What do these words mean?
Every term this site uses, defined in plain language. Each entry stands on its own. The first sentence of each entry is the exact definition used everywhere else on this site.
58 terms in six groups. Every entry has a stable anchor that will not change, so you can link straight to any term.
Core concepts
- Agent economy
- The agent economy is a market like any other, with one difference: many of the buyers and sellers are AI agents acting for people. The goods are mostly digital — data, processing, tool access. It is growing, and much of what is claimed about it cannot yet be checked. This site explains it in plain terms and publishes only numbers you can recompute.
- Agentic commerce
- Agentic commerce is ordinary buying and selling with the purchase handed to software: an AI agent buys or sells services on a person’s or company’s behalf. The person — the operator — sets the budget and the rules. The agent does the finding, agreeing, and paying.
- AI agent
- An AI agent is software given a goal and hands: it pursues the goal by taking actions — calling tools, making purchases — with limited supervision. A chatbot answers; an agent acts. This site’s recurring example is OTTO, an invoicing agent that buys text extraction from scanned pages (OCR) at $0.01 per page to do its job.
- Autonomy level
- An autonomy level is basically the length of an agent’s leash: how much it may do between human check-ins. Low autonomy means a person approves each action — a human-in-the-loop. High autonomy means the agent acts alone inside its mandate.
- Human-in-the-loop
- Human-in-the-loop is a built-in stop for approval: a checkpoint where a person must approve an agent’s action before it happens. In commerce, the checkpoint usually sits right before payment. The agent prepares the purchase; a person says yes or no.
- Intent
- An intent is a signed order form for software: a structured, provable statement of what a buyer authorized before the purchase happened. If a purchase is questioned later, the intent shows what was actually approved. Verifiable Intent is a card-network specification built on this idea.
- Machine-to-machine (M2M) payment
- A machine-to-machine (M2M) payment is a normal payment with no human on either side: the buyer and the seller are both software. When OTTO — this site’s example invoicing agent — pays $0.01 for one page of text extraction, that is an M2M payment. No person watches the transaction; only the record it leaves.
- Mandate
- A mandate is a standing permission slip an operator gives an agent: what it may buy, and up to what amount. Inside the mandate, the agent acts alone. Outside it, the agent must come back and ask. The mandate is the central object of the AP2 protocol.
- Micropayment
- A micropayment is an ordinary payment shrunk below what card fees normally allow: from fractions of a cent to a few dollars. It is only practical when fees are near zero. OTTO’s $0.01-per-page purchases of text extraction are micropayments.
- Operator
- An operator is the person or company an agent acts for — the employer who sets its budget and its rules. If you run an agent, you are its operator. Every agent purchase traces back to an operator’s permission, usually written down as a mandate.
Payments & rails
- Agent Pay
- Agent Pay is Mastercard’s program for agent-initiated card payments: card payments where the buyer pressing the button is authorized software. It pairs with Verifiable Intent, the specification for proving what the buyer authorized.
- AP2 (Agent Payments Protocol)
- AP2 (Agent Payments Protocol) is a permission system for agent spending: a Google-backed open protocol that authorizes agent payments through mandates. It sits above the movement of money — it defines who may pay and under what permission, while payment rails move the funds. Its specification is public. See mandate for its central object.
- Base
- Base is an Ethereum layer-2 network: a public ledger that runs on top of Ethereum, tuned for lower fees and faster confirmation. It matters here because x402 payments settle in USDC on Base. Those payments are on-chain, so anyone can inspect them — which is what makes independent verification possible.
- Facilitator
- A facilitator is a payment processor for the x402 world: a service that verifies and settles x402 payments on a seller’s behalf. The seller never has to touch the ledger directly. The facilitator checks the payment and confirms settlement.
- Gas fee
- A gas fee is the postage on a public-ledger transaction: a small network fee paid to get it processed. Layer-2 networks exist partly to make these fees tiny — which is what makes micropayments practical.
- HTTP 402 “Payment Required”
- HTTP 402 “Payment Required” is a web status code, like 404 “Not Found” — reserved in the 1990s for future payment use, and now used in earnest. A server answers 402 to say: pay first, then ask again. The x402 protocol is built on it. The code is defined in the HTTP standard, RFC 9110.
- Layer-2 (L2)
- A layer-2 (L2) is an express lane built on top of a main public ledger: faster and cheaper, and it settles its results back to the main network. Base, the network where x402 payments settle, is a layer-2 on Ethereum.
- On-chain
- On-chain means recorded on a public ledger that anyone can inspect — a public record book for transactions. On-chain payments are what make independent verification possible: if the money moved on-chain, anyone can recompute the numbers about it.
- Payment rail
- A payment rail is the plumbing underneath a payment: the network that actually moves the money. Card networks are rails; stablecoin networks are rails. This site covers four agent-payment rails as peers: AP2 & UCP, Stripe machine payments, Verifiable Intent & Agent Pay, and x402.
- Settlement
- Settlement is the moment a payment stops being a promise: the money has actually, irreversibly moved. On stablecoin rails, settlement is fast and final. On card rails, a settled-looking payment can still be reversed later by a chargeback.
- Stablecoin
- A stablecoin is a digital token designed to behave like a dollar bill: it aims to hold a fixed value, usually one US dollar. Its job is to not change price. Agents use stablecoins because software can hold and send them directly, without a bank account in the loop.
- UCP
- UCP is a Google-backed commerce protocol for the broader shopping flow — discovery, offers, checkout — rather than the payment step alone. This site covers it alongside AP2, its payments-side sibling.
- USDC
- USDC is a specific dollar stablecoin, issued by Circle: one token designed to equal one US dollar. It is the stablecoin that x402 payments settle in today. Because those payments happen on a public ledger, anyone can check them. Circle documents USDC on its own site.
- Verifiable Intent
- Verifiable Intent is a card-network specification for proving what a buyer authorized: a checkable order form the network can inspect before money moves. It is the Mastercard-side answer to a core question of agentic commerce: did someone actually approve this? It pairs with Agent Pay. See intent for the underlying idea.
- Wallet
- A wallet is software that can approve payments — for an agent, its spending hand, holding a balance its operator controls. Technically it holds secret keys, and the keys sign the payments. The money itself lives on the ledger; the wallet holds the authority to move it.
- x402
- x402 is an open protocol that revives the web’s dormant 402 status code so services can charge machines per request. The flow: an agent asks for a resource, receives a 402 answer with payment details, pays — in USDC on the Base network, through a facilitator — then asks again and is served. Its specification is public.
Stripe & card-rail mechanics
- ACP (Agentic Commerce Protocol)
- ACP (Agentic Commerce Protocol) is a Stripe-linked specification for checkout inside a conversation: the purchase completes where the chat is happening, instead of on the seller’s website. It belongs to the card-rail side of agentic commerce, alongside Stripe machine payments.
- Spending cap
- A spending cap is a hard ceiling on what an agent can spend, per purchase or per period — a limit on a company card. The cap holds even when the agent misjudges. OTTO, this site’s example invoicing agent, can keep buying $0.01 pages of text extraction only until its cap says stop.
- Stripe machine payments
- Stripe machine payments is card infrastructure re-cut for software buyers: Stripe’s rails for agent purchases, including payment credentials scoped to a single agent. An agent gets its own credential with its own limits — often a virtual card with a spending cap — instead of borrowing a human’s card.
- Virtual card / single-use card
- A virtual card is a card number that exists only in software — often issued for a single agent purchase, so a leaked number is worth almost nothing. By the time anyone could misuse it, it is already spent or already expired.
Protocols & standards
- MCP (Model Context Protocol)
- MCP (Model Context Protocol) is a universal adapter between AI agents and services: one standard way for an agent to connect to tools. Many sellers in the agent economy are reachable through MCP. Its specification is public.
- MCP server
- An MCP server is a service an agent can call through MCP — a shop with a standard doorway. The agent connects, sees what tools are on offer, and makes tool calls. Many sellers in the agent economy take this form.
- Offer-receipt (v0.6)
- Offer-receipt is an x402 extension standard that staples the promise to the proof: it links what a seller offered to what was actually delivered. A payment receipt alone proves money moved, not that the work was done. Offer-receipt closes part of that gap. First approved at version 0.5 in January 2026; the current revision is v0.6.
- Open standard
- An open standard is a specification anyone can read and implement without asking permission — a public recipe, not a house secret. Whether a rail’s specification is open is one of the neutral facts this site records for every rail.
- OWASP agentic security
- OWASP agentic security is community guidance on the security risks specific to AI agents, from OWASP, the open web-security nonprofit. It covers what can go wrong when software acts with authority: stolen credentials, manipulated instructions, runaway tools. The guidance is published by the OWASP GenAI Security Project.
- Protocol
- A protocol is a set of agreed rules that lets two systems work together without negotiating first — both sides already speak the same language. Payment protocols agree on how to ask, how to pay, and how to confirm. That agreement is what lets strangers’ software transact at all.
- SEP-2828
- SEP-2828 is a proposal for signed execution receipts — machine-checkable records of what an agent actually ran, not just what it paid for. It began in the MCP standards process, was withdrawn there, and continues as an IETF draft. Not a finished standard. See cryptographic receipt for the idea it builds on.
- Tool call
- A tool call is a single action an agent takes through a connected service — one press of one button, done by software. When OTTO, this site’s example invoicing agent, sends one page for text extraction, that is one tool call. Per-call pricing charges for exactly this unit.
- x402 Foundation
- The x402 Foundation is the body that stewards the x402 protocol — a caretaker for the specification rather than an owner of it. See x402 for the protocol itself.
Trust & verification
- Attestation
- An attestation is a signed statement by an identified party that something is true — a notarized claim, in machine form. Its value depends on who signed it and what the signer could actually know.
- Audit trail
- An audit trail is the recorded sequence of events that lets you reconstruct what happened — a flight recorder for transactions. In agentic commerce the trail runs from mandate to offer to payment to delivery. Where the trail has gaps, disputes get stuck.
- Concentration risk
- Concentration risk is the situation of a business with one big customer: a seller whose revenue depends on very few buyers. Revenue from a handful of buyers can vanish overnight — and can also be a sign of self-dealing. Buyer spread is one of the signals this site’s verification method is built to examine.
- Cryptographic receipt
- A cryptographic receipt is a store receipt that cannot be forged: a signed, checkable proof that a payment happened. Proving the payment is the easy half. Proving the delivery is what standards such as offer-receipt aim to add.
- Dust
- Dust is loose change too small to mean anything: payment amounts too tiny to indicate real usage. Dust inflates naive statistics, so verification filters it out. The exact threshold is defined in this site’s method specification, not in this glossary.
- Listing farm
- A listing farm is one actor flooding a catalog with low-quality listings — stuffing the shelves to game discovery. The catalog then looks bigger than the economy behind it. Farm detection is part of what this site’s verification method screens for.
- Provenance
- Provenance is the paper trail behind a claim: the traceable origin of a number, a statement, or a piece of work. Every number this site publishes carries its provenance — a source, an as-of date, and a way to recompute it.
- Recomputable
- Recomputable means you can re-derive a number yourself from public data — you do not have to take anyone’s word for it, including ours. It is this site’s bar for publishing any number. Chain-derived numbers recompute from the public ledger; catalog-snapshot numbers recompute from an archived snapshot — a weaker but still checkable form.
- Signature (cryptographic)
- A cryptographic signature is a handwritten signature made of math: it proves who created a message and that no one altered it. Wallets sign payments with them. Receipts and attestations are only as strong as the signatures on them.
- Sybil
- A sybil is one actor pretending to be many independent ones — a crowd of puppets moved by one hand. Sybil buyers can fake demand for a seller. Telling real crowds from puppet crowds is a core problem of any open marketplace.
- Trust verdict
- A trust verdict is a pre-spend decision: an answer to “is this seller safe to pay?”, delivered before the money moves. A receipt tells you what happened. A verdict tells you whether to proceed.
- Verification
- Verification is checking a claim against evidence instead of taking it on faith — the difference between “they said so” and “we checked.” In the agent economy, on-chain payments make some checking possible for anyone. This site’s job is to do that checking, and to show its work.
- Verified revenue
- Verified revenue is revenue confirmed from public chain data, not self-reported — and attributed per seller address, not per listing. One address may stand behind several listings; those listings share the attribution. The precise technical definition — thresholds, time windows — is fixed in this site’s method specification and will be quoted here verbatim once the verification engine is live.
- Wash trading / fake volume
- Wash trading is paying yourself to fake demand: money circling between accounts that one actor controls. The volume is real on the ledger and meaningless in the market. Filtering it out is part of what separates verified revenue from raw volume.
Boundaries & recourse
- Chargeback
- A chargeback is a card payment pulled back after the fact: the card network reverses the charge on the buyer’s behalf. Card rails have chargebacks; stablecoin rails deliberately do not. That difference is one of the core tradeoffs between the rails.
- Custody
- Custody is holding someone else’s money — a bank’s job, carrying a bank’s obligations. It is regulated territory. This site explains custody; it never takes custody of anything.
- Dispute
- A dispute is the formal process for contesting a bad transaction — where such a process exists. Card rails ship with dispute machinery built in, including the chargeback. Stablecoin rails settle with finality, so any dispute process has to be built on top.
- KYC/AML
- KYC/AML is the ID check at the bank counter, written into law: know-your-customer and anti-money-laundering rules for the financial system. They apply wherever agent money touches the traditional system — for example, converting stablecoins into bank-account dollars. Factual context only; nothing on this site is legal advice.
- Real-buyer filter
- A real-buyer filter separates production buyers from noise: test traffic, dust, and self-dealing. It is one of the signals behind verified revenue on this site. “Real buyer” names the filter only — the published label is always “verified.”
Last reviewed: 2026-09-01. Spotted an error? Tell us.