Skip to content

Rank #4 of 7 in Agentic Commerce

PayPal Agentic Commerce logo

PayPal Agentic Commerce

PayPal, Inc. · commercial

191131/yrnpm 608/wk

Try itExperimental

See what an agent can do with PayPal Agentic Commerce before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server PayPal documents for agentsrecorded session — replayed, not live
recorded 2026-09-14 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agent checkout — stories about agent checkout in this arenaAgent checkoutevidence →

Stories about agent checkout in this arena

46.8/100

Agent discovery — stories about agent discovery in this arenaAgent discoveryevidence →

Stories about agent discovery in this arena

25.5/100

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

39.2/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

0.0/100

Fees economics — stories about fees economics in this arenaFees economicsevidence →

Stories about fees economics in this arena

32.0/100

Merchant enablement — stories about merchant enablement in this arenaMerchant enablementevidence →

Stories about merchant enablement in this arena

12.9/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

18.0/100

Order lifecycle — stories about order lifecycle in this arenaOrder lifecycleevidence →

Stories about order lifecycle in this arena

32.4/100

Payment credentials — stories about payment credentials in this arenaPayment credentialsevidence →

Stories about payment credentials in this arena

9.8/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Protocol openness — stories about protocol openness in this arenaProtocol opennessevidence →

Stories about protocol openness in this arena

0.0/100

Refunds disputes — stories about refunds disputes in this arenaRefunds disputesevidence →

Stories about refunds disputes in this arena

36.0/100

Trust safety — stories about trust safety in this arenaTrust safetyevidence →

Stories about trust safety in this arena

9.0/100

Story verdicts — every judged story with its evidenceStory verdicts

What’s free: 0 free · 1 paid · 0 enterprise · 26 not stated in evidence

?

Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10T

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3noneuntestednone yet

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full7/10C

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1full8/10C

My agent can create and update a cart or order draft through a documented protocol call C

Cart

ai-native userAgent checkout — stories about agent checkout in this arenaAgent checkout3full8/10C

Hand my agent a scoped, limited-use payment credential — amount limits, expiry, merchant restrictions — instead of a raw card number C

Delegated credentials

ai-native userPayment credentials — stories about payment credentials in this arenaPayment credentials3partial6/10C

My agent can complete a purchase end-to-end — checkout session, delegated payment credential, confirmed order C

Checkout

ai-native userAgent checkout — stories about agent checkout in this arenaAgent checkout3partial6/10T

Publish my product or service catalog into agent surfaces through a documented feed or import API so AI agents can discover what I sell C

Merchant feeds

merchantAgent discovery — stories about agent discovery in this arenaAgent discovery3partial6/10C

I have a documented self-serve path to start accepting agent traffic — enable a setting, sign an agreement, or publish an endpoint C

Onboarding to agents

merchantMerchant enablement — stories about merchant enablement in this arenaMerchant enablement3partial5/10C

My agent or backend can subscribe to order lifecycle events — created, updated, fulfilled, canceled — pushed programmatically C

Order events

developerOrder lifecycle — stories about order lifecycle in this arenaOrder lifecycle3partial5/10C

Sensitive agent spending requires my documented approval — a confirmation step, signed mandate, or per-purchase consent — before money moves C

Human oversight

ai-native userTrust safety — stories about trust safety in this arenaTrust safety3partial5/10C

My agent can programmatically search products or services across merchants — keylessly or with self-service credentials, no private partnership required C

Agent search

ai-native userAgent discovery — stories about agent discovery in this arenaAgent discovery3disputed3/10D

Agents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots C

Agent identity

merchantTrust safety — stories about trust safety in this arenaTrust safety3none0/10

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3none0/10

The commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything C

Spec publication

developerProtocol openness — stories about protocol openness in this arenaProtocol openness3none0/10

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3n/auntestednone yet

Monetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI C

Machine payments

developerPayment credentials — stories about payment credentials in this arenaPayment credentials3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Provision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility C

Wallets

ai-native userPayment credentials — stories about payment credentials in this arenaPayment credentials3noneuntestednone yet

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3n/auntestednone yet

Buyers can complete purchases of my products inside chat and assistant surfaces (ChatGPT, Claude, Gemini, Copilot and peers) C

Embedded surfaces

merchantAgent checkout — stories about agent checkout in this arenaAgent checkout2partial6/10T

Disputes and chargebacks on agent transactions can be handled via API — evidence submission, status, outcomes C

Disputes

developerRefunds disputes — stories about refunds disputes in this arenaRefunds disputes2partial6/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10C

My agent can query the status and tracking of an order it placed, after the purchase C

Post purchase status

ai-native userOrder lifecycle — stories about order lifecycle in this arenaOrder lifecycle2partial6/10T

Refunds on agent-placed orders can be initiated and tracked programmatically C

Refunds

developerRefunds disputes — stories about refunds disputes in this arenaRefunds disputes2partial6/10T

My agent can discover payable services and APIs through a published directory or discovery index C

Service discovery

ai-native userAgent discovery — stories about agent discovery in this arenaAgent discovery2partial5/10T

Read machine-readable offer data — price, availability, variants, checkout links — for any listed product or service C

Machine readable offers

developerAgent discovery — stories about agent discovery in this arenaAgent discovery2partial5/10C

The fees for agent-originated transactions are published — I can price agentic channels without asking sales C

Fees transparency

merchantFees economics — stories about fees economics in this arenaFees economics2partialpaid5/10C

Build against a versioned commerce protocol with a published schema and conformance or validation tooling C

Protocol conformance

developerAgent checkout — stories about agent checkout in this arenaAgent checkout2partial4/10C

At least two independent parties beyond the vendor implement the protocol or platform — it is an ecosystem, not a private integration C

Ecosystem adoption

developerProtocol openness — stories about protocol openness in this arenaProtocol openness2none0/10

Orders are attributed to the originating agent and I can report on or filter transactions by agent C

Attribution analytics

merchantMerchant enablement — stories about merchant enablement in this arenaMerchant enablement2none0/10

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2none0/10

Rate-limit, allow, or deny specific agents and agent platforms accessing my catalog and checkout C

Traffic controls

merchantMerchant enablement — stories about merchant enablement in this arenaMerchant enablement2none0/10

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2none0/10

Set per-agent spend caps and usage limits and revoke an agent's payment authority instantly G

Spend controls

ai-native userTrust safety — stories about trust safety in this arenaTrust safety2none0/10

Settle agent-initiated payments in stablecoins over documented rails C

Settlement rails

developerPayment credentials — stories about payment credentials in this arenaPayment credentials2none0/10

The fraud, liability, and chargeback rules for agent-initiated transactions are documented so I know who bears the risk C

Liability

merchantTrust safety — stories about trust safety in this arenaTrust safety2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Agent-originated payments settle through documented payout and reporting flows, reconcilable like any other channel C

Payouts

merchantFees economics — stories about fees economics in this arenaFees economics1partial6/10C

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 42 stories with headroom

What would move PayPal Agentic Commerce’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product

    nonemoves Built-in AIimpact 45

    The evidence pack is entirely about PayPal enabling external AI agents (ChatGPT, Gemini, third-party MCP clients, or developer-built agents via the Agent Toolkit) to transact through PayPal/Braintree — it is infrastructure for other assistants to use PayPal, not a built-in AI assistant inside PayPal's own product that an end user delegates tasks to.

  2. Trust safety — stories about trust safety in this arenaAgents identify themselves verifiably — registered profiles, signatures, or trust tiers — so I can tell trusted agent traffic from anonymous bots

    nonemoves PA Scoreimpact 30

    PayPal's docs describe payment-token authentication (Braintree single-use tokens bound to merchant ID), PayPal-issued JWTs for verifying that requests come from PayPal's own Shopping Cart service, and webhook signature verification — but none of this constitutes a verifiable agent identity system (no registered agent profiles, agent-level signatures, or trust tiers that would let a merchant distinguish which specific AI agent or bot is originating traffic).

  3. Payment credentials — stories about payment credentials in this arenaProvision a wallet my agent holds and spends from — funded and controlled by me, with balance visibility

    nonemoves PA Scoreimpact 30

    All evidence describes merchant-side infrastructure (Agent Ready, Store Sync, agent toolkit, cart APIs) that lets AI agents check out with merchants or lets merchants build agents for order/refund/dispute management — none of it describes a consumer-provisioned wallet that a user funds, an agent holds/spends from, with balance visibility.

  4. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    Missing: any rule-builder/automation-trigger UI or API, conditional logic definition, and evidence of automatic action execution tied to rules rather than manual webhook handling.

  5. Payment credentials — stories about payment credentials in this arenaMonetize an API or service with HTTP 402 machine payments that agents pay per call without a checkout UI

    nonemoves PA Scoreimpact 30

    All evidence describes PayPal's agentic commerce as checkout-flow based (carts, ACP/UCP delegated tokens, Store Sync, agent toolkit for orders/refunds/disputes) — none of it describes HTTP 402 status-code machine payments or per-call API monetization without a checkout UI, which is a distinct technical pattern.

  6. Protocol openness — stories about protocol openness in this arenaThe commerce protocol this product speaks is published as an open, versioned specification I can read and implement without signing anything

    nonemoves PA Scoreimpact 30

    The evidence pack shows PayPal implements OpenAI's ACP and Google's UCP protocols and tells developers to 'follow the ACP agentic checkout specification,' but never provides or links a version number, license, or spec document for ACP/UCP that a developer could read independently of PayPal.

  7. Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product

    nonemoves Built-in AIimpact 30

    Evidence documents PayPal's agentic commerce stack (Agent Ready, Store Sync, cart APIs, agent toolkit, MCP server) purely as infrastructure enabling AI agents to browse catalogs, create carts, and complete transactions on a merchant's behalf — none of it shows PayPal analyzing a user's/merchant's own data to surface AI-generated insights or suggestions inside the product (e.g., analytics dashboards, business recommendations).

  8. Agenticness — how well agents can access and operate the productUse an official CLI

    nonemoves agent-readyimpact 30

    The evidence pack documents PayPal's Agent Toolkit, MCP server, REST APIs, and SDKs, but nowhere mentions an official command-line interface (CLI) tool for developers or AI-native users to interact with PayPal's agentic commerce services.

Showing the top 8 of 42 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map9 surfaces · 28 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

AI tools docs21 stories

API reference19 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>' # the remote MCP server PayPal documents for agentsreproduced
$ curl -si -X POST https://mcp.paypal.com/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'  # the remote MCP server PayPal documents for agents
HTTP/2 401

www-authenticate: Bearer realm="OAuth", resource_metadata="https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp", error="invalid_[redacted]", error_description="Missing or invalid access [redacted]"
$curl -s https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp # public OAuth resource metadatareproduced
$ curl -s https://mcp.paypal.com/.well-known/oauth-protected-resource/mcp  # public OAuth resource metadata
{"resource":"https://mcp.paypal.com/mcp","authorization_servers":["https://mcp.paypal.com"],"scopes_supported":["openid","email","profile"],"bearer_methods_supported":["header"]}
$npm view @paypal/agent-toolkit versionreproduced
$ npm view @paypal/agent-toolkit version
agent-toolkit version: 1.11.0

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

8 of 22 testable claims verified · 2 contradictedintegrity 18/100

33 distinct capability claims found in PayPal Agentic Commerce’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

8

Verified

12

Unverified

2

Contradicted

7

Undersold

Verified (15)
Unverified (25)
Contradicted (2)
Undersold (7)
Claims outside our story set (3)

Real capability claims found in PayPal Agentic Commerce’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Store Sync preserves merchant control over brand appearance and customer communications for AI-powered transactions

    source ↗
  • Store Sync currently only supports physical goods sold to US-based customers in USD — no digital goods, subscriptions, or international sales

    source ↗
  • Webhook authenticity can be verified via PayPal's verify-signature endpoint

    source ↗
Suggest a story for these →

Business model

usage-basedenterprise-custom

Agent flows ride standard PayPal/Braintree processing (PayPal Checkout 3.49% + fixed fee, cards 2.99% + fixed fee in the US); no separate published price for agent-originated traffic.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score31 (Sep 15 '26)27 (Sep 15 '26)
Agent-ready61 (Sep 15 '26)62 (Sep 15 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

⚿ auth1 auth-gated probe