Shared Payment Token (ACP) – Definition
A Shared Payment Token (SPT) is a single-use payment token in the Agentic Commerce Protocol. An AI agent gets it from a payment provider and passes it to the merchant instead of a card number. The token works for one merchant, one checkout and one charge, up to a set amount and until it expires.
A card that works once, for one shop and one amount – so an agent can pay without holding the real card number.
How it works
- The shopper approves a purchase in the agent’s interface.
- The agent’s platform sends the payment method to the payment provider’s
delegate_paymentendpoint, with an allowance. - The provider returns a token, for example
vt_01J8Z3WXYZ9ABC. - The agent passes the token to the merchant with the checkout.
- The merchant charges it through its own payment provider, as the merchant of record.
The agent never sends the card number to the merchant, and the merchant never has to trust the agent with it.
The allowance: what limits the token
In ACP 2026-04-17 every delegated token carries an allowance with six required fields:
| Field | Meaning |
|---|---|
reason | Usage pattern. Currently only one_time |
max_amount | Maximum charge, in minor units (for example 7999 for $79.99) |
currency | ISO 4217 code, lowercase, for example usd |
checkout_session_id | The checkout this payment is for |
merchant_id | The only merchant allowed to use it |
expires_at | When the token stops working |
So a leaked token is worth little: one merchant, one checkout, one charge, up to a fixed amount, for a limited time.
The allowance uses minor units. The ACP product feed writes prices differently, as 79.99 USD. Mixing the two is a common bug.
Where it stands in 2026
The token is part of ACP’s checkout flow. In March 2026 OpenAI moved away from checkout inside ChatGPT, so most ChatGPT purchases now finish on the merchant’s site and never use a delegated token. It still matters for agents that complete checkout themselves. Stripe issues these tokens as a payment provider; other providers can implement the same delegate_payment API. AP2 solves a related problem – proof that the shopper authorised the payment – with signed mandates instead.
Questions
- What is a Shared Payment Token?
- A single-use payment token in the Agentic Commerce Protocol. It lets an AI agent pass a payment to a merchant without sharing the card number, limited to one merchant, one checkout, a maximum amount and an expiry time.
- What is an allowance in ACP?
- The limits attached to a delegated payment token: usage reason (one_time), maximum amount, currency, checkout session, merchant and expiry time.
- Does the merchant see the card number?
- No. The merchant receives the token and charges it through its payment provider.
- Does ChatGPT use Shared Payment Tokens?
- Since March 2026 most ChatGPT purchases complete on the merchant’s own site, so the token is not used for them. It remains part of ACP for agents that complete checkout.
- Is a Shared Payment Token the same as AP2?
- No. The token carries a limited payment credential. AP2 uses signed mandates to prove the shopper authorised a payment.
Related
- ACP – definition
- Agentic checkout – definition
- Merchant of record – definition
- AP2 – definition
- ACP vs UCP for Magento 2