When AI Agents Pay and Sellers Monetize: Building x402 Apps on AWS — Anil Nadiminti, AWS

Read the talk

When AI Agents Pay and Sellers Monetize: Building x402 Apps on AWS

Anil Nadiminti explains how x402 turns a payment into access to a resource, how AgentCore Payments separates spending from the agent loop, and how AWS WAF lets sellers price AI requests at the edge.

From a talk by Anil Nadiminti

At a glance

Ideas worth remembering

  • x402 turns a resource request into a payment exchange: the server returns Payment Required, receives authorization, uses a facilitator for verification and settlement, then delivers content.

  • AgentCore Payments places session budgets, expiry, wallet integration and payment execution outside the agent's reasoning loop. Imported private keys remain in a KMS-protected store the agent cannot access.

  • Seller-side WAF rules can combine resource path, verified bot identity and classified intent to set prices at the edge without changing the origin.

  • The economic target is payment overhead small enough for individual resource purchases. A 25-cent fixed fee is 250 times a tenth-of-a-cent purchase; the closing examples extend these purchases to inference, compute and MCP tools.

A human paywall stops an autonomous task

A news portal works until the reader hits a paywall. A human can enter credit card details, choose a weekly, monthly or annual subscription, and obtain access. An autonomous agent encounters the same obstacle while completing a task, but the next step becomes a request for help: someone must supply payment details or an API key. Anil Nadiminti, a Senior Solutions Architect at AWS, starts with this familiar example because it exposes where autonomy breaks. The agent can find the content; it cannot finish obtaining it.

The urgency comes from a change in who requests resources. Nadiminti puts bot traffic above human traffic and says AI agents account for 95 percent of that bot traffic. The recording does not establish the population or measurement method behind those figures, so they serve as his framing rather than a universal traffic estimate. His forecast—about a billion agents performing tasks by 2027, with 60 percent of enterprises using agentic workflows—extends the same premise: more requests will arrive from software trying to complete work independently.

The news publisher has an uncomfortable choice:

  • Block bots: Blocking can forfeit AI discovery, citations and potential licensing partnerships. Content that an agent cannot reach is harder for it to incorporate into an answer.
  • Allow unpaid access: Large numbers of requests create infrastructure costs, while unrestricted reuse can weaken attribution and control over the content.

Paid machine access offers another option: let the agent obtain the resource and let the publisher earn from the request.

0:120:42
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

0:12 · section reference included

Buyers need spending controls; sellers need payment at the edge

Agent ecommerce joins two different requirements. On the buy side, an agent needs access to premium or licensed resources, a wallet and the ability to make small payments. An enterprise also needs to prevent that agent from going on a spending spree. On the sell side, a publisher needs to understand the requesting bot and charge for its activity without rebuilding the origin—the infrastructure that stores and serves the content. A shared machine-to-machine payment protocol lets these sides meet at the request.

The proposed change is from approving each purchase to setting conditions under which purchases may happen. Humans move from being in the transaction loop to supervising it, or staying outside it once limits are configured. Pay-per-use and pay-per-execution can then follow the agent's work at request speed, rather than requiring a new human subscription workflow whenever it encounters a paid resource.

Small payments make the fee structure decisive. Nadiminti uses a card-payment example with a 25-cent minimum fee plus 2.5 percent. For a purchase worth a tenth of a cent, the fixed fee alone is 250 times the purchase: $0.25 ÷ $0.001 = 250. The percentage fee barely matters beside that floor. Charging separately for each tiny resource request therefore requires a payment path whose overhead fits the size of the purchase.

4:124:41
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

4:12 · section reference included

x402 makes payment part of the resource request

x402 builds on HTTP status code 402, reserved for “Payment Required.” Nadiminti presents the protocol introduced by Coinbase as a way for machines to negotiate access through HTTP. Return to the news portal: instead of sending the agent into a human checkout, the server responds that payment is required. The client chooses a payment method and sends payment authorization back to the server.

Authorization is followed by verification and settlement. The server uses a facilitator to verify the payment authorization and complete the transaction. In the flow described here, the server releases the content after settlement completes on chain. The observable change is simple: the resource request that previously stalled now reaches the content response through a payment exchange.

What must happen between the first request and delivery of the content? The diagram separates the HTTP exchange from the facilitator's work. Payment authorization starts the transaction process; completed settlement is what precedes content delivery.

This is the force of the phrase “payment is the … credential”: the purchase itself enables access, without setting up a subscription or a separate API key for that resource. Nadiminti describes no protocol fee and nominal merchant gas fees. His description of “zero wait time” means an automated request-speed experience, rather than literal zero latency; the later figures include a 200-millisecond average settlement time on Base.

The protocol is also presented as extensible and open to implementation. Nadiminti dates its introduction to May 2025 and describes Linux Foundation open governance, with support from Coinbase, AWS, Google, Stripe, Anthropic, Cloudflare and Circle. That shared protocol supplies the connection between the AWS buyer and seller services introduced next.

How it fits togetherFrom payment-required response to content

Requests a resource, chooses a payment method and sends authorization.

The server uses a facilitator for verification and settlement, then returns the requested content.

6:417:11
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

6:41 · section reference included

AgentCore Payments gives the buyer a wallet and a budget

AgentCore Payments, part of Bedrock AgentCore, supplies the buyer's payment machinery. The service described in the recording supports Coinbase wallets and a Stripe preview wallet option, with payment connectors orchestrating transactions. It supports x402 at the time of the presentation; support for additional protocols is planned. Protocol independence is a design goal, while x402 is the concrete path shown.

A payment session constrains spending programmatically. It can specify a maximum amount and an expiry expressed in minutes. Nadiminti's example is permission to spend $5 over 30 or 60 days. The amount limits how much the session can spend; the expiry limits how long that permission lasts. Built-in observability is intended to let developers trace the activity across the stack.

The agent continues using tools, MCP servers and other resources to complete the user's task. When one of those requests returns 402, AgentCore Payments handles the transaction and tells the agent that settlement has happened. The agent can then continue toward its response. Applied to the opening example, the news paywall becomes a payment event handled by the configured service, rather than a reason to ask the user to enter card details mid-task.

Discovery is another part of the buyer's path. AgentCore Gateway exposes internal APIs through MCP, making them available as agent tools. Its integration also gives AgentCore Payments access to a Coinbase discovery service that Nadiminti describes as offering more than 10,000 endpoints available for transactions. Finding a purchasable resource and paying for it are thus separate capabilities connected through the gateway and payment service.

8:419:11
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

9:11 · section reference included

Keep keys and payment execution outside the agent loop

The wallet integration does not give the agent its private keys. Imported secret keys are stored in a secure token wallet protected by KMS, and the agent cannot access them. That distinction matters: an agent may request a paid resource without receiving the secrets that enable the payment infrastructure to transact.

Payment execution is also decoupled from the agent's reasoning loop. Skills and inputs can be poisoned by malicious actors, so the payment path runs in a deterministic layer responsible for connectors, orchestration, limits and third-party wallet integration. The model can continue choosing tools and pursuing the task, while spending controls operate outside its nondeterministic decisions. This design contains payment authority; it does not make poisoned agent inputs harmless.

Where does a resource request cross into payment execution? The diagram shows the 402 response triggering the separate payment layer, with session controls and protected wallet keys attached to that layer. The return path communicates settlement to the agent rather than passing private keys into its loop.

The separation also supports reuse of existing agent models and frameworks. Nadiminti describes payment handling as a layer that can operate without changing the agent's code. In the narrated demo, an agent discovers a secured resource, AgentCore Payments uses an already integrated wallet, and the transaction completes. The change from the opening paywall is the removal of the manual payment interruption, with the wallet and controls configured beforehand.

How it fits togetherAgent reasoning and payment execution

Uses tools and resources with the chosen model and framework.

Resource access triggers payment handling, but wallet secrets remain in the protected payment infrastructure.

11:4112:10
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

11:41 · section reference included

WAF prices the request before it reaches the origin

The seller needs enough information about a request to choose a price. Nadiminti describes AWS Web Application Firewall bot detection as recognizing more than 650 bot types, verifying bots by signature and identifying intent, such as model training or retrieval-augmented search. Identity and intent answer different questions: which organization is requesting the content, and what kind of use is the request associated with? The talk does not explain the intent-classification method or its accuracy, so intent-based pricing depends on that classification working.

WAF AI traffic monetization applies that context at the edge. With CloudFront, the content distribution network, a publisher can attach WAF and configure monetization through the console or infrastructure as code. Nadiminti also describes applying WAF to internal APIs exposed through AgentCore Gateway as MCP tools. In both cases, the seller adds payment handling in front of an existing resource rather than moving the resource into a new application.

The seller-side flow detects and categorizes the bot, identifies its intent, verifies it and uses x402 to monetize the request. The service is presented as requiring no SDK or origin changes, with publishers retaining 100 percent of revenue and no transaction or subscription fees. Those claims concern the monetization service; they do not remove the infrastructure costs that motivated the seller's dilemma or the gas fees described in the protocol discussion.

Pricing can use several independent dimensions:

  • Path: /blog, /research and an API endpoint can have different rates because they expose different resources.
  • Identity: A verified bot from an organization with an existing commercial relationship can receive a different price from an unverified bot. Anthropic is the example partner in the talk.
  • Intent: Training access can have a different rate from search access.

WAF rules combine these conditions with AND/OR logic. A seller can therefore price a request using several attributes together, rather than charging every bot the same amount.

The news portal can now distinguish human readers, verified bots and unverified bots. Human access might remain free or carry its own price, while bots follow different payment rules. Revenue dashboards aggregate results by bot and show the paths being accessed, giving the publisher a way to inspect which resources and requesters contribute to its revenue model.

14:4015:10
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

14:40 · section reference included

The transaction examples extend beyond content

Paid news access is only one use. The closing examples include LLM inference, compute, web scraping, research agents, agent-to-agent transactions and monetized MCP services. Each gives an agent a resource or capability it can purchase while performing work. The same request-and-payment pattern can therefore apply to executing a tool as well as reading a page.

For the preceding 12 months of Coinbase marketplace activity, Nadiminti reports $50 million in transaction volume across 170 million transactions. He also gives an average settlement time of 200 milliseconds on Base and a cost of about a tenth of a cent per transaction. These figures describe the cited activity and settlement setting, rather than a benchmark of the AWS services. They make the economic target concrete: many small purchases need both low payment overhead and short settlement delays.

Payments sit within the larger Bedrock AgentCore ecosystem. Builders can bring their own model and framework, add memory, use managed knowledge bases and web search, expose internal APIs through MCP, and evaluate agent performance. AgentCore Runtime hosts the agentic application at scale; Nadiminti describes each request as running in its own isolated micro virtual machine. The final architecture keeps these jobs distinct: the runtime serves the agent, the gateway connects resources, and the payment layer handles purchases when access requires them.

18:4019:10
Suggest correction

This note stays in this page until you copy or download it. Nothing is submitted; reloading clears the draft.

18:40 · section reference included

Resources

Read the complete timestamped transcript
  1. 0:01

    [music]

  2. 0:12

    Hello all, welcome to uh the agent

  3. 0:14

    e-commerce track and uh I'm Anil Lminti.

  4. 0:17

    I'm a senior solutions architect here at

  5. 0:19

    AWS. Uh I'm I'm here to talk to you

  6. 0:21

    today about how AWS is innovating and uh

  7. 0:25

    how you can build apps on uh AWS to

  8. 0:29

    support the agent e-commerce. So uh

  9. 0:32

    welcome to the session. Uh just to get

  10. 0:34

    you started, let me set the stage with

  11. 0:36

    something that you're very familiar

  12. 0:37

    with. Uh imagine that you are your

  13. 0:40

    organization is building uh a news

  14. 0:43

    portal like this, right? So you're all

  15. 0:45

    familiar with something where you're

  16. 0:46

    accessing the news content and then

  17. 0:48

    suddenly you hit a payw wall, right? So

  18. 0:50

    this is where uh you pull out your

  19. 0:52

    wallet or you try to uh figure out how

  20. 0:55

    to make the payments, set up your uh

  21. 0:57

    credentials, access keys in the sense

  22. 0:59

    that you you make a credit card

  23. 1:01

    transaction weekly, monthly or annual

  24. 1:03

    subscription and then get started to

  25. 1:05

    access the content. Right? So this is

  26. 1:06

    all the content that is behind a payw

  27. 1:08

    wall. But uh what we see now is that uh

  28. 1:11

    much of the traffic that is actually

  29. 1:13

    being uh sent to these uh uh portals now

  30. 1:16

    on the internet is all coming from bots.

  31. 1:18

    We see that we at a infliction point

  32. 1:20

    where uh the bot traffic is more than

  33. 1:23

    the human traffic right. So it's just uh

  34. 1:25

    actually in fact surpassed that and uh

  35. 1:28

    95% of that bot traffic is coming from

  36. 1:30

    AI agents. So uh essentially we are also

  37. 1:35

    looking at the rise of autonomous agents

  38. 1:37

    right so where we all started using LLMs

  39. 1:41

    asking questions asking for

  40. 1:42

    summarization being able to uh get help

  41. 1:45

    with using them as co-pilots getting

  42. 1:47

    them to do agentic work to uh do

  43. 1:49

    multi-step tasks and now we're in the

  44. 1:51

    phase of autonomous agents where agents

  45. 1:54

    are using the reasoning powers of large

  46. 1:56

    language models to complete a task and

  47. 1:58

    completing a task means that uh it it

  48. 2:00

    has to go do whatever you're asking it

  49. 2:03

    to do. And that's kind of where we are

  50. 2:04

    in the uh journey. And we see that by

  51. 2:07

    2027 about a billion agents will be

  52. 2:10

    running uh performing tasks and 60% of

  53. 2:13

    the enterprises will already be uh using

  54. 2:15

    agentic workflows. So uh what happens

  55. 2:18

    when agents hit these pay walls that uh

  56. 2:20

    we just saw? When agents hit the pay

  57. 2:22

    walls, they stall, they can't operate

  58. 2:24

    and you see those messages that hey I

  59. 2:26

    cannot access content. Uh right? So at

  60. 2:28

    that point humans get in the loop. They

  61. 2:31

    try to enter and put the credit card

  62. 2:34

    details or API keys do the transactions

  63. 2:37

    for the AI agents. But all of that is

  64. 2:39

    manual friction, right? So essentially

  65. 2:41

    bringing in a human in the loop. So

  66. 2:43

    autonom autonomous agents actually break

  67. 2:45

    [clears throat] at that point where the

  68. 2:47

    uh friction is now building up. So uh

  69. 2:50

    now sellers of the content have uh you

  70. 2:53

    know couple of options right. So block

  71. 2:55

    all the bot traffic but by blocking all

  72. 2:57

    the traffic they lose this AI powered

  73. 2:59

    discovery they miss this uh partnership

  74. 3:02

    licensing options and AI also now

  75. 3:06

    supports citations right so the

  76. 3:07

    responses so they lose all of that uh

  77. 3:09

    powered citations as well if they can't

  78. 3:10

    sell the content essentially they lose

  79. 3:13

    uh revenue generating options and if you

  80. 3:15

    allow the bots to access those uh uh the

  81. 3:18

    content what it means is that you know

  82. 3:20

    hundreds of thousands of bots or

  83. 3:22

    millions of bots could be hitting your

  84. 3:23

    uh uh infrastructure which means that

  85. 3:25

    the infrastructure costs will also raise

  86. 3:27

    and uh you need to be able to support

  87. 3:29

    all of that right so you also uh when

  88. 3:31

    you allow bots to access content you

  89. 3:33

    lose attribution the IP itself right so

  90. 3:35

    because content is now freely available

  91. 3:37

    so uh both these decisions are probably

  92. 3:41

    not not a good option they're not ideal

  93. 3:43

    so there should be another ideal option

  94. 3:45

    where uh you would want to have your AI

  95. 3:48

    agents being able to get and pay for the

  96. 3:50

    content that they are looking for and

  97. 3:53

    monetize on

  98. 3:54

    So uh now we look at the next phase of

  99. 3:57

    uh uh rise in autonomous agents where

  100. 4:00

    agents should be able to transact and

  101. 4:02

    make uh discover other agents resources

  102. 4:05

    and essentially make payments. Right? So

  103. 4:07

    this is the definition of agent

  104. 4:08

    e-commerce where AI agents can

  105. 4:10

    essentially discover uh you know it's a

  106. 4:12

    form of e-commerce where autonomous

  107. 4:14

    agents can uh discover independently and

  108. 4:16

    make those uh uh settlements and then

  109. 4:18

    access content. So let's look at uh the

  110. 4:22

    agent e-commerce the two sides of agent

  111. 4:23

    e-commerce the buy side and the sell

  112. 4:25

    side. So uh when we talk about the buy

  113. 4:27

    side the agents are making these

  114. 4:29

    transactions and on the sell side the

  115. 4:31

    sellers of the content are trying to

  116. 4:33

    monetize on the content. So on the buy

  117. 4:35

    side when you look at things AI agents

  118. 4:37

    want to access these premium paywalled

  119. 4:39

    content licensed content they want to be

  120. 4:41

    able to hold wallets which they do not

  121. 4:43

    have the option today and they want to

  122. 4:45

    be able to make these microtransactions

  123. 4:46

    you just heard in the prior talk as

  124. 4:48

    well. But enterprises when they come to

  125. 4:50

    this point they want more guardrails and

  126. 4:52

    they do not want agents to go on

  127. 4:54

    spending spree. Think about it right?

  128. 4:56

    Would you allow your AI agents to get

  129. 4:57

    handled on your wallets or credit cards

  130. 4:59

    to be able to do that transactions and

  131. 5:01

    where they could go rogue as well right?

  132. 5:03

    So that's what the buyer side is looking

  133. 5:05

    at. And on the seller side uh the there

  134. 5:08

    are again billions of transactions that

  135. 5:10

    be happening with these AI bots. So

  136. 5:11

    sellers really want to be able to

  137. 5:13

    understand what kinds of bots are

  138. 5:15

    operating uh what kinds of transactions

  139. 5:17

    they're making and uh really uh do this

  140. 5:20

    at the edge. The sellers don't want to

  141. 5:22

    change their entire infrastructure and

  142. 5:24

    origins where the content is sitting.

  143. 5:26

    They want to be able to do this at the

  144. 5:27

    edge without changing much of this.

  145. 5:29

    Right? So there is again uh one common

  146. 5:32

    thing here on the buyer side and the

  147. 5:33

    seller side which is a standardized

  148. 5:35

    approach or a protocol to be able to

  149. 5:36

    solve for this uh machine to machine

  150. 5:38

    payments at the edge. So uh bottom line

  151. 5:41

    buyers are saying that they want their

  152. 5:42

    agents to be able to pay for content uh

  153. 5:45

    and uh not have humans approving this

  154. 5:48

    and then the sellers are saying that

  155. 5:49

    they want to be able to earn from the AI

  156. 5:51

    traffic. So bottom line the subscription

  157. 5:54

    model is going to change with humans in

  158. 5:56

    the loop to becoming humans on the loop

  159. 5:59

    or out of the loop and that's kind of

  160. 6:01

    what we are building towards. uh the the

  161. 6:03

    traditional one-sizefits model does not

  162. 6:06

    work anymore because of the fact that uh

  163. 6:08

    again we look at that in the next slide

  164. 6:10

    where uh the transactions cost will not

  165. 6:12

    really work right all of this needs to

  166. 6:14

    happening at realtime speed and the

  167. 6:17

    paper use and paper execution is what

  168. 6:19

    the f future is going to look like so if

  169. 6:22

    you're a seller you would have come

  170. 6:23

    across this right so there is a 25 cent

  171. 6:25

    minimum transaction fees as well as 2.5%

  172. 6:29

    on top of that and all of these

  173. 6:31

    microtransactions are uh you know in the

  174. 6:33

    in in like a cent subsend or you know

  175. 6:36

    micro cents is what we are calling them.

  176. 6:38

    So if you add like a 25 cents on top of

  177. 6:40

    that it's essentially like 250 times to

  178. 6:42

    what you know they are essentially

  179. 6:44

    paying for. So the all of this model

  180. 6:46

    does not work and uh while we are trying

  181. 6:49

    to solve for that a very brief history

  182. 6:50

    uh of this is every HTTP call

  183. 6:53

    essentially responds back uh you know

  184. 6:54

    there's a response for that you've seen

  185. 6:56

    200 status codes 404 uh you know and the

  186. 6:59

    301 these are all like status codes that

  187. 7:01

    you're familiar with and then there is

  188. 7:03

    one status code which is 402 which has

  189. 7:05

    uh not been used it was reserved for

  190. 7:07

    payment required and now finally uh

  191. 7:10

    Coinbase has introduced this uh as uh

  192. 7:13

    transactions over 402 which is also

  193. 7:15

    called as X42 where they uh you know the

  194. 7:17

    protocol talks about how you can do

  195. 7:19

    machine to-achine transactions uh using

  196. 7:21

    this protocol right so we'll take a

  197. 7:23

    closer look at that but uh what happens

  198. 7:25

    within the protocol is uh you know if

  199. 7:27

    you look at this uh flowchart here a

  200. 7:29

    client makes a request to the server and

  201. 7:31

    then the server responds back with the

  202. 7:33

    payment required uh the client then

  203. 7:36

    figures out what is the payment method

  204. 7:37

    that it wants to operate and then it

  205. 7:39

    sends the payment authorization to the

  206. 7:41

    server the server then utilizes a

  207. 7:43

    facilitator to complete the verification

  208. 7:46

    and then also utilizes the same

  209. 7:48

    facilitator to complete the transaction

  210. 7:50

    and once the settlement is completed

  211. 7:52

    onchain essentially the server will then

  212. 7:54

    respond back with the content right so

  213. 7:56

    this is what's happening under the X42

  214. 7:58

    protocol I thought I'll pick one of the

  215. 7:59

    protocols and just uh explain this to

  216. 8:01

    you but uh why this is compelling is uh

  217. 8:03

    you know essentially there is no

  218. 8:04

    protocol fees uh or the fees that a

  219. 8:07

    consumer is paying for uh you know these

  220. 8:10

    microcent transactions and the merchant

  221. 8:12

    is paying very nominal gas fees is uh

  222. 8:14

    again there is zero wait time this is

  223. 8:16

    happening at the speed of internet and

  224. 8:19

    uh there is no friction there is no API

  225. 8:21

    keys to set up no subscriptions and the

  226. 8:23

    payment is the essentially the uh

  227. 8:25

    credential to be able to get the content

  228. 8:27

    so there is no centralization it's uh

  229. 8:30

    x42 can be extended as well and you can

  230. 8:32

    implement it and there are no

  231. 8:33

    restrictions as well so some key

  232. 8:35

    milestones here are you know it was

  233. 8:37

    introduced last year uh May 2025 it

  234. 8:41

    explored is not part of the Linux

  235. 8:43

    Foundation under open governance and

  236. 8:46

    it's backed by Coinbase, AWS,

  237. 8:49

    Google, Stripe, Anthropic, Cloudflare

  238. 8:52

    and Circle right so many more folks in

  239. 8:55

    there that are supporting that

  240. 8:56

    organizations in there. So uh from

  241. 8:58

    Amazon we have also released agent core

  242. 9:00

    payments uh under the bedrock uh suite

  243. 9:03

    so where uh agents will make be able to

  244. 9:06

    make payments and we'll go into some of

  245. 9:07

    the details here. So let's talk about

  246. 9:09

    the buyer side here and what is involved

  247. 9:11

    right? So we uh we understood from the

  248. 9:13

    developers that they really want to be

  249. 9:15

    able to get this uh agents to have

  250. 9:16

    wallet support. They want to be able to

  251. 9:18

    have real-time settlement uh have the

  252. 9:21

    budget and guardrails which enterprises

  253. 9:23

    really want and observability throughout

  254. 9:26

    the stack where they would want to have

  255. 9:28

    uh the full stack trace of everything

  256. 9:29

    that's happening uh under the hood. So

  257. 9:32

    I'm excited to share with you that we've

  258. 9:34

    launched agent core payments and this is

  259. 9:35

    a service that allows AI agents to

  260. 9:38

    autonomously discover uh authorize and

  261. 9:40

    execute payments with a few lines of

  262. 9:42

    code. Uh now we've launched this in

  263. 9:44

    partnership with Coinbase and Stripe

  264. 9:46

    where you can bring wallets from

  265. 9:49

    Coinbase and Stripe preview to be able

  266. 9:50

    to do these operations and we'll go into

  267. 9:53

    some of the details but uh the core

  268. 9:55

    capabilities to start with are wallet

  269. 9:56

    support where you can bring the the

  270. 9:59

    wallets from Coinbase and Stripe. you're

  271. 10:01

    able to orchestrate the payments using

  272. 10:03

    payment connectors and uh today we

  273. 10:05

    support X42 with many more protocols to

  274. 10:08

    uh you know that are in the pipeline.

  275. 10:09

    The service is designed to be protocol

  276. 10:11

    agnostic. So as new protocols emerge, we

  277. 10:14

    are going to be adding the support for

  278. 10:16

    those protocols as well. And uh you know

  279. 10:18

    the the settlement is going to be

  280. 10:20

    instantaneous uh instant essentially and

  281. 10:23

    uh the payment limits can be set uh

  282. 10:25

    which is the most important thing that

  283. 10:26

    we spoke about where enterprises are

  284. 10:28

    looking to put some payment limits and

  285. 10:30

    guards on how these transactions can

  286. 10:31

    operate. So uh observability is builtin

  287. 10:35

    and uh essentially all of this uh

  288. 10:37

    operates with uh you know security as

  289. 10:39

    the uh layer that is operating uh the

  290. 10:41

    whole model right. So with that let's

  291. 10:43

    look at uh some of these uh details on

  292. 10:46

    how the payments limit can be set up

  293. 10:47

    right. So you can create payment

  294. 10:48

    sessions where you can set the

  295. 10:51

    programmatically set the maximum amount

  296. 10:53

    of uh uh value that can be used for

  297. 10:56

    transactions or you can also set expiry

  298. 10:59

    time in minutes. think where uh you are

  299. 11:01

    able to set that uh I can the agent can

  300. 11:04

    actually spend maybe $5 in 30 days or 60

  301. 11:08

    days right so that's kind of the

  302. 11:09

    operation uh model that you can set with

  303. 11:11

    many more uh you know details that are

  304. 11:13

    available I'm only going over a few

  305. 11:15

    features but uh let's look at what

  306. 11:18

    happens on the buyer side when the user

  307. 11:20

    is asking an agent to make a particular

  308. 11:23

    uh you know requesting for resources

  309. 11:25

    right so agent completes the request by

  310. 11:28

    accessing tools MPPP servers other

  311. 11:30

    resources as well. So at that point of

  312. 11:32

    time if the agent uh is uh looking at

  313. 11:36

    you know it it finds that the there is a

  314. 11:38

    response from one of the tool calls or

  315. 11:40

    requests with a 402 agent core payments

  316. 11:43

    is going to handle the request uh to

  317. 11:45

    complete the transaction and then let

  318. 11:47

    the AI agent know that uh essentially

  319. 11:49

    the settlement happened and the AI uh

  320. 11:52

    agent will be able to respond back with

  321. 11:54

    the users. So in this process when the

  322. 11:57

    wallets are uh wallet support is

  323. 11:59

    imported the the the secret keys that

  324. 12:02

    you use to import the wallets actually

  325. 12:04

    are stored in a secure token wallet that

  326. 12:06

    is uh secured by KMS where you know

  327. 12:10

    that's there. So essentially the agent

  328. 12:12

    does not have access to the private

  329. 12:13

    keys. This is most important uh to note.

  330. 12:16

    And uh next thing is that uh agent core

  331. 12:18

    payments is also integrated uh through

  332. 12:20

    uh a gateway which is also part of uh

  333. 12:22

    which is another service that we have to

  334. 12:25

    mp5 your internal APIs. Uh through agent

  335. 12:28

    core gateway uh the agent core payments

  336. 12:31

    can get access to discovery service uh

  337. 12:33

    in coinbase where there are 10,000 plus

  338. 12:36

    endpoints that are available to transact

  339. 12:38

    and then u again there is a per session

  340. 12:40

    budget that we just discussed as well.

  341. 12:43

    So uh there is a decoupling of agent

  342. 12:46

    infrastructure and uh the payment

  343. 12:48

    infrastructure by design where the agent

  344. 12:50

    can operate it it in its own loop and

  345. 12:52

    whenever it sees the payment the payment

  346. 12:55

    uh connectors orchestration payment

  347. 12:56

    limits and integration with third party

  348. 12:58

    wallets can happen right so it's

  349. 13:00

    important to decouple them because again

  350. 13:02

    skills can be poisoned inputs for the

  351. 13:05

    agents can also be uh you know poisoned

  352. 13:07

    by inputs as well right so where

  353. 13:09

    malicious actors could uh try to do that

  354. 13:12

    so By decoupling and making this uh by

  355. 13:16

    design a agents can essentially have a

  356. 13:18

    secure path for these transactions and

  357. 13:20

    payments do not touch the you know

  358. 13:24

    undeterministic path but this is more on

  359. 13:25

    a deterministic uh uh layer as well. So

  360. 13:28

    why this is important is that uh again

  361. 13:30

    agents uh the code of the agents does

  362. 13:33

    not have to change. You can bring your

  363. 13:35

    own model frameworks and then the

  364. 13:36

    payment itself uh can flow through uh in

  365. 13:39

    the payment uh uh layer itself. So again

  366. 13:43

    the controls the policies pending

  367. 13:45

    controls can be outside of the payment

  368. 13:48

    stack itself and again it's this is

  369. 13:50

    built to be protocol agnostic. So this

  370. 13:52

    is uh one of the console screens where

  371. 13:54

    it shows how you can import uh the

  372. 13:56

    payment connector uh and it shows that

  373. 13:59

    you know you can select the the coinbase

  374. 14:01

    wallet and the stripe preview wallet

  375. 14:03

    from the console and uh this is a demo

  376. 14:06

    in action where we are showing how a

  377. 14:08

    secure resource can be accessed. Now in

  378. 14:10

    this case uh the AI agent is essentially

  379. 14:14

    making a you know discovering that there

  380. 14:15

    is a secure source the agent core

  381. 14:18

    payments is kicking in and then it's

  382. 14:20

    completing the transaction by utilizing

  383. 14:23

    the wallet that is already integrated

  384. 14:25

    and uh the transaction completes. Now uh

  385. 14:29

    this is on the buyer side. Now let's

  386. 14:32

    look at the seller side to understand

  387. 14:33

    what's happening. Right? So uh again

  388. 14:35

    there is a lot of bot activity that's

  389. 14:37

    happening. We have released uh under uh

  390. 14:40

    the uh AWS web application firewall a

  391. 14:42

    feature where we have bot detection in

  392. 14:44

    place. Today we detect over 650

  393. 14:46

    different types of bots. Think of bots

  394. 14:48

    like perplexity bot, GPD bot, cloud bot,

  395. 14:51

    you know, again Google bots, right? So

  396. 14:53

    there are so many bots that are out

  397. 14:54

    there. So we're able to detect also

  398. 14:57

    understand the intent of these bots. So

  399. 14:58

    why are these bots accessing the

  400. 15:00

    content? Are they accessing the content

  401. 15:02

    to train their models? are they doing it

  402. 15:04

    because they have to respond back to an

  403. 15:06

    intent where they're uh responding for a

  404. 15:08

    rag search. So we're able to identify

  405. 15:10

    the intent. We're also able to verify

  406. 15:12

    the bots and identify them by a

  407. 15:14

    signature. So we are able to say hey

  408. 15:17

    this is a verified bot. So maybe you

  409. 15:19

    have uh built a relation with one of

  410. 15:21

    these organizations and these

  411. 15:24

    verification will allow you to have a

  412. 15:26

    different pricing for the organizations

  413. 15:28

    that are already verified. So we'll look

  414. 15:30

    at that in a second. So there's also

  415. 15:31

    real-time traffic analysis that allows

  416. 15:34

    uh more uh to be customized. And I'm

  417. 15:36

    also happy to share with you today that

  418. 15:38

    we announced VAF AI traffic

  419. 15:41

    monetization. This is a service that

  420. 15:42

    allows you to monetize uh based on the

  421. 15:45

    content that uh you know based on how

  422. 15:47

    you can measure, verify and monetize

  423. 15:49

    based on the AI traffic that is hitting

  424. 15:51

    your endpoints. Now if you might be

  425. 15:53

    familiar with CloudFront which is our

  426. 15:55

    content distribution network you can add

  427. 15:57

    a web application firewall at that point

  428. 15:59

    and essentially you can moni start

  429. 16:01

    monetizing uh right away and based on a

  430. 16:04

    few clicks uh you can do that again

  431. 16:06

    using infrastructure as code as well.

  432. 16:07

    Now I also spoke about a gateway service

  433. 16:10

    that allows you to expose your AI

  434. 16:12

    endpoints uh that are internal use and

  435. 16:15

    mcpify them. So the same web application

  436. 16:17

    firewalls can be used there. So your

  437. 16:19

    internal APIs can be MCPI and then you

  438. 16:21

    can start monetizing as well. So what

  439. 16:23

    happens during monetization? The AI

  440. 16:25

    agent AI bot essentially requests for

  441. 16:28

    some content. The bot context uh

  442. 16:31

    understands what kinds of bots is

  443. 16:33

    detecting it. It's able to detect the

  444. 16:34

    bot. It's able to categorize and

  445. 16:37

    understand the intent of the bot as we

  446. 16:39

    discussed earlier and verify uh and

  447. 16:42

    check what kind of bot is available. So

  448. 16:43

    then we are able to monetize uh using

  449. 16:46

    the X42 and the publishers get paid as

  450. 16:49

    well. So important to note is that again

  451. 16:51

    there is no SDK change no changes at the

  452. 16:53

    origin origin. Publishers keep 100% of

  453. 16:56

    the revenue as well and uh again there

  454. 16:59

    is no transaction fees or subscription

  455. 17:00

    fees. So this supports X42 and we are

  456. 17:04

    adding support for more uh protocols as

  457. 17:06

    well. U a few dimensions on how you can

  458. 17:09

    start monetizing. Think uh you have

  459. 17:11

    separate paths. So a slash uh uh blog in

  460. 17:15

    this case can be charging for a

  461. 17:16

    different rate than a slash research or

  462. 17:19

    maybe an API endpoint itself and uh you

  463. 17:22

    you know the identity of these bots.

  464. 17:24

    Again, if you make uh some kind of a

  465. 17:26

    relationship with the uh bots uh

  466. 17:29

    companies, organizations, maybe you make

  467. 17:30

    a relation with Anthropic, then you can

  468. 17:33

    essentially have a different pricing for

  469. 17:34

    those bots versus different uh

  470. 17:36

    unverified bots, right? So, uh think of

  471. 17:39

    that option. And then you can also set

  472. 17:40

    different pricing for intent as well. If

  473. 17:42

    somebody's coming here, if a bot is

  474. 17:45

    accessing the content for uh again

  475. 17:47

    training, you can charge a different

  476. 17:48

    rate than what it's doing for a search

  477. 17:50

    as well. So again, these are different

  478. 17:52

    VAF rules. they can be uh in a

  479. 17:54

    combination of end or or then you can

  480. 17:57

    access that. So this is how the

  481. 17:58

    reimagine flow would look like uh where

  482. 18:01

    you're allowing the AI agents or you

  483. 18:04

    know essentially verified bots and

  484. 18:06

    unverified bots to have different

  485. 18:07

    pricing and humans to have different

  486. 18:09

    pricing. Some cases you want to have

  487. 18:11

    humans to access the content freely.

  488. 18:12

    Some cases again the humans could be

  489. 18:14

    charged where the bots could be charged

  490. 18:16

    differently as well. Right? So this is

  491. 18:18

    how uh you know you can reimagine the

  492. 18:20

    price. So again there is some uh

  493. 18:21

    dashboards that show the revenue numbers

  494. 18:24

    and how uh you know you're uh able to

  495. 18:27

    aggregate by different uh bots and

  496. 18:30

    figure out what kind of revenue model

  497. 18:31

    you want to operate and it also shows

  498. 18:33

    what is the path uh that's being

  499. 18:35

    accessed by these bots right so uh again

  500. 18:38

    what is currently uh everyone using

  501. 18:40

    agent e-commerce for they're using agent

  502. 18:42

    commerce to uh run um again LLM

  503. 18:45

    inference getting uh compute web

  504. 18:48

    scraping uh they're uh creating research

  505. 18:50

    search agents to be able to uh you know

  506. 18:53

    serve the requests and uh agent to agent

  507. 18:55

    as well. We see MCPs also being

  508. 18:57

    monetized now. Uh again this is the last

  509. 19:00

    12 months of uh traffic uh from um again

  510. 19:04

    what we are seeing on uh Coinbase

  511. 19:06

    agentic market u where you're seeing

  512. 19:08

    that a $50 million volume transaction

  513. 19:10

    happened over 170 million transactions.

  514. 19:13

    The average settlement time is 200

  515. 19:15

    milliseconds on base uh with about a

  516. 19:19

    tenth of a cent as cost per transaction.

  517. 19:22

    So I spoke to you about agent uh agent

  518. 19:25

    core payments which is uh one of the you

  519. 19:28

    know parts of the bigger ecosystem agent

  520. 19:30

    uh bed agent core uh where you can

  521. 19:33

    essentially bring your own model. You

  522. 19:34

    can bring your own framework and uh you

  523. 19:37

    can start building AI agents. You can

  524. 19:40

    add context by adding memory. You can uh

  525. 19:43

    bring again your own managed knowledge

  526. 19:45

    bases. You can add web search

  527. 19:46

    capabilities to the agents. you can

  528. 19:48

    mcpify your internal APIs and then you

  529. 19:51

    can uh have many more features like

  530. 19:53

    being able to run evaluation on how your

  531. 19:55

    agents are performing. So again you can

  532. 19:58

    uh use runtime which is a bedrock uh

  533. 20:01

    agent core runtime where you can bring

  534. 20:03

    your own agentic uh uh application and

  535. 20:06

    serve uh at scale and every request will

  536. 20:10

    have uh its own isolated uh micro

  537. 20:12

    virtual machine that is running to serve

  538. 20:14

    the requests. So that's it from my side

  539. 20:17

    here today. Uh thank you and uh hope you

  540. 20:20

    have a nice day.

  541. 20:22

    [applause]

  542. 20:38

    >> [music]