Attestation
Linux Foundation Takes the Reins on x402, the HTTP Payment Protocol for AI Agents
The Linux Foundation announced the operational launch of the x402 Foundation this week, a new open-governance body created by Coinbase to steward x402, an open standard for internet-native payments over HTTP. The protocol embeds payment capabilities directly into web requests so that AI agents, APIs, and applications can send and receive money as part of ordinary web interactions, supporting rails from traditional cards to stablecoins.
This matters because it's one of three parallel developments this week that split the agentic-commerce trust problem into distinct, addressable layers. A companion piece from Biometric Update lays out the full stack: 1Password handles credential access for Anthropic's Claude, using a zero-exposure architecture where an agent can complete a login-gated task but the actual password or one-time code never enters its context. Dai Nippon Printing's CATRINA platform uses verifiable credentials to prove which human authorized a given AI agent's purchase and under what scope. x402 is the third leg — it's the settlement layer, giving the actual transaction a native, auditable payment rail instead of bolting crypto or card processing onto an ad hoc integration.
What makes the x402 launch notable isn't the protocol design itself, which Coinbase shipped earlier in 2026, but the governance shift. Handing stewardship to the Linux Foundation, with Jim Zemlin explicitly framing it as ensuring the payment layer of the internet stays neutral and interoperable, is a bid to keep a single vendor from controlling how agents pay each other. The foundation already has 40 member organizations, including Visa, Mastercard, Amazon Web Services, Stripe, Shopify, Circle, Google, and Ripple — a genuinely cross-industry roster spanning card networks, cloud providers, and stablecoin issuers.
The practical upshot: every x402 transaction is designed to leave a verifiable payment record tied to the HTTP request that triggered it, which is the accountability piece that's been missing as agents start acting as autonomous purchasers rather than assistants relaying a human's card number. Paired with DNP's delegated-authority credentials and 1Password's scoped-access model, the pieces are forming a chain where you can ask, after the fact, who authorized an agent, what it was allowed to do, and whether the resulting payment matches that authorization — three separate, independently verifiable answers instead of one opaque log.
None of these three efforts alone solves agent accountability. But their arrival in the same week, addressing complementary layers rather than competing for the same one, is a more concrete signal of infrastructure maturing than another single-vendor pilot would be.