Skip to content
untold_bits logountold_bits
Blog
July 24, 2026

My agent still can't pay for anything

Four companies moved this year to let software pay its own way, and the coverage read like consensus. The part that matters is still open: whose permission does your agent need to spend its own money?

Thomas Schouten
16 mins read

My agent still can't pay for anything.

It runs a content pipeline, sweeps a watchlist, reads and summarises and drafts. It costs me money constantly. But every one of those costs is something I paid for in advance, by hand, one platform at a time. $50 on Perplexity for search. $30 on ScrapeCreators. $50 on fal.ai. A Higgsfield subscription I used in bursts, now cancelled, because a monthly bill is not the same as paying when I need it. Apify, metered, for scraping and sweeping. A dozen dashboards, a dozen balances, all topped up by me when they run dry.

Composio takes some of the pain out. It is the MCP of MCPs: instead of wiring my agent into a dozen scattered platforms, I wire it into one and it reaches the rest. Close to giving it a wallet.

Except it isn't one. If my agent hits something it has to pay for that I have not configured in advance, it stops and waits for me. That is the state of the art in my own stack in July 2026: the software can do the work, and it cannot buy anything.

Four companies moved to fix that this year, and the coverage read like consensus. Franklin Templeton called agentic payments blockchain's killer use case. Coinbase built the x402 standard. 40 organisations signed on, including every major card network. Cloudflare is shipping the ability to unlock pages with agentic payments.

It isn't consensus. What those parties agree on is narrow. What they left open is the part that matters most, and almost nobody is writing about it: whose permission does your agent need to spend its own money?

Payment is the last thing still tied to a human

My agent stops because payment, alone among everything in the stack, still runs through a relationship.

Usage gets metered fine. What does not scale is the arrangement behind it: a subscription, a prepaid balance, an API key issued to a known account. Somebody has to provision access, accept terms, and attach a payment method. Bitfinex put the failure mode precisely: that setup "works when an agent depends on a small, stable set of vendors. It breaks down the moment it is expected to operate across the open internet, discovering new paid services mid-workflow or contracting specialist sub-agents on demand."

That is my situation exactly, and being more organised will not fix it. Every new paid dependency is a human errand.

What agents need instead is a loop that sits inside execution rather than beside it:

Request → Payment required → Pay → Access → Continue

If payment always needs a human, then autonomy stops at the paywall, and every agent is really a very fast assistant waiting for its card to be topped up.

The web reserved a slot for this and never used it

When the architects of the web wrote the rules for how browsers and servers talk to each other, they included a response code for exactly this situation. Number 402. They labelled it "payment required" and left it there.

It sat unused for 30 years because the money did not work. Every payment method available carried credit risk: the chance that a transaction would be reversed, disputed, or turn out to be fraud. Hedging that risk costs money, and the cost does not scale down. A blog charging a tenth of a cent for an article would eat roughly 30 cents in processing overhead to collect it.

So the floor sat far above the value of a page view, and the web went looking for a business model that cleared it. It found advertising.

I want to be careful about how far to push that. Dave Birnbaum, writing in Forbes, traces almost everything we dislike about the internet back to this single mechanism: fees forced payment into batches, batches had to be priced, pricing batches required surveilling behaviour, and content optimised for the broad engagement that made batches big. The chain from credit risk to surveillance advertising is tight and I think it holds. The chain from there to the quality of what we read is plausible and unproven.

But the narrow version is enough: the reason the web sells attention instead of value is that it could not collect small amounts of money.

Micropayments failed for a reason that has now expired

Every few years someone tries micropayments again and it does not take. The usual explanation is fees, and fees were real. But they were never the whole story.

Nick Szabo named the better reason decades ago: mental transaction costs. Humans dislike making repeated tiny decisions. Ask me to approve a tenth of a cent forty times an hour and I will refuse, not because the money matters but because the deciding is exhausting.

Agents don't get decision fatigue. And that's the whole thing: the constraint never lifted, the buyer changed. The human limitation is intact and permanent. It simply stopped being the binding constraint the moment humans stopped being the ones deciding.

Which is why this attempt at micropayments is different from 30 years of failed ones, and why four serious companies moved on it at once.

Those four are worth taking one at a time, because each wants something different: the first is an asset manager telling investors what this means for portfolios. The second an exchange that wrote the standard and handed it away. The third a company that hosts infra for most of the web and will collect like a tollgate. And the fourth a Bitcoin infrastructure team that thinks the other three picked the wrong money to begin with.

Franklin Templeton: the institution says the radical thing

Franklin Templeton manages money at a scale where nothing gets published without a compliance review. In July they published an article by Sandy Kaul, their Head of Digital Assets and Innovation, arguing that agentic AI is "the killer use case for blockchain and crypto."

Her argument: AI is becoming an actor, and actors transact, in amounts too small and too constant for legacy rails to carry. Visa clears thousands of transactions per second but settles one to three business days later, and for an agent that needs to know whether it can afford its next call, that lag reintroduces exactly the human-scale waiting the whole design is meant to remove. Blockchains clear and settle at once.

Then they draw the following conclusion: investors positioned in AI equities cannot capture this, so they should extend into cryptocurrencies. That argument has circulated among the crypto crowd for years. But when a compliance-bound asset manager publishes the outsider thesis in hedged analyst language, the news is who is now willing to say it out loud where it used to get you dismissed.

Franklin Templeton also sells digital-asset products. Their thesis is aligned with their company objectives. That does not make it less valid.

x402: Coinbase built the standard and then gave it away

The protocol that switched 402 back on is called x402, and the mechanics are simple enough to state in a paragraph. Your agent requests a resource. The server answers 402 Payment Required along with a payload saying what it costs, what asset it accepts, and where to send it. The agent pays and repeats the request with proof of payment attached. A facilitator verifies the proof, and the server returns the resource. No checkout page, no separate payment API, no account. Coinbase's reference implementation is open source on GitHub under the Linux Foundation's x402 Foundation, you can try it without risking anything you would mind losing.

The payment is the credential. There is nothing to sign up for. Metering was never the hard part of usage-based billing, the onboarding was. An agent that must register before it can buy anything cannot shop across an open web, and it is the account requirement rather than the fee that keeps agents confined to pre-integrated vendors.

Coinbase originated x402 and then contributed it to the Linux Foundation under vendor-neutral governance. In July the Foundation launched with 40 member organisations. Premier members include Adyen, AWS, American Express, Circle, Cloudflare, Fiserv, Google, Mastercard, Monad, MoonPay, Ripple, Shopify, the Solana and Stellar foundations, Stripe, and Visa.

Giving away the protocol was more a growth strategy than altruism. A standard a company owns is a standard its competitors will not build on. Visa and Coinbase do not co-develop anything under one roof unless nobody owns the roof.

Which sets up an observation I keep coming back to. Often a technological transition means the shift replaces the incumbents. Franklin Templeton's own article closes on that note. Except look at who's involved this time. The card networks that Web3 was supposed to disintermediate are premier members of this new standard from day one. Joining costs them nothing, so they joined. Where incumbents freeze is where a change cuts into what they already charge for. My prediction: everyone adopts the standard quickly and quietly, and then fights for years about the fees.

Cloudflare: the toll booth at the edge

Whoever owns the request owns the toll booth.

Cloudflare sits in front of a very large share of the world's web traffic as a proxy layer, across more than 330 cities. In July they announced the Monetization Gateway: an engine that will let any Cloudflare customer charge for any asset behind them, whether a web page, a dataset, an API, or an MCP tool call, with payment settled in stablecoins over x402.

Their framing is the widest door into this whole subject, and it is not a crypto argument at all. For 30 years the web ran on one principle: you give away content, you receive human attention, and you sell that attention through advertising, subscriptions, and e-commerce. An agent does not look at ads and does not maintain a subscription to every tool it touches. It reads a page once, takes what it needs, and leaves. By Cloudflare's own measurement, AI crawlers already request content anywhere from a hundred to tens of thousands of times for every visitor they send back. That figure is theirs, about a problem they sell into, but it is also the most concrete number anyone has published on the asymmetry.

They are honest about why per-request billing never happened before. Rails were too expensive and too slow, yes. But also, to bill per request you had to become a payments company.

The architecture matters more than the product. Payment evidence moves into the request itself, so the request path and the payment-validation path merge. Cloudflare is not being sneaky about the position this gives them. They say it themselves: the agent becomes the primary buyer on the internet and the request becomes the transaction. They are simply also the company that sees the request first.

And it has not shipped. The post is written almost entirely in the future tense, and the call to action is a waitlist form.

Meanwhile my agent is still paying for Apify the old way: a prepaid balance I topped up last Tuesday.

Lightning Labs: the rival 402

I should declare an interest of my own here, because I am not neutral about Lightning.

In 2019 I went to the Lightning Conference in Berlin, and I bought a beer with my Lightning wallet. Scan, confirm, done, for a fee too small to think about. I still have the branded conference merch sitting on a shelf at home. It was the first moment digital money felt like true cash to me rather than some magic internet money. No card terminal, no three-day settlement, no merchant account, no permission.

That was seven years ago. The thing I paid with then is now being proposed as the payment layer for autonomous software.

On the same day Coinbase launched its Agentic Wallets, Lightning Labs open-sourced a toolkit that gives agents the ability to transact natively on Bitcoin's Lightning Network. Their standard is called L402. Same HTTP 402 status code, same request-challenge-pay-access loop, settlement in bitcoin or in Tether's USDt carried over Lightning via Taproot Assets. Lightning Labs' LN Agent Tools are open source as well, like Coinbase's implementation.

Two standards, same dormant status code, opposite answers about what the money should be. That is a real fight over the monetary foundation of a large new economy, and it was reported as a done deal.

Dave Birnbaum makes the technical case against x402 in Forbes. He is Bitcoin-aligned and says so in his contributor bio, which is the right way to do it. His argument: x402 is architecturally agnostic but operationally narrow. At the spec level it abstracts chains away behind scheme and network fields. In practice, he says, it leans on EIP-3009, a transfer-authorisation standard Circle proposed in 2020, and only USDC implements it. So "token-agnostic" resolves to "any token that supports EIP-3009," which resolves to USDC, settled through a Coinbase-hosted facilitator on Coinbase's own L2.

I have not verified that claim and I am not going to pretend otherwise. It is the sharpest question anyone has asked about x402, and it is in tension with several entities supporting it, which include Solana, Stellar, Ripple, Cardano, NEAR, and Polygon. Either those memberships are commitments rather than shipped integrations, or the EIP-3009 constraint has loosened.

The Bitcoin side does not agree with itself either. Bitfinex argues for Lightning as the rail while explicitly refusing the either/or: stablecoin payments on Lightning "aren't a detour around Bitcoin." Their position is Bitcoin as reserve money and stablecoins as transactional currency, both riding the same rail, which conveniently suits a Tether affiliate. They and Birnbaum cite the same Bitcoin Policy Institute study of AI models choosing between monetary instruments, one for an overwhelming preference for Bitcoin and the other for a reserve-versus-transactional split. Same research, opposite emphasis, both from Bitcoin-aligned publishers.

Whose permission does your agent need

When your agent holds money, whose permission does it need to spend it?

If it holds bitcoin, nobody's. It is a bearer asset: no issuer, no counterparty, nobody who can reverse or freeze it. If it holds USDC, the answer is longer. Circle has to remain solvent, because USDC is a claim on Circle's reserves, subject to Circle's terms of service. Coinbase's sequencer has to keep ordering transactions on Base. The facilitator has to keep verifying. And everyone in that chain has to stay in regulators' good graces.

None of that is a scandal, and none of those parties is hiding. Circle publicly issues USDC, Coinbase publicly operates Base, Cloudflare publicly verifies at the edge. The dependency goes unexamined because nobody uses it as the frame: 40 organisations agreeing on a protocol tells you nothing about who has to stay solvent for a payment on it to mean anything.

The other side deserves the same honesty. A bearer asset that an autonomous agent holds is a security surface. Lost keys are unrecoverable, there is nobody to call, and self-custody for software means key management for software. Bitcoin also moves in price, which is a real problem for anything held longer than a moment. Neither answer is free.

Which is where Franklin Templeton's conclusion comes apart while their diagnosis survives. They are right that agents need rails legacy payments cannot provide. But their portfolio advice was to hold the chains' native tokens, on the logic that agents must pay gas. Look at what the builders actually shipped: Cloudflare settling in USDC, straight into the seller's wallet, redeemable to fiat. Circle promising clearing in seconds for a fraction of a cent. Tether carrying dollars over Lightning. What agents send is a dollar. Possibly one specific dollar, from one issuer. The value accrues to whoever issues the dollar, whoever facilitates the transfer, and whoever owns the request.

I am not telling you what to buy, and I am not qualified to. I am saying the question of what your software holds is an operational risk question before it is an investment one. And so far the clear winners of all this are in my opinion the centralised entities like Tether and Circle. As it always has been.

Nobody is running this at scale yet

We have standards and working open-source code on both the institutional and web3 side. But we have little to no public data on transaction volume. Cloudflare's gateway is a waitlist. 40 foundation members is agreement, not actual throughput. That combination, massive institutional alignment with no production receipts, is either the earliest stage of something real or the most expensive letter of intent in fintech history. Probably the former. But "probably" is not "certainly," and that distinction matters if you are a company betting on building on it.

What I am actually doing about it

I don't have a playbook for you, and I am suspicious of anyone who does at this stage. Nobody knows which rail wins, whether agent-held stablecoins survive their first serious regulatory contact, or whether self-custodial agent wallets turn out to be a wonderful idea or an expensive lesson.

What I am doing is the smallest real test I can run.

Apify, which my content pipeline already uses for watchlist sweeps, added x402 support at the end of June. More than 20,000 of their Actors are now payable over the protocol, in USDC on Base, with no Apify account and no API key. So the experiment is not hypothetical: I am giving an agent a wallet with five dollars in it, pointing it at the same sweep my pipeline runs anyway, and letting it pay for the run itself.

I want to see the 402 come back with my own eyes. I want the transaction on Basescan. And I want to know what it feels like when software I wrote buys something without asking me, and to get a taste of the future. Because what is genuinely new is that the authorisation moved from me to the software.

Which brings me back to that beer in Berlin. What made it land in 2019 was the absence of everything the technology replaced. No terminal, no account, no waiting. If the agent economy gets its rails right, that same absence is what my software will experience every time it needs something. And if it gets them wrong, we will have rebuilt the account-and-permission layer we were trying to escape, except now it will be machines filling in the forms.

That decision is being made right now by people who publicly disagree with each other, and it will be difficult to revisit. When you read the next announcement about consensus, check who is not in the room.

I will keep topping up balances by hand until one of them wins. Then I will write up what happened when I stopped.