Agentic Payments on Amazon Bedrock AgentCore
Agents that can pay for approved APIs and data within hard limits a human sets in advance, with a receipt and audit trail for every payment.
- Industries
- Fintech
- Author
- Solvren AI Engineering
- Published
- Last updated
Solvren AI is an AI forward deployment company: our engineers embed with the client’s team and build inside the client’s own cloud.
Problem
Some APIs and data feeds answer with HTTP 402 Payment Required. An agent running unattended needs a way to pay for them without a human approving each request.
Regulated buyers will not let an agent spend money unless the design assumes the model can be manipulated and bounds what it can spend regardless.
What we deployed
- An agent that requests approved paid resources through Amazon Bedrock AgentCore Payments using the x402 protocol.
- The application, not the model, owns approval and spending rules. The model can ask for a paid call; application code decides whether it happens.
- Built and tested on a test network with test-only USDC. AgentCore Payments is an AWS preview capability, and no client funds moved.
How it works
-
1Agent
Decides it needs a paid resource and requests it through a tool call.
-
2Application
Approval check: approved recipient, asset, network, per-payment ceiling, session budget.
-
3AgentCore Payments
Handles the x402 exchange, signs from the wallet, records the transaction.
-
4Paid API
Verifies payment and returns the resource; the response is treated as untrusted input.
The x402 flow
When the agent requests a paid resource, the server replies with HTTP 402 and a payment instruction. AgentCore Payments signs a payment from the configured wallet, retries the request with proof of payment, and returns the resource.
Application-owned approval
The model calls an application-defined tool to request a purchase. Before any payment, application code checks the recipient, asset, network, per-payment ceiling, and remaining session budget. The model never holds wallet credentials.
Receipt verification
Every payment produces a receipt that is logged. Before the agent’s answer is returned, the application checks that the answer matches the actual receipt, so a fabricated receipt in the model’s output is rejected.
Controls
- Approved recipients, asset, and network, set in advance by a human.
- A per-payment ceiling.
- A session budget with an expiry.
- Separate IAM roles for administration and runtime.
- Paid responses treated as untrusted input to the model.
- A receipt and audit trail for every payment, and a check that the final answer matches the receipt.
Results
Note: Testnet only. These runs used test networks and test-only USDC; AgentCore Payments is in preview and its APIs may change.
| Measure | Result |
|---|---|
| Test payments executed | Being measured |
| Payments blocked by policy | Being measured |
| Session budget limit | Being measured |
We publish only numbers we measured.
Why it fits regulated teams
The controls come first and autonomy second, which is the order a fintech risk or compliance team needs before approving any agent that can spend.
Related industries: Fintech
FAQ
Can an AI agent pay for an API on its own?
Yes, within limits. With Amazon Bedrock AgentCore Payments and the x402 protocol, an agent can pay for a resource that returns HTTP 402, but in our design the application approves each payment against rules a human set in advance.
What stops a manipulated agent from overspending?
The model never decides on its own. Application code enforces approved recipients, a per-payment ceiling, and a session budget with an expiry, and runtime and admin permissions use separate IAM roles.
How do you know a payment actually happened?
Every payment has a receipt in the audit trail, and the application checks the agent’s final answer against that receipt. A receipt the model invents is rejected.
Did real money move?
No. This build ran on test networks with test-only USDC. AgentCore Payments is an AWS preview capability.