How AgentWallet Implements AP2 Mandate Chains with did:web
AgentWallet supports Google's Agent Payments Protocol on the buyer side, building AP2 mandate chains and resolving signing keys via did:web. Here is what that means.
AgentWallet implements Google's Agent Payments Protocol (AP2) on the buyer side. It builds the AP2 mandate chain that authorizes an agent's purchase and resolves the signing keys used to verify that chain via did:web. This lets an agent present cryptographically verifiable authorization for what it is buying.
What a mandate chain does
AP2 expresses agent purchase authority as a chain of signed mandates. Each link states what was authorized and by whom, so a merchant or payment provider can verify that the agent is acting within a real, delegated mandate rather than on its own initiative. AgentWallet assembles this chain on the buyer side as part of a purchase.
Resolving keys with did:web
To verify a signed mandate you need the signer's public key. AgentWallet resolves signing keys via did:web, a decentralized identifier method that anchors a key to a web domain. That means verification does not depend on a single central registry: the key is discoverable from the domain that owns it.
- Buyer-side — AgentWallet builds and presents the mandate chain for an agent's purchase.
- Verifiable — each mandate is signed so it can be checked, not merely trusted.
- did:web — signing keys are resolved from the owning web domain.
Frequently asked questions
- Which side of AP2 does AgentWallet implement?
- The buyer side. It builds the mandate chain that authorizes an agent's purchase and resolves signing keys via did:web.
- What is a mandate chain?
- A chain of signed mandates expressing who authorized what, so a counterparty can verify the agent is acting within delegated authority.
- Why did:web for keys?
- did:web anchors a signing key to a web domain, so verification does not depend on a single central registry.
Sources
Give your agents a wallet
Per-agent wallets, virtual cards, USDC on Base, and policy guardrails — provisioned through one MCP endpoint.
Start free