AP2 is a future option, not a requirement.
Attesso is a PSP-agnostic spending-control and evidence layer. You do not need AP2 to use it. We are exploring an AP2 v0.2 human-not-present adapter as a future compatibility option, so mandates issued in other systems could enter the same runtime. Conformance and production compatibility are not yet claimed.
Attesso’s AP2 v0.2 adapter is in development.
Compatibility is a staged claim.
The first target is one pinned human-not-present profile. Attesso does not claim AP2 conformance, FIDO certification, or general production support. The native spending-control path is fully usable without AP2 today.
AP2 stays outside the core product.
- Verify issuer trust, signatures, audience, timestamps, version, type, pair binding, and replay.
- Preserve exact signed AP2 artifacts, source-specific digests, provenance, and disclosures.
- Translate only lossless supported semantics into the canonical policy and action runtime.
- Create AP2 Mandate Receipts only when Attesso is legitimately acting as the action Verifier.
Verifier, not every participant.
For the supported profile, Attesso is being designed to authorize an identifiable closed mandate presentation when configured as the Verifier.
Attesso does not issue Merchant Checkout Receipts or payment-method-provider Payment Receipts, and it never re-signs externally supplied receipts as its own.
Native hosted passkey approval remains independent of AP2 and continues to feed the same source-neutral runtime.
Using AP2 mandates or exploring compatibility?
Discuss the supported profile, semantic boundaries, and evidence responsibilities with us.