AgentCore payments — autonomous payment execution
AgentCore payments lets an agent or application pay for paid APIs, MCP servers and web content. ProcessPayment validates the request, checks session spending limits, signs the transaction through the configured external wallet provider (Coinbase or Stripe Privy) and returns payment proof for the merchant, using the x402 protocol or the Machine Payments Protocol (MPP). AgentCore payments is payment infrastructure for agents, not an AI model.
Recorded characteristics
- Function
- Operational path: agent/application → AgentCore payments → PaymentSession → PaymentInstrument → configured external payment provider/wallet → payment proof/transaction → external merchant or paid resource. ProcessPayment (paymentType CRYPTO_X402 or MPP) validates the request, checks the active session's spending against configured limits (denying it if limits would be exceeded), retrieves wallet credentials from AgentCore Identity, signs the transaction through the configured PaymentConnector and returns signed payment proof; the agent then retries the original request with the proof (X-PAYMENT header for x402, Authorization header for MPP). Supported framework integrations (Strands Agents plugin, LangGraph middleware) can automatically react to HTTP 402 responses, process payment and retry with payment proof. This is not native AgentCore payments scheduling or event triggering: payment occurs when the agent encounters a paid resource.
- Data access
- Uses the PaymentManager's workload identity in AgentCore Identity to retrieve stored payment-provider credentials; operates on the specified PaymentInstrument (an embedded stablecoin wallet scoped to a user ID) within a PaymentSession. Observability: ProcessPayment telemetry can include payment manager, connector, instrument, session, spend amount and currency, remaining session budget, merchant and agent name where supplied. This does not establish anything about downstream merchant audit records.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Not established
- Permission basis
- Mixed
- Administrative control
- Separation of duties: AWS documents a five-role IAM model separating administrator (control plane), management (sessions/instruments), agent execution (ProcessPayment), service operations (ResourceRetrievalRole) and AWS Marketplace subscription (Coinbase only). AWS warns against granting PaymentSession write permissions (e.g. CreatePaymentSession) and ProcessPayment in the same role, because the caller could bypass payment limits by creating new sessions with elevated budgets. Spending controls: each PaymentSession has an expiry time and an optional budget (maxSpendAmount, currency); further payments are denied once the session expires or the budget is reached. These are automated policy controls, not human confirmation.
- Default state
- Disabled
- Availability
- Generally available (AWS announcement 18 Aug 2026; preview launched May 2026) in the AWS Regions AWS lists. Not usable merely because AgentCore exists: a PaymentManager, PaymentConnector with provider credentials, a funded PaymentInstrument with delegated signing granted by the end user, a PaymentSession and the relevant IAM authority must all be configured first.
- Licensing
- Charged under AgentCore pricing; wallet providers are Coinbase (CDP) and Stripe (Privy).
- External model or provider
- No fixed AI model: AgentCore payments is payment infrastructure; reasoning comes from whatever agent/framework the developer builds. External payment providers: Coinbase, Stripe (Privy).
- Limitations and uncertainty
- Human confirmation not_established: AWS documents prior authorisation (funding the wallet, end-user delegation of signing authority, IAM permission, session creation, spending limits) and autonomous payment execution, but no universal platform-enforced human approval immediately before each individual payment. Those prior authorisations are not runtime human confirmation. Framework integrations raise interrupts on payment failure, which is not per-payment approval. Permission basis recorded as mixed because multiple distinct runtime authority mechanisms are documented: the caller's IAM ProcessPayment (payment execution) authority, the PaymentManager's service role/workload identity that retrieves wallet credentials, and the end user's delegated wallet signing authority at the external provider; AWS deliberately separates management from execution authority. Unresolved: whether behaviour, limits and proofs are identical across Coinbase and Stripe Privy; no universal maximum transaction limit is documented beyond the configured session budget; downstream merchant audit records are not established; exact delegated-signing mechanics at each provider are provider-defined. Not credited: unrestricted spending, mandatory per-payment human approval, native payment scheduling or event triggers. Documentation contradiction check: no stale Preview wording found on the current developer-guide pages reviewed on 2 Oct 2026.
Evidence
- How AgentCore payments works
Supports: Function · Actions · External actions · Data access · Permission basis · Default state · Primary source
Agents autonomously pay for APIs, MCP servers and web content via x402 or MPP; payment flow with limit check, signing, retry.
ProcessPayment signs the transaction through the configured external partner and returns proof.
Payment signed through external wallet provider and proof submitted to the merchant.
Wallet credentials retrieved from AgentCore Identity via the PaymentManager workload identity.
PaymentManager specifies authorizer type and IAM role; service provisions a workload identity.
Manager, connector, instrument and session must be configured before payments can be processed.
- Amazon Bedrock AgentCore payments: Enable secure microtransaction payments for AI agents
Supports: General · Admin controls · External model · Primary source
AgentCore payments is a fully managed service within AgentCore for agent microtransactions.
PaymentSession budget (maxSpendAmount, currency) and expiry; payments denied when exceeded.
Wallet integration with CoinbaseCDP and Stripe (Privy).
- Processing payments — Amazon Bedrock AgentCore
Supports: Default state · Primary source
Data plane workflows follow control plane setup: create instrument, session, then process payment.
- Process a payment — Amazon Bedrock AgentCore
Supports: Actions · External actions · Function · Primary source
ProcessPayment validates, checks budget, signs on blockchain, returns signed result.
Agent retries merchant request with signed proof (X-PAYMENT) or MPP credential (Authorization).
Supports CRYPTO_X402 and MPP payment types.
- ProcessPayment — Amazon Bedrock AgentCore Data Plane API Reference
Supports: Actions · Data access · Primary source
API processes a payment using a payment instrument within a payment session.
Request carries user ID and agent name headers, instrument, session and manager ARN.
- IAM roles for AgentCore payments
Supports: Permission basis · Admin controls · Human confirmation · Primary source
Five-role IAM model separating administrator, management, agent execution, service operations and Marketplace roles.
Warns against combining session write permissions and ProcessPayment in one role (limit bypass).
Authority is granted through IAM roles in advance; no per-payment human approval step documented.
- AgentCore payments observability
Supports: Admin controls · Primary source
ProcessPayment telemetry: manager, connector, instrument, session, spend, remaining budget, merchant, agent name.
- Framework integrations for AgentCore payments
Supports: Function · Human confirmation · Primary source
Strands plugin and LangGraph middleware automatically handle HTTP 402 responses and retry.
Plugin raises interrupts on payment failure; no per-payment approval documented.
- AgentCore payments is now generally available in Amazon Bedrock AgentCore
Supports: Availability · Licensing · Primary source
General availability announced 18 Aug 2026 as a capability within Amazon Bedrock AgentCore.
Pricing under AgentCore pricing.