trail
TL;DR Summary
The agentic commerce alphabet is a depth chart, not a quarterback controversy. MCP, A2A, UCP, ACP, AP2, and the rest each answer a different question, and one purchase can run through four of them without conflict—the builders say so themselves. Sorting the alphabet into five floors is the easy part; the hard part is that each floor takes away something your measurement stack used to see.
Your fantasy football draft just happened without you. You set the rules weeks ago, then forgot about it. The platform took it from there, and now you’ve come back to an outcome that’s already yours.
You’re in line at the espresso stand and check out your new roster, bracing yourself. But it’s better than what you’d have built with a clock running. It read your rankings, applied your rules, took the boring running back in the fourth round when you would have reached for someone more exciting, and spent every pick while you were somewhere else adulting.
What sits wrong is not that it went badly, but that it went well, without you.
Rewind an hour. A different tool tells you a receiver is going three rounds later than originally projected. Then it stops, not caring what you do next. Ignore it and nothing happens.
Two tools: One recommends and waits, the other acts. You supervise the first, delegate the second, and only notice the difference when you come back to a team you “own” but didn’t assemble.
This line runs straight through the way people are now shopping, and it sorts the alphabet everyone is tripping over.
Every Tool Either Advises or Acts
Agentic commerce happens when the second kind of tool goes shopping. An AI agent finds the product, builds the order, and completes the purchase instead of handing someone a link and wishing them luck. Everything to follow is somebody’s answer for how it should work.
An agent advises or an agent acts. It surfaces a recommendation and hands control back, or it moves—cart, authorization, order—while you’re doing something else. Exactly which one has little to do with how smart the model is. It depends on the plumbing the agent is permitted to touch. A projection tool with root access to your league is an auto-draft. An auto-draft with the acting turned off is a projection tool.
Protocols are the plumbing that shapes what an agent can do. The question isn’t Who’s winning? but Which floor is this thing on?
Not a Quarterback Controversy—a Depth Chart
The format war framing arrived early and stuck: two quarterbacks, one job; pick a starter and bench the other. This was the wrong shape, but it settled before anyone noticed. Nearly every pair of protocols positioned as rivals operates on a different floor of the stadium, and one agentic purchase can run through four of them without conflict.
There are five floors to this user journey: substrate, discovery and cart, identity, authorization, and settlement. This is not an official taxonomy, but the five questions every agentic purchase has to answer. (Your fantasy football league answers them too.) Other explainers have sorted the stack this way. What follows asks a new question: what it costs you to measure.
Floor One: Substrate
This is the league platform itself, which nobody thinks about until it goes down mid-draft. It doesn’t rank or pick anyone; it’s how every piece reaches every other piece.
MCP (Model Context Protocol) is a substrate-layer open standard, created by Anthropic in November 2024, that defines how an AI application connects to external tools, data sources, and APIs. In December 2025, Anthropic donated it to the Agentic AI Foundation, a Linux Foundation project it anchors; the current specification is dated July 28, 2026.
MCP has a sibling that handles the other direction: A2A (Agent2Agent), introduced by Google in April 2025, is the substrate-layer open standard that lets agents discover each other, publish what they can do, and divide work across vendors that never coordinated. Google donated it to the Linux Foundation in June 2025, and on August 17, 2026, it joined MCP inside the Agentic AI Foundation.
Neither one buys anything, but together they make connected action possible. It’s the floors above that decide whether the action becomes a transaction. A connection is not a visit; it leaves no session behind.
Floor Two: Discovery and Cart
This is the projection tool and draft board: what’s available, who’s worth having, and the queue that holds your picks until something spends them.
UCP (Universal Commerce Protocol) is a discovery-and-cart open standard, launched by Google at NRF in January 2026 with Shopify, Etsy, Wayfair, Target, and Walmart. It spans product discovery through post-purchase. Merchants publish a /.well-known/ucp manifest so agents can read the catalog, and Google’s documentation is clear about who owns the customer: “You remain the Merchant of Record for all transactions.” Its Universal Cart, expanded in May 2026, holds items across retailers.
ACP (Agentic Commerce Protocol), maintained by OpenAI and Stripe, specifies how a business receives an agent purchase request and how a payment credential is delegated to complete it. Its April 2026 release added cart and product feeds alongside the checkout and payment APIs. It’s still in beta.
The sentence that ends the rivalry framing isn’t from an analyst, but Google’s own UCP merchant documentation: “UCP is fully compatible with protocols such as AP2, A2A, and MCP.” The same page tells merchants to “pick the communication medium that best suits their development needs such as APIs, MCP, or A2A.” The protocol most often cast as ACP’s chief rival treats interoperability with the rest of the stack as a selling point. Anyone still scoring it like a matchup is working from a 2025 map.
This is where the shortlist gets made, where your brand appears or doesn’t, before anyone decides anything.
Floor Three: Identity
Your league already separates two questions you’ve never had to weigh on their own: 1) Is the person logging in actually your manager, not just someone with her password? and 2) What is she allowed to do once she’s in? The first question is answered on this floor.
For years, merchants trained their systems to treat automated traffic as hostile. Agentic commerce now asks them to learn that some of it is a customer with a credit card.
Visa Trusted Agent Protocol, introduced in October 2025, lets a merchant distinguish an agent shopping for a real consumer from a bot worth blocking. What it conspicuously does not do is move money. Visa’s own specification is payment-method agnostic: It confirms that the shopper is real, then steps out of the way. The actual payment moves through whatever rail the merchant already runs, MCP or ACP among them. It’s a wrapper, not a rail, a distinction often blurred in coverage of card network protocols.
Mastercard Agent Pay, unveiled in April 2025, is the comparable acceptance framework on Mastercard rails. In June 2026, Agent Pay for Machines extended the work to continuous machine-initiated payments.
Both networks are built for a world with several standards. Nobody designs for interoperability expecting to be alone on the field. Note what is being verified: the agent. The person who wants the thing is upstream of anything the merchant sees.
Floor Four: Authorization
This is the commissioner’s settings. Not who’s logging in, but what a manager can do once they are—the rules that bound auto-draft before it picks.
AP2 (Agent Payments Protocol) is the authorization-layer open standard here, announced by Google in September 2025 with more than 60 partners, donated to the FIDO Alliance in April 2026. Its mechanism is the mandate: a cryptographically signed artifact proving an agent has permission for this purchase, at this scope, at this moment. It still carries a pre-1.0 version number, so details are subject to change.
Identity asks who’s knocking. Authorization asks what they are allowed to do.
Floor Five: Settlement
Money moves.
Your league has a version of this. Auction drafts run on budgets you can overspend. Free Agent Acquisition Budget (FAAB) bidding spends a balance down over a season. Everything a settlement layer does, except move funds.
Settlement runs mostly on existing rails: card networks, processors, and infrastructure that has cleared payments for years. The genuinely new entrant is narrower than the coverage suggests.
x402 takes a status code that’s sat idle since the 1990s—402 “Payment Required,” reserved for a use case nobody ever built—and gives it one: software paying software one request at a time. An agent paying an API, not a parent buying a backpack. Coinbase contributed it to the Linux Foundation, which announced the x402 Foundation in April 2026 and stood it up operationally in July with 40 members including Visa, Mastercard, Stripe, Google, and AWS. This is machine-to-machine infrastructure, not yet the consumer purchase story. What lands at the end of a consumer purchase is a valid order with no path attached.
One Acronym, Four Protocols
ACP is four things. There’s the aforementioned Agentic Commerce Protocol. There’s Agent Client Protocol, which standardizes how coding agents talk to code editors, live and unrelated to commerce. Then there are two that no longer stand on their own: IBM’s Agent Communication Protocol, whose project page now points readers to an A2A migration guide, and the AGNTCY collective’s Agent Connect Protocol, whose specification repository was archived in April.
All four names still turn up in the same coverage, and if a deck cites ACP without spelling it out, you won’t know which floor the vendor is standing on, so you’ll want to ask.
The Reversal Nobody Priced In
The surface expected to define the category retreated.
OpenAI pulled back Instant Checkout in March 2026, turning ChatGPT toward discovery, sending shoppers to the retailer’s own site to finish. Agentic commerce’s flagship act-mode experience reverted to advice. The protocol underneath it continued; its specification picked up a new version the following month.
Auto-draft turned back into a start/sit tool. The button belonged to a company. The standard didn’t.
Now look at what the protocols cast as rivals actually did. December 9, 2025: MCP anchors the launch of the Agentic AI Foundation. April 2, 2026: x402 goes to the Linux Foundation. April 24: Stripe, which co-maintains ACP, joins the technical council steering UCP. April 28: AP2 goes to FIDO. August 17: A2A moves into the Agentic AI Foundation alongside MCP.
Four protocols often framed as a matchup handed themselves to shared governance, and the fifth is a company helping govern the standard it was cast against. Nobody hands a playbook to the league office mid-season. This is not a rivalry. It’s plumbing getting plumbed.
Advice Mode Leaves No Click; Execution Mode Leaves No Session
Both modes break the same instrument from opposite ends.
Your league logs every pick the agent makes for you: timestamped, ordered, attributable. Likewise, commerce agents leave records: orders, credentials, mandates, API calls. These aren’t the trail marketers are used to reading: recommendations, alternatives discarded, the media exposure creating demand, the link between conversation and conversion.
When an agent advises, influence happens inside a conversation, then conversion happens elsewhere. When an agent acts, the merchant receives a valid order and payment record with no familiar referral path explaining what produced it. As Back to School 2026 laid out, last season’s problem was an impression the measurement stack could see but couldn’t credit. This one is a decision trail the stack never receives.
This is a measurement puzzle, not a plumbing problem. None of the five floors solves it. They are the game tape, not the adjustment: evidence of which handoff occurred, not why the demand existed.
When the Trail Is the Thing That’s Missing
Each floor takes something different: session, impression, intent, path. Last-touch attribution reads what survives. Marketing mix modeling reads the market around the paths that no longer exist. Incrementality testing settles what the others cannot: Did the activity change an outcome? Kochava applies all three, because no single method can reconstruct a trail the consumer experience no longer produces.
The Roster That Survives the Season
The manager who wins isn’t the one who drafts best on day one. They’re the one whose roster still functions in December, after the injuries, waiver moves, and the foundational pick that doesn’t survive the season.
Instant Checkout was a foundational pick, but one week into the season, it was off the board.
The protocols underneath are still standing, with more members than they had at launch.
Build on the standard, not on any one company’s button. Ask of every agent touching your business: Does it advise or act? Then ask which floor grants permission.
Your team drafted itself. It’s still your team.


