Computer-Use and Browser Agents: AI That Operates SoftwareAgent protocols and agent-ready websites · Lesson 12 of 16
Agent protocols and agentic commerce: MCP, A2A, ACP, UCP and AP2
Video lecture
Agent protocols and agentic commerce: MCP, A2A, ACP, UCP and AP2
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Agent protocols and agentic commerce
Clicking through a checkout page is a clumsy way for software to talk to software. So alongside computer use, the industry is building protocols that let agents call tools, talk to other agents and buy things through structured interfaces. In this lesson you will learn what MCP, A2A, ACP, UCP and AP2 each do, which layer they sit in, and what that means for your business.
0:29 Connecting agents
Start with MCP, the Model Context Protocol. Anthropic introduced it in November 2024, and it's now widely adopted. It connects an AI application to tools and data exposed by servers. Next, A2A, Agent2Agent. Google launched it in April 2025, and it became a Linux Foundation project that June. It lets agents discover each other, delegate tasks and share results, without exposing their internal memory or tools.
0:58 Why it matters
Why does this matter? Because as AI assistants start shopping, booking and comparing on behalf of users, the way businesses get chosen changes. If an assistant can check your availability, price and returns through a structured interface, you're easy to recommend and easy to buy from. If it has to fight through a confusing checkout, it may pick a competitor. Protocols are how this gets standardized, and understanding them early helps you prepare without chasing every announcement.
1:31 Shipping containers for AI
Here's an analogy. Think about how international shipping works. There's a standard container that fits any ship, train or truck. There are standard shipping documents that customs officers everywhere understand. And there are letters of credit that let banks guarantee payment between strangers. Agent protocols are building the same things for AI. MCP is the standard container for tools. A2A is the shared paperwork between agents. And commerce and payment protocols are the letters of credit that let an agent buy something with verifiable authority.
2:08 Simple example: Agent Card
A simple example of an Agent Card in action. Your agency publishes a site audit agent. Its Agent Card says: name, Site Audit Agent. Skill: landing page audit, checks offers, tracking tags, broken links and accessibility basics. Endpoint and security requirements. Now a client's own marketing agent, built by a different vendor, reads that card, sees the skill it needs, authenticates, and sends a task: audit these twelve landing pages for the Eid campaign. It gets back an artifact, the findings report. No custom integration project needed.
2:46 Agentic commerce
Then commerce. ACP, the Agentic Commerce Protocol, came from OpenAI and Stripe in September 2025 and powers Instant Checkout in ChatGPT. UCP, the Universal Commerce Protocol, launched by Google with retail and payments partners in January 2026, covers journeys from discovery to checkout across Google's AI surfaces, starting with eligible US merchants. And AP2, the Agent Payments Protocol, from Google and payments partners, uses cryptographically signed mandates as proof of what the user actually authorized.
3:19 Four durable ideas
Think of them as layers. MCP connects an agent to its tools. A2A connects agents to each other. ACP and UCP define how an agent and a merchant complete a purchase. AP2 provides verifiable authorization for the payment. They overlap and compete in places, and the market will consolidate. The ideas that will last are discovery, structured descriptions of capabilities, verifiable authorization, and auditable transactions.
3:47 A2A essentials
Let's look closer at A2A, which reached its one point oh specification in 2026. Each agent publishes an Agent Card, a JSON file conventionally served at a well-known address on its domain. The card lists the agent's name, what it does, its endpoints, its capabilities like streaming, its security requirements, and its skills. Work happens in tasks with a clear lifecycle: submitted, working, input required, completed. Messages carry text, files and data, and results come back as artifacts. The lesson text shows an illustrative card for a site-audit agent.
4:26 Three agent routes to your store
So what does this mean if you sell things? When an AI assistant shops for a user, your visitor may be an agent, not a person. Agents reach you three ways. They browse your site like a human, using computer use. They use a commerce protocol through the platforms and payment providers you already have. Or they call your APIs or MCP servers directly. Whatever the route, agents compare feeds ruthlessly, so accurate prices, availability, shipping and return policies matter more than ever.
5:02 Worked example: readiness review
A skincare brand in Lahore, selling across Pakistan and the Gulf, did a readiness review. Protocol checkout programs weren't available in its markets yet, so it focused on what it could control: accurate marketplace feeds, clean product structured data, a checkout a browser agent can complete, and machine-readable shipping and return policies. It also asked its payment providers about their agentic commerce plans. When programs open, it's ready. And it treats any new agent endpoint as attack surface, with authentication and rate limits.
5:38 For builders
If you build agents rather than sell things, what should you do with these protocols? Start with MCP for connecting your agents to tools and data, because it's the most widely supported today. Consider A2A when you need separate agents, perhaps from different teams or vendors, to hand work to each other. And treat every agent endpoint you publish like a public API: authenticate callers, authorize each skill, validate inputs, rate-limit, and log. A new protocol doesn't remove old security basics.
6:13 Who is liable?
A question every merchant asks: who is responsible when an agent buys the wrong thing? The honest answer is that rules are still evolving. Card-network rules, payment-provider terms, consumer protection law and the protocols themselves all play a part, and they differ by country. Protocols with signed user mandates are designed to give clearer evidence of what the user authorized. Until the rules settle, talk to your payment provider about agent-initiated orders, and keep clear, fair return policies.
6:47 Three mistakes
Three common mistakes. First, treating protocol announcements as universal availability. Many programs start with selected merchants in specific countries, so check eligibility where you operate. Second, confusing the layers: MCP doesn't buy things, and a checkout protocol doesn't connect agents to your database. Third, forgetting that every Agent Card, MCP server or commerce endpoint is new attack surface that needs authentication, authorization, input validation and rate limits.
7:16 Try this now
Try this now. Draw three columns: browse, protocol and API. Under browse, note how well a browser agent could complete your key task on your site today. Under protocol, note which commerce or payment programs your platform and payment provider support in your markets, and their status. Under API, note whether you expose availability, pricing or booking in a structured way. Pick one gap you can close this quarter, like accurate feeds or a read-only availability endpoint, and assign an owner.
7:51 Recap
Recap. MCP is agent to tools, A2A is agent to agent, ACP and UCP are agent to merchant checkout, and AP2 is verifiable payment authorization. Availability varies by region and program, so check before you plan. Your next step: map your business to the three agent routes, browse, protocol and API, and pick one gap to close this quarter. Next lesson: making your website genuinely agent-friendly.
From clicking to talking
Computer use is how agents operate software built for humans. But clicking through a checkout is a clumsy way for software to talk to software. A parallel movement is building protocols so agents can call tools, talk to other agents, and complete purchases through structured interfaces. As a practitioner you need to know what each protocol does, which layer it sits in, and what it means for your business. Protocol versions and adoption move fast: check each project's official site before you build.
The protocol map (as of September 2026)
| Protocol | Originated by | Layer | What it does |
|---|---|---|---|
| MCP (Model Context Protocol) | Anthropic (Nov 2024), now broadly adopted | Agent to tools and data | Standard way for AI apps to connect to tools, resources and prompts exposed by servers |
| A2A (Agent2Agent) | Google (Apr 2025); Linux Foundation project since June 2025 | Agent to agent | Agents discover each other via Agent Cards, delegate tasks, stream updates, exchange artifacts, without exposing internals |
| ACP (Agentic Commerce Protocol) | OpenAI and Stripe (Sept 2025) | Agent to merchant checkout | Lets AI assistants complete purchases with merchants; powers Instant Checkout in ChatGPT |
| UCP (Universal Commerce Protocol) | Google with retail and payments partners (Jan 2026) | Agent to merchant commerce | Open standard for discovery-to-checkout journeys across Google's AI surfaces; checkout initially for eligible US merchants with expansion planned |
| AP2 (Agent Payments Protocol) | Google with payments partners (Sept 2025) | Payment authorization | Uses cryptographically signed mandates as verifiable evidence of user intent; designed as an extension to A2A and MCP |
Think of them as layers: MCP connects an agent to its tools; A2A connects agents to each other; ACP and UCP define how an agent and a merchant complete a purchase; AP2 provides verifiable authorization for the payment. They overlap and compete in places, and the landscape will consolidate. The durable ideas are discovery, structured capability descriptions, verifiable authorization and auditable transactions.
A2A in practice
A2A reached its 1.0 specification in 2026 and is governed as a Linux Foundation project with support from many technology companies. Key concepts:
- Agent Card: a JSON document, conventionally served at
/.well-known/agent-card.json, describing the agent's name, description, endpoints (with protocol bindings such as JSON-RPC, gRPC or HTTP+JSON), capabilities (streaming, push notifications), security schemes and skills. - Tasks: the unit of work, with a lifecycle (submitted, working, input required, completed, failed, and so on).
- Messages and parts: text, files and structured data exchanged during a task.
- Artifacts: the outputs a task produces.
- Opacity: agents collaborate without sharing internal memory, prompts or tools.
A simplified Agent Card for a hypothetical agency service:
{
"name": "Site Audit Agent",
"description": "Runs read-only technical and content audits of a website and returns a findings report.",
"supportedInterfaces": [
{"url": "https://agents.example-agency.com/a2a/v1", "protocolBinding": "JSONRPC", "protocolVersion": "1.0"}
],
"capabilities": {"streaming": true, "pushNotifications": false},
"defaultInputModes": ["text/plain", "application/json"],
"defaultOutputModes": ["application/json", "text/markdown"],
"skills": [
{"id": "landing-page-audit", "name": "Landing page audit",
"description": "Checks offers, tracking tags, broken links and accessibility basics on up to 50 URLs.",
"tags": ["audit", "marketing", "qa"],
"examples": ["Audit these 12 landing pages for the Eid campaign"]}
]
}Field names and required properties are defined in the specification; treat this as illustrative and validate against the current schema and SDK (official SDKs exist for several languages, including Python).
What agentic commerce means for merchants
When an AI assistant shops on a user's behalf, the "visitor" to your store may be an agent reading structured data, not a human browsing pages. Merchants increasingly face three routes:
- Agents browse your site like humans (computer use). Your site must be accessible and machine-readable; next lesson.
- Agents use a commerce protocol (ACP, UCP) through platforms and payment providers you already use. Participation usually runs through your commerce platform, product feeds and payment processor, often via early-access programs. Check eligibility in your region; initial rollouts have focused on the US.
- Agents call your APIs or MCP servers directly, for example a booking or quote API.
Practical merchant checklist:
- Keep product feeds complete and accurate (price, availability, shipping, returns); agents compare these ruthlessly.
- Make policies machine-readable: returns, shipping times, warranties.
- Decide your fraud and authorization stance for agent-initiated orders; protocols with signed mandates give better evidence than a bot filling a form.
- Watch disputes and refunds: who is liable when an agent buys the wrong item? Protocols and card-network rules are still evolving; talk to your payment provider.
Worked example: a Lahore skincare brand
A skincare brand selling in Pakistan and the Gulf reviews its readiness. Protocol checkout programs are not yet available to it, so it focuses on what is: accurate product feeds for the marketplaces it uses, clean Product structured data on its site, an accessible checkout that a browser agent can complete, and clear, machine-readable return and shipping policies. It also notes which payment providers it uses and asks each about their agentic commerce roadmap. When programs open in its markets, it is ready.
Pitfalls
- Treating protocol announcements as universal availability. Check regions, eligibility and status.
- Confusing layers: MCP does not buy things; ACP does not connect agents to your database.
- Ignoring security: an Agent Card or MCP server is a new attack surface requiring authentication, authorization and rate limits.
How to measure success
For merchants: share of orders or sessions identified as agent-originated (where your platform reports it), feed error rates, agent-checkout completion in tests. For builders: interoperability tests passing against the official SDKs.
Key takeaways
- MCP connects agents to tools, A2A connects agents to agents, ACP and UCP handle agent checkout, AP2 adds verifiable payment mandates.
- A2A agents publish Agent Cards (conventionally at /.well-known/agent-card.json) describing skills, endpoints and security.
- Merchants should prioritize accurate feeds, machine-readable policies, accessible checkout and payment-provider conversations.
- Protocol availability varies by region and program; verify status and treat new endpoints as attack surface.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Map your business to the three agent routes (browse, protocol, API). For each, note one gap you could close this quarter.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.