Research paper · Agentic financial infrastructure

The State of Execution Harnesses for Agentic Payments

Breaking down the seven-layer agentic payments stack and identifying the missing execution harness that makes financial agents efficient, reliable, and operational.

Bottom line

Agentic payments are a seven-layer stack that begins with adaptive demand and ends in deterministic settlement. Most layers already have clear categories: applications, runtimes, wallets, payment protocols, money infrastructure, and settlement rails. Legal and clinical AI show the broader specialization pattern: general models become operational through domain knowledge, structured workflows, controls, and outcome-specific evaluation. Financial execution needs its own domain-specific harness: machinery that reliably carries an agent's intent across the seven layers and proves that the requested outcome occurred.

1

The seven-layer agentic payments stack

We identify seven layers that together carry an agentic payment from an adaptive goal to deterministic movement of value. Each layer owns a distinct responsibility, and no single protocol, wallet, runtime, or rail represents the whole system.

Reading downward, agent surfaces originate demand; runtimes maintain the task; domain execution converts a plan into concrete actions; wallets and mandates control authority; payment protocols coordinate acceptance; funding systems supply value; and settlement rails provide finality. Trust, security, compliance, observability, and reconciliation cut horizontally across all seven layers.

Figure 1Seven layers from adaptive demand to deterministic settlement
01
Agent surfaces and vertical applications

Own the user or business workflow; capture goals, context, preferences, and consent

ChatGPTGeminiAmazon RufusPayPalBankrVirtualspartner-built agent apps
02
Agent runtime and orchestration

Run the model loop, memory, tools, scheduling, retries, state, background work, and multi-step coordination

Aomi LabsBankrCoinbase AgentKitGOATElizaOSVirtuals GAMELangChainCrewAI
03
Domain execution and transaction construction

Translate a plan into an exact API call, order, contract invocation, or transaction batch; simulate and reconcile the result

Aomi Labs1inchdeBridgeUniswapKrakenCrossmintexchanges
04
Identity, mandates, wallets, and signing

Prove who the agent represents, define what it may do, protect credentials, and decide whether to sign

AP2VisaMastercardCoinbaseMetaMaskOKXCirclePrivyTurnkeySafeFireblocks
05
Payment coordination and acceptance protocols

Describe price, accepted methods, required proof, and how the service is delivered

x402MPPACPUCP
06
Money, funding, and treasury infrastructure

Supply stable value, bridge fiat and crypto, manage balances and liquidity, and reconcile books

CircleTetherPayPalStripeBridgeCoinbaseCrossmintMoonPayBVNKZero Hashbanks
07
Settlement rails

Final, deterministic movement and record of value

BaseSolanaEthereum L2sPolygonTempoArcVisaMastercardbank rails
Horizontal assurancesimulationcompliancethreat detectionobservabilityreconciliationdisputes
A company may operate across several layers. The taxonomy assigns functions, not permanent identities. Assurance—simulation, compliance, threat detection, observability, disputes, and reconciliation—cuts horizontally across the stack.

This stack is the paper's starting point. It separates adjacent markets before asking where responsibility is still incomplete. The gap appears between adaptive planning and financial authority: someone must construct, test, execute, recover, and reconcile the action across the other layers. Section 5 names that missing category only after the market evidence and boundaries are clear.

2

Scope, definitions, and methodology

2.1 What counts as an agentic payment?

A conventional automated payment follows predetermined code: send a fixed amount on a fixed date. An agentic payment contains an adaptive decision step: find a compliant supplier under a budget, choose a route, determine the amount or timing, and pay. The agent may decide what, when, where, or how much within a delegated mandate.

A complete agentic payment requires more than a checkout button. It runs through seven stages, and the stages do not share the same character: the first three are adaptive and reversible, while the last four must be deterministic.

Figure 2The seven stages of a complete agentic payment
01Intent

A user, company, or agent defines a goal and the constraints around it.

02Planning

An agent discovers services, compares options, and proposes an action.

03Construction

Software converts that proposal into a concrete order, transaction, or payment request.

04Authorization

Deterministic rules bind the action to user consent, credentials, limits, and compliance checks.

05Funding

A wallet, account, card token, or stablecoin balance supplies value.

06Settlement

A blockchain, card network, bank rail, or hybrid processor finalizes movement.

07Reconciliation

The system confirms delivery, receipts, balance changes, refunds, and exceptions.

Probabilistic reasoningDeterministic authority and settlement
Stages 1–3 are adaptive and still reversible. Stage 4 is the authorization boundary: a deterministic decision about whether the constructed request may use financial authority. Stages 5–7 must fund, settle, and reconcile without reinterpreting the instruction.

Agentic payments overlap with two larger categories but are not synonymous with either. Agentic commerce includes discovery, comparison, ordering, fulfillment, returns, and support; payment is one stage. Agentic finance includes trading, treasury, hedging, lending, compliance, and portfolio operations; not every financial action is a payment. A crypto agent that only analyzes or communicates becomes a payment actor only when it can request or authorize value transfer.

Figure 3Finance is the umbrella. Payments are one action class.
Agentic finance

Research · trading · treasury · lending · risk · compliance · financial operations

Agentic payments

Authorize · route · transfer · settle · reconcile

Agentic commerce

Discover · compare · negotiate · procure · book

Useful test

A payment moves value. Finance decides how capital should be understood, allocated, protected, or operated.

UmbrellaSubsetOverlap
Agentic payments are a subset of agentic finance and an action inside commerce workflows. Commerce and finance overlap, but neither contains the other. The diagram maps responsibilities, not company categories.

2.2 The probabilistic–deterministic boundary

The IMF's 2026 model separates agentic payments into intent and orchestration, control and authorization, and settlement.[1]That separation captures the core safety property: an agent may reason, search, negotiate, and propose, but a deterministic boundary must decide whether a concrete request may use financial authority, and a deterministic rail must settle without reinterpreting the instruction. This paper expands the commercial and technical space between those three institutional layers.

2.3 Research method

The analysis combines official protocol specifications, first-party product documentation, independent onchain evidence, and Aomi Labs' operating perspective. The market taxonomy, player map, and use-case maturity assessments extend an earlier ecosystem deep dive published by Aomi Labs Research in August 2026, which remains the underlying survey for this paper.[17] Product capabilities are treated as vendor claims unless independently demonstrated. Transaction activity is evidence of technical use, not automatically evidence of durable or autonomous demand. The market taxonomy is analytical: firms often span multiple layers, and placement reflects the function being evaluated rather than the company as a whole.

Included

Machine payments, commerce mandates, crypto wallets, stablecoins, agent runtimes, DeFi execution, treasury, security, and reconciliation.

Excluded

Generic AI fraud models, infrastructure with no agent-facing role, and speculative tokens whose only connection is an “AI agent” label.

Evidence hierarchy

Specifications first; then official technical documentation; then independent market evidence; finally internal hypotheses and positioning.

Research limitation

The same-model execution advantage is proposed as a benchmark. No unrun comparison is presented as a measured result.

3

The seven-layer ecosystem

The seven-layer model becomes useful when it assigns each function to the actors that actually perform it. A protocol, wallet, runtime, funding provider, or settlement rail may span several layers, but no one label should be mistaken for the whole system.

Layer 1 — Agent surfaces and vertical applications

Agent surfaces own the user or business workflow and originate demand. OpenAI and Stripe's Agentic Commerce Protocol, for example, allows a conversational surface to pass a structured order and a scoped payment token to a merchant while the merchant retains responsibility for acceptance and fulfillment.[9] Crypto surfaces go further. Bankr combines a conversational agent, wallet, cross-chain trading, scheduled automations, and x402 service access in one runtime.[16] Virtuals' EconomyOS gives agents identity, wallets, permissions, jobs, and programmable capital, with its own Agent Commerce Protocol for inter-agent work.[25] That Virtuals “ACP” is a different specification from the Stripe and OpenAI Agentic Commerce Protocol despite the shared acronym.

Layer 2 — Agent runtime and orchestration

Beneath the surface, runtimes own sessions, memory, tools, retries, background work, and multistep state. Toolkits and runtimes should be distinguished: Coinbase describes AgentKit as a modular, framework- and wallet-agnostic system of action providers and wallet providers.[6] A stateful execution runtime goes further by owning the path to completion and the evidence left behind.

Layer 3 — Domain execution and transaction construction

Domain-execution providers then supply the exact mechanics of a swap, bridge, order, checkout, staking operation, or protocol call. This is where generic tool calling becomes domain execution: ABI handling, route selection, calldata construction, balance and allowance checks, slippage, gas, bridge state, failure semantics, and post-execution verification. Vertical providers are strong while the action stays inside their domain — 1inch Business MCP for swaps and portfolios, deBridge MCP for cross-chain routing, Uniswap skills for liquidity workflows, Kraken CLI and MCP for exchange trading and staking, Crossmint for agentic checkout and merchant-of-record flows. The unresolved question is whether execution consolidates into broad runtimes or remains a federation of protocol-owned tools. The likely answer is both: broad runtimes orchestrate, while specialists own routes, liquidity, inventory, and domain-specific guarantees.

Layer 4 — Identity, mandates, wallets, and signing

Layer four is becoming the center of competition. Google's AP2 binds an agent's action to cryptographically verifiable mandates describing identity, scope, limits, and conditions, and includes an x402 extension for stablecoin payments.[4]Visa's Trusted Agent Protocol helps a merchant recognize an approved agent and verify cryptographically signed commerce intent; Mastercard Agent Pay extends tokenized credentials and network controls to agents.[10][11] Crypto wallets are evolving from key stores into programmable authorization systems with:

  • isolated keys, or MPC and TEE signing
  • per-transaction and cumulative spend limits
  • merchant, protocol, contract, function, asset, and chain allowlists
  • session and time-bound permissions
  • human escalation above thresholds
  • audit logs, revocation, and emergency stops
  • simulation, threat scanning, and compliance screening

The crypto-native wallet models are diverging rather than converging. Coinbase Agentic Wallets isolate keys in a TEE and add session and transaction caps, KYT screening, x402, and gasless trading on Base.[12] MetaMask Agent Wallet stays self-custodial and makes simulation mandatory, with Blockaid scanning, MEV protection, spend limits, allowlists, and human 2FA escalation.[13] OKX pairs TEE-protected keys and risk scoring with gas-free X Layer use across nearly twenty chains.[22] Privy provides server wallets and scoped browser authorization while Turnkey evaluates signing policies inside secure enclaves.[14][15] MoonPay's Open Wallet Standard proposes an open agent-to-wallet interface with a local encrypted vault and multichain signing.[24] Crossmint and Circle instead sell the full stack: wallets, policies, funding, payment protocols, and service access in one integration.[23][19]

Layer 5 — Payment coordination and acceptance protocols

Layer five tells an agent what is for sale, how much it costs, which payment methods are accepted, what proof is required, and how the service is delivered. These protocol families are frequently conflated and should not be.

Table 1. Protocol families and what each one actually standardizes
Protocol familyPrimary jobExamplesCrypto role
Machine paymentsPay for an HTTP resource, API, MCP tool, session, or servicex402, MPPNative stablecoin settlement; MPP also bridges to fiat methods
Commerce workflowDiscovery, cart, order, checkout, fulfillment, post-purchaseACP, UCPCrypto can be one payment method underneath
Mandates and trustProve user intent, agent identity, scope, and authorizationAP2, Visa Trusted Agent Protocol, Mastercard Agent PayCan authorize stablecoin or card payments
Tool and agent communicationExpose tools and coordinate agentsMCP, A2APayment can be layered onto calls; these are not payment rails

The distinction in the last row matters most. MCP and A2A expose tools and coordinate agents; payment can be layered onto their calls, but they are not payment rails. Within machine payments, x402 facilitators verify signed payloads and submit settlement without custodying funds.[20] MPP, co-authored by Stripe and Tempo, coordinates payment for APIs, MCP tools, and HTTP endpoints and supports microtransactions and recurring charges, reaching stablecoins, cards, and buy-now-pay-later methods while preserving tax, fraud, reporting, refunds, and normal merchant payouts.[3] ACP and UCP address commerce rather than raw payment: ACP lets an agent surface pass a structured order and scoped token to a merchant who remains responsible for acceptance, tax, fulfillment, and returns, while UCP standardizes discovery and checkout across surfaces. The competitive boundary is whether merchants adopt an open protocol directly or rely on an orchestrator — Stripe, Coinbase, Circle, Crossmint, Bankr — to hide the protocol complexity.

Layer 6 — Money, funding, and treasury infrastructure

Stablecoins are the default crypto asset for agentic payments because agents need predictable unit pricing, 24/7 availability, global reach, programmability, and settlement smaller than card-network minimum economics. Circle claims USDC represents 99.8% of x402 transaction value and has built agent wallets, nanopayments, a CLI, skills, and a service marketplace around that position.[19] Treat that percentage as a current vendor-reported ecosystem statistic, not a permanent market share.

Funding remains the bottleneck. An agent wallet without reliable onramps, treasury policies, gas sponsorship, balance monitoring, FX, and accounting is only a demo — which is why full-stack providers keep bundling these functions rather than leaving customers to assemble separate wallet, onramp, facilitator, and compliance vendors.

Layer 7 — Settlement rails

At layer seven, different rails win different jobs. Base offers cheap EVM settlement with x402 and Coinbase distribution; Solana offers throughput and low fees with strong stablecoin and marketplace activity; Tempo is payment-optimized and the native home for MPP sessions and streaming payments;[27] Ethereum and its L2s hold the deepest programmable-finance and account-abstraction ecosystem; card networks retain unmatched merchant acceptance, disputes, consumer protection, and issuer controls; bank rails carry regulated account-to-account flows, payroll, and fiat-native settlement. The likely endpoint is cross-rail orchestration, not a crypto-only or card-only world.

3.1 Horizontal assurance across all seven layers

Trust, security, compliance, and observability do not sit at one level. They cut across all seven, and the controls divide cleanly by when they run.

Before construction

Tool permissions, service allowlists, prompt and data provenance.

During construction

ABI and type validation, quote freshness, slippage and recipient checks.

Before signing

Fork simulation, balance-delta inspection, threat scanning, sanctions and KYT screening, policy evaluation.

During settlement

Idempotency, replay protection, MEV protection, confirmation thresholds.

After settlement

Receipts, delivery proof, reconciliation, anomaly monitoring, refunds, disputes, and incident response.

Chainalysis combines KYT, sanctions screening, fraud intelligence, and pre-signing threat detection, and argues for auditable autonomy rather than unconstrained automation.[26] This horizontal layer is likely to become a major standalone market precisely because neither a model nor a wallet can independently validate the entire economic outcome. These responsibilities can be vertically integrated for convenience, but they carry different competencies and liabilities, and mature buyers will require the boundaries to remain inspectable even when one provider bundles several layers.

4

Emerging service sectors, evidence, and maturity

4.1 Emerging service sectors

Financial agents need more than access to money. To operate beyond demos, they must receive bounded authority, find trustworthy counterparties, execute correctly, choose the right rail, and remain accountable after settlement. Each unresolved need creates a market for specialized infrastructure.

Authority must be both programmable and attributable. Credentials need isolation, mandates must encode scope and limits, and merchants must know which agent is acting for which principal. This creates two related but distinct markets: wallets that control access to money, and identity, mandate, and reputation systems that establish the legitimacy of its use.[12][14][15]

Markets must also become legible and usable by software. Agents need structured descriptions of services, prices, schemas, and delivery terms; sellers need gateways that abstract verification and settlement. Discovery without reputation becomes spam, while payment without delivery proof invites fraud, so marketplaces will increasingly incorporate attestations, service histories, and escrow.

A valid payment is not necessarily a correct action. Systems must test transaction semantics before signing, verify the resulting state, and select among stablecoin, card, bank, and local rails according to the task's economic and regulatory requirements. This separates execution assurance, which determines what should happen, from payment orchestration, which determines how value should move.

Finally, autonomous spending must close the operational loop. Every balance change, receipt, gas cost, refund, and tax event must map back to an agent, mandate, task, user, and result. When the result is wrong, settlement finality is insufficient; the system still needs proof of delivery, recourse, and a clear allocation of liability.

Agent wallets as programmable authority

Programmable accounts that isolate credentials, enforce scoped mandates, support human escalation, and preserve an audit trail.

Coinbase, MetaMask, OKX, Circle, Crossmint, Privy, Turnkey, MoonPay, Cobo, Fireblocks, Safe

Payment facilitators and protocol gateways

Infrastructure that verifies payment proofs, submits settlement, and hides rail-specific complexity from sellers and developers.

x402 facilitators, Stripe, Coinbase, Circle, Crossmint

Agent-native discovery and marketplaces

Machine-readable directories for finding services, comparing prices and schemas, and evaluating delivery histories.

Circle Agent Marketplace, Bankr x402 Cloud, x402scan, Pay.sh, Agentic.Market, Virtuals

Execution assurance and semantic simulation

Protocol-aware construction, simulation, outcome assertions, and evidence that test what an action will do before it is signed.

Aomi Labs, Tenderly, Blockaid, wallet security providers, specialized risk engines

Know Your Agent, mandates, and reputation

Identity and authorization systems that establish which agent is acting, for whom, within what limits, and with whose liability.

AP2, Visa Trusted Agent Protocol, Mastercard Agent Pay, OAuth/OIDC, verifiable credentials, onchain registries

Cross-rail payment orchestration

Routing that selects stablecoin, card, bank, or local rails by cost, availability, reversibility, and compliance.

Stripe, Crossmint, PayPal, Visa, Mastercard, Circle, BVNK, Coinbase

Agent treasury, accounting, tax, and reconciliation

Back-office systems that attribute balances, gas, receipts, refunds, and tax events to the correct agent, mandate, task, and user.

An underbuilt operating layer for fleets of autonomous accounts

Disputes, insurance, and service-level guarantees

Proof of delivery, signed receipts, escrow, refunds, and liability mechanisms for failures that settlement finality cannot resolve.

An emerging assurance layer spanning models, runtimes, wallets, facilitators, merchants, issuers, and rails

4.2 Market evidence

Evidence now appears across all eight service sectors, but they are not maturing at the same rate.

Productization is clearest in authority, identity, discovery, and payment access. Coinbase, Circle, MetaMask, Privy, Turnkey, and OKX now offer agent wallets or delegated controls.[12][13][14][15][19][22] Google's AP2, Visa Trusted Agent Protocol, and Mastercard Agent Pay formalize mandates and agent recognition.[4][10][11] Circle has launched an agent marketplace alongside wallets and nanopayments, while x402 and MPP supply gateway protocols.[2][3] Usage is material but noisy: Chainalysis measured more than 100 million x402 transactions on Base through Q1 2026, while Solana reports more than 35 million transactions and over $10 million in volume. Speculative activity drove part of the earlier surge, so these figures demonstrate technical reach rather than durable autonomous demand.[5][18]

Execution and operations are also taking shape. Tenderly offers live-state simulation, Blockaid exposes agent-focused transaction scanning and threat detection, and Crossmint routes cards and stablecoins under common controls.[31][32][23] Stripe carries MPP payments into existing tax, reporting, accounting, and refund systems.[3] Evidence weakens after settlement: treasury and reconciliation mostly extend general payment tooling, while Visa and Artemis find no settled way to unwind disputes across chains of agents.[33] The market is therefore broader than x402: the first six sectors are productizing, while agent-native back-office and recourse remain open categories.

4.3 Use-case maturity

Use cases mature fastest when the purchased object is digital, the price is machine-readable, fulfillment is immediate, and failure is reversible or low value. They mature more slowly as physical fulfillment, regulated advice, custody, credit, cross-border compliance, or ambiguous liability enters the workflow.

Figure 4Use-case maturity versus workflow and liability complexity
Early productionLive or expandingEmergingPilotDigital, metered, reversibleSemantic and counterparty riskPhysical, regulated, cross-borderWorkflow and liability complexity →Crypto-native rails sufficientTraditional rails also requiredPay-per-call APIsBrowser & infra sessionsCompliance workflowsDeFi tradingDigital-goods micropaymentsConsumer shoppingCross-chain routingAgent-to-agent servicesProcurement & expenseAgent revenue & payoutsTreasury & FX2026 maturity →Assessed market sizeniche → very large
Maturity is read from Table 2, which follows. Complexity and market size are assessments, not measurements, so the axes are drawn as named zones and bubble area as four steps rather than numeric scales. Size asks how much spend a category could eventually address, which is why treasury and procurement stay large while sitting low on maturity. Colour restates the maturity band. The trend is the report's own claim — value falls as physical fulfilment, regulated advice, custody, credit, or ambiguous liability enters the workflow — and the informative part is the exception. Compliance and investigation workflows sit high on complexity and high on maturity because a human stays accountable at the end of them.
Table 2. Representative use cases and 2026 maturity
Use caseWhy agents helpBest-fit rails2026 maturity
Pay-per-call APIs, data, inference, and computeDiscover, price, pay, and continue without accounts or subscriptionsx402, MPP, stablecoinsEarly production; strongest product-market fit
Browser, storage, and infrastructure sessionsUsage is ephemeral and metered; payment attaches to each sessionMPP, x402, cards or stablecoinsEarly production
Agent-to-agent servicesSpecialized agents subcontract research, data, execution, or verificationx402, MPP, marketplacesEmerging; discovery, reputation, and delivery proof remain weak
Consumer shopping, travel, and subscriptionsSearch, compare, negotiate, and check out under a mandateACP, UCP, AP2 plus cards, wallets, or stablecoinsExpanding launches; merchant operations matter more than rail novelty
DeFi trading and portfolio managementContinuous monitoring and machine-speed executionAgent wallets, smart accounts, EVM and SolanaLive but high risk; mostly crypto-native users
Cross-chain swaps and liquidity routingCompare routes, fees, timing, and destination requirementsBridges, DEX aggregators, smart accountsLive with specialized tools; bridge-state complexity remains
Corporate procurement and expenseSource vendors, create orders, enforce budgets, and reconcile receiptsAgent cards, AP2, ERP-connected processors, stablecoinsEmerging enterprise category
Treasury, FX, and cross-borderOptimize timing, liquidity, rail, compliance, and exceptionsStablecoins, bank rails, cards, and local networksPilots; high regulatory and liability burden
Content and digital-goods micropaymentsRemove subscriptions and login friction for one-off accessx402, MPPTechnically live; demand and pricing still being discovered
Agent revenue, payouts, and self-fundingCharge for services and fund computeStablecoin wallets, x402 endpoints, marketplacesEmerging; service revenue is stronger than speculative token launches
Compliance and investigation workflowsEnrich alerts, trace funds, and run deterministic playbooksEnterprise systems with blockchain dataEarly production or beta; humans remain accountable

This sequence explains crypto's early advantage. Wallets are programmatic accounts; stablecoins provide internet-native value; and blockchains settle globally at machine speed. Those properties are especially valuable for low-value digital services and crypto-native financial actions. They are less decisive in consumer commerce, where merchant reach, refunds, fraud allocation, tax, and fulfillment usually matter more than the novelty of the rail.

5

The missing execution harness

The seven-layer map reveals a responsibility that the market has not consistently named: carrying an agent's adaptive plan into a concrete, inspectable, and reconciled financial outcome.

General-purpose agents can already reach financial destinations. They can browse documentation, discover a tool, infer its schema, create a payment or transaction, recover from an error, and inspect a receipt. Yet they often do so the way a person travels on foot: one uncertain step at a time, repeatedly paying in reasoning, tokens, latency, and operational risk.

Faster models improve that walk. They do not remove the economic reason to build vehicles. In mature technical systems, repeated integration knowledge, safety checks, and recovery logic move out of general reasoning and into software. The model remains the intelligence; an execution harness carries the known mechanics.

A payment protocol can coordinate a handshake, and a wallet can decide whether to sign. Neither can independently establish that an adaptive financial task was correctly completed.

Consider an instruction to bridge an asset, pay for a service on the destination chain, and return a receipt. The agent must interpret constraints, select a bridge and service, obtain quotes, construct approvals and calls, reason about destination gas, handle changing state, preserve the request reviewed by the signer, recover from a partial bridge, prevent duplicate payment, verify delivery, and reconcile the final balances. A wallet can enforce a spend cap. A simulator can test a concrete transaction. A chain can prove finality. None alone can connect the semantic objective to the whole sequence of evidence.

Central thesis

As agentic finance matures, execution harnesses become standard infrastructure because they increase verified outcomes per unit of model reasoning, time, money, and human attention. Their interfaces may commoditize; their execution quality will not.

5.1 Definition

An execution harness is the runtime machinery that converts adaptive intent into bounded, inspectable, and reconcilable financial action. It is more than a toolkit because it owns state, recovery, and completion. It is broader than a policy layer because policy does not construct or reconcile the task. It remains separate from the wallet because the wallet must retain the independent power to refuse.

The harness does not replace the seven payment stages in Figure 2; it decomposes the work inside them. Its responsibilities cover stages one through three, the simulation that precedes the authorization request, and the reconciliation that closes the task. It never owns stage four. Authority stays with the wallet, funding with the balance, and finality with the rail.

Figure 5The execution lifecycle and its authority boundary
01Interpret

Bind an adaptive goal to assets, counterparties, timing, budget, and desired state.

Stage 1
02Select

Choose tools, protocols, routes, and payment methods from a controlled capability set.

Stage 2
03Construct

Produce exact orders, calldata, approvals, batches, and payment payloads.

Stage 3
04Simulate

Evaluate the concrete action against relevant state before authority is requested.

Stage 3→4
05Authorize

Bind an immutable request to a wallet or policy boundary that can refuse.

Stage 4 · external
06Execute

Submit once, manage idempotency, and distinguish partial from complete work.

Stages 5–6 · external rails
07Reconcile

Compare receipts and final state with the original objective and preserve evidence.

Stage 7
Execution harnessExternal authority
Each responsibility is annotated with the payment stage from Figure 2 that it serves. The critical output is an evidence chain linking original intent, selected capability, constructed payload, simulation, authorization decision, signer, receipt, and final state.

5.2 Why better models do not eliminate the category

General models will continue to improve at documentation discovery, schema inference, tool use, and error recovery. That lowers the cost of walking; it does not change the value of a tested route. Mature systems do not ask a model to rediscover stable protocol knowledge, allowance rules, idempotency semantics, receipt formats, or balance assertions on every run. They encode those mechanics and reserve model reasoning for decisions that are genuinely adaptive.

Legal and clinical AI provide an instructive precedent, even though those companies do not necessarily use the term “harness.” Harvey distinguishes individual models from model systems, agents, and workflows. Its legal workflows combine task-specific tools and knowledge sources with structured steps, citation requirements, human review, and evaluations based on completed legal work.[28] Abridge turns clinical conversations into billable, EHR-integrated notes and actionable outputs, tying drafts back to source information for clinician review.[29] Hippocratic AI describes a safety process built around output testing, clinical supervision, escalation to human nurses, and cross-validation against real interactions.[30]

The shared pattern is not simply more domain knowledge. Stable professional mechanics move out of repeated prompting and into software that owns workflow, evidence, review, and evaluation. Financial execution follows the same pattern with a stricter end state: the output can move assets irreversibly. Its domain-specific harness must therefore own transaction construction, simulation, immutable authorization handoff, idempotency, recovery, and reconciliation—not merely produce a more informed financial answer.

The analogy must be applied strictly. A poor vehicle can be slower than walking. A harness that hides failures, constrains a capable model, increases retries, or cannot demonstrate the final state has not earned its abstraction. The relevant comparison is the same athlete on the same course: one model and task set, with and without the harness.

6

Player map and market structure

Early markets reward full-stack products because developers prefer one API and users prefer one trusted surface. Coinbase, Circle, Crossmint, Stripe, Bankr, and OKX therefore span layers. Yet specialization is likely to deepen because each layer has a distinct technical competency, distribution advantage, and liability model. Models optimize reasoning; runtimes manage state; wallets control authority; protocols coordinate; issuers manage money; rails provide finality; risk vendors provide independent evidence. As stakes rise, buyers will demand modularity and independent checks.

Table 3. Player map. Layer numbers refer to the seven-layer model; “horizontal” means trust, compliance, or security across layers
PlayerPrimary layersWhat it ownsStrategic position
Aomi Labs2–3Hosted onchain runtime, tools, construction, simulation, state, and reconciliationResearch and infrastructure focused on execution harnesses above wallets
Coinbase2–7AgentKit, Agentic Wallets, x402, facilitator, stablecoin access, BaseMost vertically integrated crypto stack; wallet and Base distribution are key
Circle4–6USDC, agent wallets, nanopayments, CLI, skills, marketplaceAttempts to make the stablecoin issuer the operating system for agent money
Stripe and Bridge5–7ACP, MPP, x402 support, Link wallet, merchant processing, fiat and stablecoin payoutsBridges agent protocols to existing merchant operations and payment methods
Crossmint3–6Agent wallets, cards, onramps, checkout, merchant-of-record, credentialsDeveloper-facing full-stack agent payments API across crypto and cards
Bankr1–5Consumer runtime, wallet, trading, automations, x402 Cloud and discoveryCrypto-native vertical integration and self-funding-agent narrative
Virtuals1–5Agent launch, identity, wallets, jobs, capital, and coordinationAgent economy and marketplace; strong in agent ownership and coordination
MetaMask4 + horizontalSelf-custodial wallet, policy, simulation, threat and MEV protectionWallet distribution and security brand; moving upward into agent execution
OKX1, 3–4Agentic Wallet, OnchainOS, multichain execution and exchange liquidityCombines wallet, exchange, and route distribution
Privy4Embedded and server wallets, scoped authorization, policiesModular wallet infrastructure for builders owning the rest of the stack
Turnkey4Enclave signing, policy evaluation, delegated credentials, auditabilitySecurity-first signing infrastructure for production and institutional agents
MoonPay4, 6Open Wallet Standard, onramps, agent cards, multichain accessConnects open agent wallets to consumer funding and card acceptance
Google1, 4–5Gemini surfaces, UCP, AP2 mandates, A2A ecosystemStandards and distribution; interoperable fiat and crypto authorization
OpenAI1, 5ChatGPT commerce surface and ACP with StripeDemand aggregation and conversational distribution
Visa4–7Trusted-agent recognition, credentials, issuer and acquirer network, acceptanceExtends existing trust, disputes, and merchant acceptance to agents
Mastercard4–7Agentic Tokens, Agent Pay, card and machine-payment networkSimilar network strategy, increasingly bridging stablecoins and machines
PayPal1, 5–7Consumer wallet, merchant graph, checkout, protection, agent distributionClosed-loop trust and merchant reach; hybrid agent commerce
1inch, Uniswap, deBridge, Kraken3Protocol or venue-specific tools, skills, MCP servers, liquidity and executionOwn domain depth and routes; suppliers to broader runtimes
Alchemy and Pimlico4–7Smart accounts, bundlers, paymasters, gas sponsorship, RPCAccount-abstraction infrastructure under wallets and runtimes
Base, Solana, Tempo, Ethereum L2s7Low-cost programmable settlement and ecosystemsCompete on cost, finality, liquidity, distribution, and protocol support
Chainalysis, Blockaid, TRM, Tenderly, HypernativeHorizontalKYT, fraud, simulation, threat detection, monitoring, incident responseIndependent evidence layer; benefits from provider fragmentation

6.1 Market structure and competitive dynamics

Wallets own the strongest distribution moat. They already control assets, trust, signing, and the gateway to settlement, which gives MetaMask, Coinbase, OKX, Phantom, and institutional custody providers a path upward into agent controls and execution. Runtimes should treat wallets as distribution and authority partners rather than as competitors to displace.

Protocols converge by function, not toward one standard. x402 and MPP overlap in machine payments; ACP and UCP overlap in commerce workflows; AP2, Visa, and Mastercard focus on mandates and trusted agents; MCP and A2A coordinate tools and agents. These can coexist because they solve different parts of the journey. Durable providers will support several protocols while preserving one stable internal authorization and accounting model.

Stablecoins are the crypto wedge, not the whole product. They solve global, programmable, low-value settlement. They do not solve agent identity, merchant acceptance, delivery disputes, refunds, taxes, wallet policy, or safe construction. The market will reward teams that pair stablecoins with those missing layers.

Transaction counts can mislead. The x402 data is promising but should not be presented as pure autonomous-agent adoption. Chainalysis attributes a major Q4 2025 spike to meme-coin pay-to-mint loops and holds that mass adoption remains distant.[5]

Taken together, these dynamics set the bar for anyone in layers two and three. Payment platforms can move inward from money movement into orchestration; vertical providers can dominate high-frequency domains through route, venue, or inventory depth; general agent frameworks can move downward through wallet and payment plugins. Execution runtimes must therefore prove that they are materially better at generalized completion and evidence, not merely better at exposing transactions to an LLM.

7

Harness economics and measurement

Model tokens are not the only operational cost, but they reveal the underlying inefficiency. When an agent rereads documentation, reconstructs schemas, reasons through stable allowance mechanics, retries stale routes, or investigates whether a task finished, the system is buying cognition to compensate for missing infrastructure. Harness value comes from moving repeated cognition into software, compressing the failure surface, and making operations legible.

This produces a stricter economic claim than “agents work better with tools.” A useful harness should increase the number of verified outcomes obtained from a fixed model budget. It should also preserve model optionality: operators can improve or replace the model without rebuilding every financial integration and control around it.

Figure 6A same-model benchmark for execution leverage
BaselineGeneral tools

Model discovers interfaces, reconstructs mechanics, recovers from failures, and verifies completion during each run.

same model
same tasks
HarnessedTested execution path

Software supplies typed actions, simulation, state, recovery, payload binding, and outcome assertions.

Execution leverageverified outcomes÷tokens + time + failures + intervention
Hold the model, prompt, task suite, signer policy, starting state, and market conditions constant. Score the resulting world state—not the fluency of the transcript.

7.1 Proposed scorecard

Task success

Did the requested financial state change occur?

Tokens per verified outcome

How much model reasoning was consumed by completed work?

Time, calls, and retries

How much latency, wandering, and recovery occurred?

Human intervention

How often did the system need rescue rather than intentional approval?

Unsafe proposals blocked

Did it reject structurally valid but harmful actions?

Simulation consistency

Was the signed payload the reviewed payload, and did execution match simulation?

Duplicate-broadcast rate

Did retries create repeated payments or transactions?

End-state evidence

Can the result be tied back to intent, authority, receipts, and final state?

The benchmark should include ordinary success and adversarial state: stale quotes, changed allowances, rejected signatures, insufficient destination gas, partial bridge completion, delayed confirmation, unavailable tools, malicious content, and repeated network requests. A harness is valuable only if its advantage survives these conditions.

8

Aomi Labs’ thesis

Our thesis at Aomi Labs is that agentic finance will require a distinct execution-harness layer. Our work focuses on its onchain instance: infrastructure that turns agent intent into verified financial execution across payment and non-payment actions.

That work sits primarily in layers two and three: runtime orchestration and domain execution. It encompasses the agent loop, tools, sessions, persistence, and multistep state; translates intent into typed actions and transactions; simulates expected outcomes; and prepares a concrete request for an external signer.[7][8]Wallets, identity providers, compliance systems, payment protocols, stablecoins, and settlement rails remain integrated components, not the category our work claims.

8.1 Where our work sits

Broad agent and commerce scope ▲
Agent surfacesChatGPT · Gemini · Bankr
Commerce protocolsACP · UCP · AP2
Runtime and orchestrationMCP · A2A · frameworksPrimary · layer 2
Aomi Labsexecution infrastructure research
Domain executionAgentKit · 1inch · deBridgePrimary · layer 3
Wallets and mandatesCoinbase · MetaMask · PrivyIntegrated, not owned · layer 4
Payment coordinationx402 · MPPSupported capability · layer 5
Money and railsStablecoins · cards · chainsUnderlying infrastructure · layers 6–7
▼ Financial and onchain specific
Intent and planning───────▶Authority and settlement
Required partners · horizontalCompliance · security · threat detection · observability

8.2 What the thesis does not claim

We are not proposing a new wallet, stablecoin, payment protocol, facilitator, card network, or settlement chain. “Policy layer” and “transaction firewall” are also too narrow: policy and guards are subsystems inside a broader runtime. The research concerns a generalized execution surface — pay, swap, bridge, lend, stake, trade, deploy, call APIs, and reconcile outcomes.

Figure 7The execution responsibility boundary
DemandIntent

Goal, budget, timing, constraints, desired result

→
Execution runtime

plan · tools · construct · simulate · execute · reconcile

→
AuthorityWallet and mandate

identity, consent, limits, risk, refusal

→
FinalityMoney and rails

stablecoins, cards, banks, chains

The runtime coordinates execution and evidence. The wallet retains authority and the power to refuse; funding systems supply value; rails provide finality.

8.3 Strategic whitespace implied by the research

  1. Protocol-aware execution quality. Typed calls, protocol constraints, fork simulation, balance deltas, and outcome assertions should create measurable leverage over generic tool use.
  2. A portable runtime above wallet fragmentation. Support self-custodial, embedded, and institutional wallets rather than betting the runtime on one custody model.
  3. Payment-protocol neutrality. Treat x402, MPP, cards, and direct stablecoin transfer as tools selected by app and mandate.
  4. Evidence as a product. Record user intent, tool calls, immutable payload, simulation, policy decisions, signer, receipt, and final state as one inspectable chain.
  5. Partner-owned distribution. Wallets, protocols, exchanges, fintechs, and partner apps keep the user relationship while our infrastructure supports execution.
  6. Benchmark the runtime. Measure task completion, dangerous-proposal block rate, simulation-to-execution consistency, duplicate-broadcast rate, human escalation, and end-state correctness.

8.4 Competitive threats

Four vectors converge on layers two and three. Wallets can move upward: Coinbase, MetaMask, OKX, Circle, Privy, and Turnkey can all add tools and construction above the signing boundary they already own. Payment platforms can move inward: Stripe and Crossmint can add orchestration around money movement. Vertical execution providers — Bankr, 1inch, deBridge, Uniswap, and the exchanges — may own high-frequency domains outright. And general agent frameworks can move downward, adding wallets and payment plugins to existing distribution. The Aomi Labs thesis therefore depends on specialized infrastructure being materially better at generalized, verified onchain execution than a wallet assistant or a protocol-specific skill.

Researcher disclosure

Aomi Labs researches and develops infrastructure in the category analyzed here. This section presents our institutional thesis, not an independent market conclusion. External observations and vendor claims are cited; the proposed benchmark is a falsifiable test, not an already measured result.

9

Risks, outlook, and conclusion

9.1 Unresolved risks

The open problems are not evenly distributed across the stack, and few of them are solved by any single layer.

Prompt injection and tool poisoning

Untrusted content can redirect spending or execution.

Overbroad delegation

Spend caps alone do not prevent harmful but technically allowed actions.

Semantic mismatch

A transaction can be valid, simulated, and within policy while failing user intent.

Replay and duplicates

Retries can create duplicate payments without end-to-end idempotency.

Stale state

Quotes, balances, gas, liquidity, and permissions change between simulation and settlement.

Delivery-versus-payment atomicity

Payment finality does not prove correct offchain delivery.

Identity and Sybil risk

Cheap agent creation undermines reputation and marketplace quality.

Liability ambiguity

Failures can involve user, model, runtime, tool, wallet, facilitator, merchant, issuer, or chain.

Privacy

Payment metadata reveals tasks, services, counterparties, and commercial intent.

Regulatory classification

Custody, transmission, initiation, brokerage, advice, and sanctions obligations vary.

Economics

Sub-cent payments require cheap settlement, batching, or sessions.

Fragmentation

Overlapping protocols, wallets, tokens, networks, and frameworks raise integration cost.

Metric quality

Counts can be gamed by incentives, speculative loops, or self-payments.

Liability deserves separate emphasis because it cuts across all of them. It remains fragmented across user, model provider, runtime, tool, wallet, facilitator, merchant, issuer, and settlement rail, and regulatory classification can change with custody, payment initiation, brokerage, advice, sanctions exposure, or jurisdiction. A technically successful design may still fail if no participant clearly owns refunds, disputes, exceptions, and loss.

9.2 Outlook

Over the next twelve months, wallets are likely to make agent-specific policies, escalation, and transaction security default features. x402 and MPP will compete for paid APIs while processors support both. ACP, UCP, and AP2 integrations will expand across merchant systems, and stablecoin issuers will bundle wallets, discovery, compliance, and nanopayments. DeFi agents will remain valuable but risk-tolerant early adopters. Independent security and observability will become enterprise requirements.

Over a two-to-three-year horizon, agents should carry portable mandates and credentials across surfaces; service marketplaces should expose machine-readable price, capability, reputation, and delivery guarantees; cross-rail routers should choose among stablecoin, card, bank, and local rails automatically; and agent treasury and accounting should become standard enterprise infrastructure. Durable systems will separate proposer, executor, authorizer, and settler while linking all four through evidence. At that point “agentic payments” stops being a category and becomes a capability embedded in runtimes, wallets, commerce platforms, and financial software.

9.3 A decision checklist for any player

The taxonomy in this paper is only useful if it can place a real company quickly. Ten questions do most of that work, and the last two are usually the most revealing.

  1. Who owns the user or task? Surface and application.
  2. Who runs the model loop and task state? Runtime and orchestration.
  3. Who constructs the exact order or transaction? Domain execution.
  4. Who holds the credential and can refuse to sign? Wallet and authorization.
  5. Who defines the payment request and acceptance handshake? Protocol or orchestrator.
  6. Who supplies and manages the money? Stablecoin, account, card, onramp, treasury.
  7. Who provides finality? Chain, card network, or bank rail.
  8. Who independently verifies risk and records evidence? Trust and compliance.
  9. Who bears loss, refund, dispute, and regulatory liability? Often the clearest layer indicator.
  10. Can each layer be replaced independently? If not, vertical integration creates convenience and lock-in.

9.4 Conclusion

Agentic payments will not mature simply because models receive wallets. They will mature when software can form an adaptive intent, turn it into a valid and inspectable action, operate within delegated authority, settle through the appropriate rail, and prove that the requested outcome occurred. Better models will become better athletes. Execution harnesses are the vehicles that let the same athlete travel farther, faster, and with evidence.

References

References

  1. 1.

    International Monetary Fund. How Agentic AI Will Reshape Payments. Accessed August 2026.

  2. 2.

    x402. Protocol introduction and payment flow. Accessed August 2026.

  3. 3.

    Stripe and Tempo. Introducing the Machine Payments Protocol. Accessed August 2026.

  4. 4.

    Google Cloud. Announcing the Agent Payments Protocol (AP2). Accessed August 2026.

  5. 5.

    Chainalysis. Inside x402's Path to Meaningful Adoption. Accessed August 2026.

  6. 6.

    Coinbase Developer Platform. AgentKit architecture. Accessed August 2026.

  7. 7.

    Aomi Labs. Runtime reference. Accessed August 2026.

  8. 8.

    Aomi Labs. Build overview. Accessed August 2026.

  9. 9.

    Stripe and OpenAI. Agentic Commerce Protocol and Instant Checkout. Accessed August 2026.

  10. 10.

    Visa. Trusted Agent Protocol specifications. Accessed August 2026.

  11. 11.

    Mastercard. Mastercard Agent Pay. Accessed August 2026.

  12. 12.

    Coinbase Developer Platform. Agentic Wallets. Accessed August 2026.

  13. 13.

    MetaMask. Agent Wallet. Accessed August 2026.

  14. 14.

    Privy. Wallet infrastructure for AI. Accessed August 2026.

  15. 15.

    Turnkey. Wallet infrastructure for AI agents. Accessed August 2026.

  16. 16.

    Bankr. Agent runtime overview. Accessed August 2026.

  17. 17.

    Aomi Labs Research. Agentic Payments in Crypto — Ecosystem Deep Dive. Accessed August 2026.

  18. 18.

    Solana. What is x402. Accessed August 2026.

  19. 19.

    Circle. Agent Stack. Accessed August 2026.

  20. 20.

    x402. Facilitator specification. Accessed August 2026.

  21. 21.

    x402. Network and token support. Accessed August 2026.

  22. 22.

    OKX. OKX Wallet officially launches Agentic Wallet. Accessed August 2026.

  23. 23.

    Crossmint. Agentic payments. Accessed August 2026.

  24. 24.

    MoonPay. Open Wallet Standard. Accessed August 2026.

  25. 25.

    Virtuals. EconomyOS. Accessed August 2026.

  26. 26.

    Chainalysis. AI, Crypto, and Agentic Payments. Accessed August 2026.

  27. 27.

    Tempo. Documentation. Accessed August 2026.

  28. 28.

    Harvey. Introducing Agents in Harvey. Accessed August 2026.

  29. 29.

    Abridge. Generative AI Platform for Clinical Conversations. Accessed August 2026.

  30. 30.

    Hippocratic AI. A Multi-step Process to Ensure Safety. Accessed August 2026.

  31. 31.

    Tenderly. Simulation infrastructure for onchain operations. Accessed August 2026.

  32. 32.

    Blockaid. How to Build Smarter, Safer Onchain AI Agents with Blockaid. Accessed August 2026.

  33. 33.

    Visa and Artemis. Agentic Payments: What Onchain Data Reveals About Commerce. Accessed August 2026.