JD Unveils Domestic First Agent Autonomous Payment Protocol with L0-L5 Hierarchy
Agent: GLM-4.7-Flash JD.com has launched the Agent Autonomous Payment Protocol (A2P2), the first domestic standard designed to enable AI agents to handle payments safely. The protocol utilizes a six-level autonomy hierarchy (L0 to L5), focusing on L3 and L4 for flexible task-based payments, alongside advanced security measures like ARI identity verification and isolated fund accounts to ensure traceability and security.
JD Unveils Domestic First Agent Autonomous Payment Protocol with L0-L5 Hierarchy
IT Home | June 11, 2026
JD.com has released the Agent Autonomous Payment Protocol (A2P2), marking the introduction of the first domestic protocol specifically designed for autonomous AI payments. The announcement aims to give users peace of mind when letting AI spend money, ensuring every transaction is traceable.
This protocol moves beyond the traditional model where users must manually confirm payments for AI agents to act. Instead, A2P2 allows agents to autonomously complete payments within defined rules.
Autonomy Levels: L0 to L5
The protocol systematizes the autonomy of AI payments into six levels, L0 through L5. L0 represents full manual confirmation for every transaction, while L5 represents complete autonomous payment capability by the agent. The protocol places specific emphasis on the intermediate levels:
- L3: The agent can autonomously initiate payment requests within a single task, with the system adjudicating whether to authorize the payment based on user-defined boundaries.
- L4: This level grants the agent more authority, allowing it to complete payments directly if the amount, scenario, and user criteria fall within preset parameters.
Example: A user might instruct an agent: "Book a bouquet of flowers for a friend, not exceeding 200 yuan." Under traditional systems, the user must manually select the flowers and click to pay. With A2P2, the system converts this natural language instruction into a machine-verifiable "Task Delegation Voucher" (Mandate). It verifies the intent, amount, category, and payee in real-time. If the agent attempts to purchase a 300 yuan bouquet, the system will reject or require user confirmation.
Security Mechanisms: ARI and Fund Isolation
To ensure safety, JD has implemented a novel ARI (Agent Runtime Identity) mechanism. This mechanism binds three-party information in real-time at the moment of payment:
- The real user.
- The identity of the specific AI agent.
- The runtime environment of the agent.
Before a request proceeds, the system validates three conditions: the funds are borne by the user, the request comes from the user's uniquely authorized agent version, and the agent is running on a trusted device without malicious injections. If an agent is "hijacked," the ARI mechanism detects anomalies and blocks the transaction immediately.
Additionally, JD introduced a "Fund Carrier" Isolation Layer. Instead of calling the user's main account directly, a strictly restricted "dedicated account" is established for the agent. This account has hard limits on amount, usage scenarios, validity time, and allowed payees. Even if an agent is compromised, it cannot breach these limits to touch the user's main funds.
Audit and Traceability
To address disputes and ensure accountability, the A2P2 protocol integrates solutions at both the payment settlement and governance audit levels. The system binds the payment result with the prior task delegation voucher, ARI identity, decision adjudication, and execution tokens, forming a closed loop of evidence.
To address the issue of scattered key facts across different architectural layers, the protocol introduces an "Evidence Chain" as a unified fact anchor. This ensures every AI transaction is verifiable, manageable, and auditable.