AIAI EngineerSep 1, 2026· 20:41

When AI Agents Pay and Sellers Monetize: Building x402 Apps on AWS — Anil Nadiminti, AWS

Anil Nadiminti, Senior Solutions Architect at AWS, presents AgentCore Payments — a service that lets AI agents autonomously discover, authorize, and execute payments for premium content over the x402 protocol. He explains how AgentCore handles paywalls through wallet support via Coinbase, with KMS-secured secret storage keeping private keys safe. Bot detection verifies trusted agents while blocking malicious ones, and per-session budgets with spend limits keep settlement instantaneous at internet speed. Real-time traffic analysis and observability throughout the stack ensure payment connectors, MCP5 integration, and web scraping all operate without exposing credentials — no centralization required, no SDK change, and no friction for developers building agentic applications.

  1. 0:00Intro & welcome
  2. 1:00Bot traffic passes human traffic
  3. 2:00x402 protocol explained
  4. 3:00Seller's dilemma: block or absorb
  5. 4:00Verified bots & signatures
  6. 5:00KMS-backed key storage
  7. 6:00WAF rules at the edge
  8. 7:00MCP5 internal APIs
  9. 8:00Deterministic agent loop
  10. 9:00Attribution & identity
  11. 10:00Protocol agnostic design
  12. 11:00Bot detection at edge

Powered by PodHood

Transcript

Intro & welcome0:00

Anil Nadiminti0:13

Hello all, welcome to the Agent E-commerce track, and I'm Anil Nadiminti. I'm a Senior Solutions Architect here at AWS. I'm here to talk to you today about how AWS is innovating and how you can build apps on AWS to support the Agent E-commerce.

So, welcome to the session. Just to get you started, let me set the stage with something that you're very familiar with. Imagine that you or your organization is building a news portal like this,right? So you're all familiar with something where you're accessing the news content, and then suddenly you hit a paywall,right?

So this is where you pull out your wallet, or you try to figure out how to make the payments, set up your credentials, access keys, in the sense that you make a credit card transaction, weekly, monthly, or annual subscription, and then get started to access the content,right?

Bot traffic passes human traffic1:00

Anil Nadiminti1:07

So this is all the content that is behind a paywall. But what we see now is that much of the traffic that is actually being sent to these portals now on the internet is all coming from bots. We see that we're at an inflection point where the bot traffic is more than the human traffic,right?

So it's just, actually, in fact, surpassed that, and 95% of that bot traffic is coming from AI agents. So, essentially, we are also looking at the rise of autonomous agents,right? So where we all started using LLMs, asking questions, asking for summarization, being able to get help with using them as copilots, getting them to do agent work, to do multi-step tasks, and now we're in the phase of autonomous agents where agents are using the reasoning powers of large language models to complete a task.

And completing a task means that it has to go do whatever you're asking it to do,right? That's kind of where we are in the journey. And we see that by 2027, about a billion agents will be running performing tasks, and 60% of the enterprises will already be using agent workflows.

x402 protocol explained2:00

Anil Nadiminti2:17

So what happens when agents hit these paywalls that we just saw? When agents hit the paywalls, they stall, they can't operate, and you see those messages that, "Hey, I cannot access content,"right? So at that point, humans get in the loop.

They try to enter and put the credit card details or API keys to those transactions for the AI agents, but all of that is manual friction,right? So essentially bringing in a human in the loop. So autonomous agents actually break at that point where the friction is now building up.

So now sellers of the content have, you know, a couple of options,right? So block all their bot traffic, but by blocking all the traffic, they lose this AI-powered discovery, they miss this partnership, licensing options, and AI also now supports citations,right?

Seller's dilemma: block or absorb3:00

Anil Nadiminti3:07

So the responses. So they lose all of that powered citations as well if they can't sell the content. Essentially, they lose revenue-generating options. And if you allow the bots to access the content, what it means is that, you know, hundreds of thousands of bots or millions of bots could be hitting your infrastructure, which means that the infrastructure costs will also raise, and you need to be able to support all of that,right?

So you also, when you allow bots to access content, you lose attribution, the IP itself,right? So because content is now freely available. So both these decisions are probably not a good option. They're not ideal. So there should be another ideal option where you would want to have your AI agents being able to get and pay for the content that they are looking for and monetize on that.

So now we look at the next phase of rise in autonomous agents where agents should be able to transact and discover other agents' resources and essentially make payments,right? So this is the definition of Agent E-commerce where AI agents can essentially discover.

Verified bots & signatures4:00

Anil Nadiminti4:12

You know, it's a form of e-commerce where autonomous agents can discover independently and make those settlements and then access content. So let's look at the Agent E-commerce, the two sides of Agent E-commerce, the buy side and the sell side.

So when we talk about the buy side, the agents are making these transactions, and on the sell side, the sellers of the content are trying to monetize on the content. So on the buy side, when you look at things, AI agents want to access this premium paywall content, licensed content.

They want to be able to hold wallets, which they do not have the option today, and they want to be able to make these microtransactions you just heard in the prior talk as well. But enterprises, when they come to this point, they want more guardrails, and they do not want agents to go on spending spree.

Think about it,right? Would you allow your AI agents to get handle on your wallets or credit cards to be able to do that,right? Transactions and where they could go rogue as well,right? So that's what the buyer side is looking at.

KMS-backed key storage5:00

Anil Nadiminti5:06

And on the seller side, there are, again, billions of transactions that would be happening with these AI bots. So sellers really want to be able to understand what kinds of bots are operating, what kinds of transactions they're making, and really do this at the edge.

The sellers don't want to change their entire infrastructure and origins where the content is sitting. They want to be able to do this at the edge without changing much of this,right? So there is, again, one common thing here on the buyer side and the seller side, which is a standardized approach or a protocol to be able to solve for this machine-to-machine payments at the edge.

So bottom line, buyers are saying that they want their agents to be able to pay for content and not have humans approving this, and then the sellers are saying that they want to be able to earn from the AI traffic.

So bottom line, the subscription model is going to change with humans in the loop to becoming humans on the loop or out of the loop, and that's kind of what we are building towards. The traditional one-size-fits-model does not work anymore because of the fact that, again, we look at that in the next slide where the transactions costs will not really work,right?

WAF rules at the edge6:00

Anil Nadiminti6:13

All of this needs to be happening at real-time speed, and the paper use and paper execution is what the future is going to look like. So if you're a seller, you would have come across this,right? So there is a 25 cent minimum transaction fees as well as 2.5% on top of that, and all of these microtransactions are, you know, in the, like, a cent, subcent, or, you know, microcents is what we are calling them.

So if you add, like, 25 cents on top of that, it's essentially like 250 times what, you know, they are essentially paying for. So all of this model does not work, and while we are trying to solve for that, a very brief history of this is every HTTP call essentially responds back, you know, there's a response for that.

You've seen 200 status codes, 404, you know, and 301, these are all, like, status codes that you're familiar with. And then there is one status code which is 402, which has not been used. It was reserved for payment required, and now, finally, Coinbase has introduced this as transactions over 402, which is also called as x402, where they, you know, the protocol talks about how you can do machine-to-machine transactions using this protocol,right?

MCP5 internal APIs7:00

Anil Nadiminti7:23

So we'll take a closer look at that, but what happens within the protocol is, you know, if you look at this flowchart here, a client makes a request to the server, and then the server responds back with the payment required.

The client then figures out what is the payment method that it wants to operate, and then it sends the payment authorization to the server. The server then utilizes a facilitator to complete the verification and then also utilizes the same facilitator to complete the transaction, and once the settlement is completed on-chain, essentially the server will then respond back with the content,right?

So this is what's happening under the x402 protocol. I thought I'll pick one of the protocols and just explain this to you, but why this is compelling is, you know, essentially there is no protocol fees or the fees that a consumer is paying for, you know, these microcent transactions, and the merchant is paying very nominal gas fees.

Deterministic agent loop8:00

Anil Nadiminti8:15

Again, there is zero wait time. This is happening at the speed of internet, and there is no friction. There are no API keys to set up, no subscriptions, and the payment is essentially the credential to be able to get the content.

So there is no centralization. It's x402 can be extended as well, and you can implement it, and there are no restrictions as well. So some key milestones here are, you know, it was introduced last year, May 2025. x402 is now part of the Linux Foundation under open governance, and it's backed by Coinbase, AWS, Google, Stripe, Anthropic, Cloudflare, and Circle,right?

So many more folks in there that are supporting that, organizations in there. So from Amazon, we have also released AgentCore Payments under the Bedrock suite, so where agents will be able to make payments, and we'll go into some of the details here.

Attribution & identity9:00

Anil Nadiminti9:09

So let's talk about the buyer side here and what is involved,right? So we understood from the developers that they really want to be able to get these agents to have wallet support. They want to be able to have real-time settlement, have the budget and guardrails, which enterprises really want, and observability throughout the stack where they would want to have the full stack trace of everything that's happening under the hood.

So I'm excited to share with you that we've launched AgentCore Payments, and this is a service that allows AI agents to autonomously discover, authorize, and execute payments with a few lines of code. Now we've launched this in partnership with Coinbase and Stripe where you can bring wallets from Coinbase and Stripe preview to be able to do these operations, and we'll go into some of the details.

But the core capabilities to start with are wallet support where you can bring the wallets from Coinbase and Stripe. You're able to orchestrate the payments using payment connectors, and today we support x402 with many more protocols to, you know, that are in the pipeline.

Protocol agnostic design10:00

Anil Nadiminti10:10

The service is designed to be protocol agnostic, so as new protocols emerge, we are going to be adding the support for those protocols as well. And, you know, the settlement is going to be instantaneous, instant, essentially, and the payment limits can be set, which is the most important thing that we spoke about where enterprises are looking to put some payment limits and guardrails on how these transactions can operate.

So observability is built in, and essentially all of this operates with, you know, security as the layer that is operating the whole model,right? So with that, let's look at some of these details on how the payments limit can be set up,right?

So you can create payment sessions where you can set the programmatically set the maximum amount of value that can be used for transactions, or you can also set expiry time in minutes. Think where you are able to set that I can, the agent can actually spend maybe $5 in 30 days or 60 days,right?

Bot detection at edge11:00

Anil Nadiminti11:09

So that's kind of the operation model that you can set with many more, you know, details that are available. I'm only going over a few features, but let's look at what happens on the buyer side. When the user is asking an agent to make a particular, you know, requesting for resources,right?

So agent completes the request by accessing tools, MCP servers, other resources as well. So at that point of time, if the agent is looking at, you know, it finds that there is a response from one of the tool calls or requests with the 402, AgentCore Payments is going to handle the request to complete the transaction and then let the AI agent know that essentially the settlement happened and the AI agent will be able to respond back with the users.

So in this process, when the wallets are, wallet support is imported, the secret keys that you use to import the wallets actually are stored in a secure token wallet that is secured by KMS where, you know, that's there.

So essentially the agent does not have access to the private keys. This is most important to note. And next thing is that AgentCore Payments is also integrated through a gateway, which is also part of, which is another service that we have to MCP5, your internal APIs.

Through AgentCore gateway, the AgentCore Payments can get access to discovery service in Coinbase where there are 10,000 plus endpoints that are available to transact. And then, again, there is a per-session budget that we just discussed as well. So there is a decoupling of agent infrastructure and the payment infrastructure by design where the agent can operate in its own loop, and whenever it sees the payment, the payment connectors, orchestration, payment limits, and integration with third-party wallets can happen,right?

So it's important to decouple them because, again, skills can be poisoned. Inputs for the agents can also be, you know, poisoned by inputs as well,right? So where malicious actors could try to do that. So by decoupling and making this by design, AI agents can essentially have a secure path for these transactions, and payments do not touch the, you know, undeterministic path, but this is more on a deterministic layer as well.

So why this is important is that, again, AI agents, the code of the agents does not have to change. You can bring your own model frameworks, and then the payment itself can flow through in the payment layer itself.

So again, the controls, the policy spending controls can be outside of the payment stack itself, and again, this is built to be protocol agnostic. So this is one of the console screens where it shows how you can import the payment connector, and it shows that, you know, you can select the Coinbase wallet and the Stripe preview wallet from the console.

And this is a demo in action where we are showing how a secure resource can be accessed. Now, in this case, the AI agent is essentially making, you know, discovering that there is a secure resource. The AgentCore Payments is kicking in, and then it's completing the transaction by utilizing the wallet that is already integrated, and the transaction completes.

Now, this is on the buyer side. Now, let's look at the seller side to understand what's happening,right? So again, there is a lot of bot activity that's happening. We have released under the AWS web application firewall a feature where we have bot detection in place.

Today we detect over 650 different types of bots. Think of bots like Perplexity Bot, GPT Bot, Claude Bot, you know, again, Google Bots,right? So there are so many bots around there. So we're able to detect, also understand the intent of these bots.

So why are these bots asking the content? Are they asking the content to train their models? Are they doing it because they have to respond back to an intent where they're responding for a RAG search? So we're able to identify the intent.

We're also able to verify the bots and identify them by a signature. So we are able to say, "Hey, this is a verified bot." So maybe you have built a relation with one of these organizations, and these verifications will allow you to have a different pricing for the organizations that are already verified.

So we'll look at that in a second. So there's also real-time traffic analysis that allows more to be customized. And I'm also happy to share with you today that we announced WAF, AI traffic monetization. This is a service that allows you to monetize based on the content that, you know, based on how you can measure, verify, and monetize based on the AI traffic that is hitting your endpoints.

Now, if you might be familiar with CloudFront, which is our content distribution network, you can add a web application firewall at that point, and essentially you can start monetizingright away, and based on a few clicks, you can do that, again, using infrastructure as code as well.

Now, I also spoke about a gateway service that allows you to expose your AI endpoints that are internal and MCP5 them. So the same web application firewalls can be used there. So your internal APIs can be MCP5, and then you can start monetizing as well.

So what happens during monetization? The AI agent, AI bot essentially requests for some content. The bot context understands what kinds of bots it's detecting. It's able to detect the bot. It's able to categorize and understand the intent of the bot, as we discussed earlier, and verify and check what kind of bot is available.

So then we're able to monetize using the x402, and the publishers get paid as well. So important to note is that, again, there is no SDK change, no changes at the origin. Publishers keep 100% of the revenue as well, and again, there are no transaction fees or subscription fees.

So this supports x402, and we are adding support for more protocols as well. A few dimensions on how you can start monetizing. Think you have separate paths. So a slash blog in this case can be charging for a different rate than a slash research or maybe an API endpoint itself.

And you know the identity of these bots. Again, if you make some kind of relationship with the bots companies, organizations, maybe you make a relation with Anthropic, then you can essentially have a different pricing for those bots versus different unverified bots,right?

So think of that option. And then you can also set different pricing for intent as well. If somebody is coming here, if a bot is asking the content for, again, training, you can charge a different rate than what it's doing for a search as well.

So again, these are different WAF rules. They can be in a combination of and or, and then you can access that. So this is how the reimagined flow would look like where you're allowing the AI agents or, you know, essentially verified bots and unverified bots to have different pricing and humans to have different pricing.

Some cases you want to have humans to access the content freely. Some cases, again, the humans could be charged where the bots could be charged differently as well,right? So this is how, you know, you can reimagine the price.

So again, there are some dashboards that show the revenue numbers and how, you know, you're able to aggregate by different bots and figure out what kind of revenue model you want to operate. And it also shows what is the path that's being accessed by these bots,right?

So again, what is currently everyone using AgentEcommerce for? They're using AgentEcommerce to run, again, LLM inference, getting compute, web scraping. They're creating research agents to be able to, you know, serve the request and agent to agent as well.

We see MCPs also being monetized now. Again, this is the last 12 months of traffic from, again, what we are seeing on Coinbase Agentic market where you're seeing that a $50 million volume transaction happened over 170 million transactions.

The average settlement time is 200 milliseconds on base with about a tenth of a cent as cost per transaction. So I spoke to you about AgentCore Payments, which is one of the, you know, parts of the bigger ecosystem, Agent WebDock AgentCore, where you can essentially bring your own model, you can bring your own framework, and you can start building AI agents.

You can add context by adding memory. You can bring, again, your own managed knowledge bases. You can add web search capabilities to the agents. You can MCP5 your internal APIs, and then you can have many more features like being able to run evaluation on how your agents are performing.

So again, you can use runtime, which is Bedrock AgentCore runtime, where you can bring your own agentic application and serve at scale, and every request will have its own isolated micro virtual machine that is running to serve the requests.

So that's it from my side here today. Thank you, and hope you have a nice day.