Canonical definition

Shared Payment Token (ACP) – Definition

A Shared Payment Token (SPT) is a single-use payment token in the Agentic Commerce Protocol. An AI agent gets it from a payment provider and passes it to the merchant instead of a card number. The token works for one merchant, one checkout and one charge, up to a set amount and until it expires.

In one sentence

A card that works once, for one shop and one amount – so an agent can pay without holding the real card number.

How it works

  1. The shopper approves a purchase in the agent’s interface.
  2. The agent’s platform sends the payment method to the payment provider’s delegate_payment endpoint, with an allowance.
  3. The provider returns a token, for example vt_01J8Z3WXYZ9ABC.
  4. The agent passes the token to the merchant with the checkout.
  5. The merchant charges it through its own payment provider, as the merchant of record.

The agent never sends the card number to the merchant, and the merchant never has to trust the agent with it.

The allowance: what limits the token

In ACP 2026-04-17 every delegated token carries an allowance with six required fields:

FieldMeaning
reasonUsage pattern. Currently only one_time
max_amountMaximum charge, in minor units (for example 7999 for $79.99)
currencyISO 4217 code, lowercase, for example usd
checkout_session_idThe checkout this payment is for
merchant_idThe only merchant allowed to use it
expires_atWhen the token stops working

So a leaked token is worth little: one merchant, one checkout, one charge, up to a fixed amount, for a limited time.

Two units, two places

The allowance uses minor units. The ACP product feed writes prices differently, as 79.99 USD. Mixing the two is a common bug.

Where it stands in 2026

The token is part of ACP’s checkout flow. In March 2026 OpenAI moved away from checkout inside ChatGPT, so most ChatGPT purchases now finish on the merchant’s site and never use a delegated token. It still matters for agents that complete checkout themselves. Stripe issues these tokens as a payment provider; other providers can implement the same delegate_payment API. AP2 solves a related problem – proof that the shopper authorised the payment – with signed mandates instead.

Questions

What is a Shared Payment Token?
A single-use payment token in the Agentic Commerce Protocol. It lets an AI agent pass a payment to a merchant without sharing the card number, limited to one merchant, one checkout, a maximum amount and an expiry time.
What is an allowance in ACP?
The limits attached to a delegated payment token: usage reason (one_time), maximum amount, currency, checkout session, merchant and expiry time.
Does the merchant see the card number?
No. The merchant receives the token and charges it through its payment provider.
Does ChatGPT use Shared Payment Tokens?
Since March 2026 most ChatGPT purchases complete on the merchant’s own site, so the token is not used for them. It remains part of ACP for agents that complete checkout.
Is a Shared Payment Token the same as AP2?
No. The token carries a limited payment credential. AP2 uses signed mandates to prove the shopper authorised a payment.

Related

Sources

Checked 28 September 2026 against the ACP repository: spec/2026-04-17 (openapi.delegate_payment.yaml, schema.delegate_payment.json) and rfcs/rfc.payment_handlers.md.