AP2 v0.2

Operational infrastructure for delegated mandates.

AP2 defines how participants exchange signed mandates and receipts. Attesso is building the stateful runtime needed to verify those mandates, enforce their limits, control single use, and retain evidence.

Attesso’s AP2 v0.2 adapter is in development.

Status

Compatibility is a staged claim.

The first target is one pinned human-not-present profile. Attesso does not claim AP2 conformance, FIDO certification, or general production support.

Native hosted passkey approval
Available in sandbox
Canonical mandate and action runtime
Implemented
AP2 v0.2 human-not-present adapter
In development
AP2 conformance
Not yet claimed
Qualified-provider finality
Production requirement
Production external execution
Not yet generally available
Adapter boundary

AP2 stays outside the core runtime.

  • Verify issuer trust, signatures, audience, timestamps, version, type, pair binding, and replay.
  • Preserve exact signed AP2 artifacts, source-specific digests, provenance, and disclosures.
  • Translate only lossless supported semantics into the canonical policy and action runtime.
  • Create AP2 Mandate Receipts only when Attesso is legitimately acting as the action Verifier.
Role boundaries

Verifier, not every participant.

For the supported profile, Attesso is being designed to authorize an identifiable closed mandate presentation when configured as the Verifier.

Attesso does not issue Merchant Checkout Receipts or payment-method-provider Payment Receipts, and it never re-signs externally supplied receipts as its own.

Native hosted passkey approval remains independent of AP2 and continues to feed the same source-neutral runtime.

View the authorization runtime

Working with AP2 mandates or provider finality?

Discuss the supported profile, semantic boundaries, and evidence responsibilities with us.