← AUTOMATER NEWSROOM

AWS Bedrock AgentCore Payments Ships: Agents Buy Services Mid-Task While the Platform Enforces the Limit

Amazon Bedrock AgentCore payments gives agents managed wallets, x402 signing and spending ceilings enforced by AWS infrastructure. Incarna cut a two-to-three-month build to 200 lines and three days, and LangChain's Restock shows the build-it-yourself path with Stripe Link.

A diagram showing an AI agent mid-task paying a paid endpoint per call through AgentCore payments, which holds the wallet, signs the purchase, and enforces a session spending ceiling the model cannot raise.A diagram showing an AI agent mid-task paying a paid endpoint per call through AgentCore payments, which holds the wallet, signs the purchase, and enforces a session spending ceiling the model cannot raise.
AgentCore payments sits between the agent and the paid endpoint: the endpoint quotes a price over HTTP 402, the managed service signs from the agent's wallet, and the session ceiling is enforced outside the model, per the AWS post. Illustration by Automater Newsroom.

Agents keep hitting the same wall mid-task: the next step costs a fraction of a cent, and nobody is online to approve the purchase. On October 8, 2026, AWS published a walkthrough of Amazon Bedrock AgentCore payments, a managed capability that lets an agent pay for a model inference, an API response, web content, or a call to another agent while it runs. The detail that matters to operators: spending limits are enforced by AWS infrastructure, not by the agent’s prompt or its code.

The AWS Machine Learning Blog article titled Pay-per-inference for AI agents: How BlockRun and Incarna use Amazon Bedrock AgentCore payments, showing the post's headline and opening section.
The AWS Machine Learning Blog post of October 8, 2026 introducing Amazon Bedrock AgentCore payments through the BlockRun and Incarna pay-per-inference integration. · Original source

What shipped

AgentCore payments bundles what teams would otherwise assemble themselves. Per the post, it handles the payment protocol, connects to a wallet, signs each transaction, and enforces spending limits, and it works with x402-compatible endpoints, including Amazon Bedrock inference endpoints. The mechanic is an HTTP 402 “Payment Required” challenge: the paid endpoint answers with a price for that specific call, the agent calls ProcessPayment, AgentCore checks the quote against the session’s limits and signs the authorization from the agent’s wallet, the seller verifies the signature, and the call is served and charged.

Two schemes are supported. exact suits prices known up front. upto lets the agent authorize a ceiling while the provider settles actual usage under it, which maps onto dynamically priced inference.

A five-step numbered flow diagram of one paid inference: the agent needs a call, the endpoint answers HTTP 402 with a price, the payment session checks the ceiling and signs from the agent's wallet, the seller verifies the signature, and the inference is served and settled per call.A five-step numbered flow diagram of one paid inference: the agent needs a call, the endpoint answers HTTP 402 with a price, the payment session checks the ceiling and signs from the agent's wallet, the seller verifies the signature, and the inference is served and settled per call.
The per-request payment loop described in the AWS post: a 402 quote, a session-checked signature from the agent's own wallet, and a per-call charge settled on-chain. Diagram by Automater Newsroom.

The production proof

BlockRun is the seller: a pay-as-you-go inference router serving more than 90 models from more than 15 providers over x402, with every call quoted, paid, and settled independently. Incarna, built by SpreadX, plays the buyer with a persistent agent identity that carries its own wallet, email address, social accounts, and action history across runs, live on Base mainnet.

The numbers are the story. Incarna scoped x402 payment support at two to three months and shipped in three days — one to build, two to test — in roughly 200 lines of application code. Across the beta, agents processed over 1,000 payments ranging from $0.001 to $0.05 per call, each settling individually on-chain in USDC on Base. Wallets are provisioned through the Coinbase CDP connector; the customer owns the wallet and grants Incarna a delegated authorization to spend from it.

The ceiling lives outside the model

The control that makes this defensible is the payment session. A session sets a ceiling, the most the agent can spend, plus an expiry, and AgentCore enforces both at the infrastructure layer. AWS states that an agent cannot exceed its limits even if its prompt is manipulated. Incarna sizes sessions to a day’s budget, and AWS notes that integrations without session-level budgets today can adopt them without code changes.

Setup is mostly provisioning. Store Coinbase CDP or Stripe Privy credentials as a payment credential provider, which keeps secrets in AWS Secrets Manager instead of your code. Create a Payment Manager and connector, set a default spending limit, then create the payment instrument, the embedded wallet the agent pays from. The end user funds it and grants signing permission through a redirect URL; on a test network you can fund it with testnet USDC. A guided path runs through the AgentCore payments skill in the Agent Toolkit for AWS, in Claude Code, Kiro, or Codex, or via the AgentCore CLI, SDK, or AWS SDK. AgentCore itself is AWS’s platform for building, connecting, and optimizing production agents with any framework and any model, per the product page.

The build-it-yourself twin

The same day, LangChain published Restock, a sample office-supply agent that runs in Slack on Managed Deep Agents, searches real products through Zinc, and pays through Link, Stripe’s consumer wallet, over the Machine Payments Protocol. The same two principles recur. The model never touches payment credentials: the Link session lives in a user-owned MDA Connection, the payment token is deleted after use, and only a public summary returns to the model. And spending stays inside a budget the model cannot raise: the user approves an amount up to a set ceiling, and a Slack review interrupt pauses the run until someone clicks Approve or Reject. Nothing the model writes into a tool call can approve the purchase.

AgentCore payments Restock on Managed Deep Agents
Rail x402, settled in USDC on Base Machine Payments Protocol with Link
Wallet Coinbase CDP embedded wallet, customer-owned Link session in a user-owned Connection
Spend control Session ceiling enforced by infrastructure User-approved amount plus Slack review
Best fit Pay-per-call services at scale Consumer purchases driven from chat

In the documented run, a $25 pens request became a $23 Link approval, a $21.18 retailer order, a $22.18 payment with Zinc’s fee, and an $0.82 refund. Restock ships three modes — rehearsal, link-test, and live — selected with RESTOCK_MODE, with sample code on GitHub.

What to do with it

  • Size a session ceiling per task, the way Incarna sizes one per day, and let the platform block the agent instead of hoping the prompt does.
  • Keep approvals and limits in code the model cannot touch. That is LangChain’s closing rule, and it is AgentCore’s design.
  • Reconcile per-call charges against the meters you already keep, as with any other agent billing meter, and wire anomalies to cost alerts that can auto-pause a lane.
  • Before any agent gets checkout power, run the pre-authorization checklist and decide who holds the keys when one token can call thousands of paid tools.

The shape is settling: agents that spend money get wallets they do not control, ceilings they cannot raise, and receipts that settle per call. AWS will run that for you inside Bedrock; LangChain shows the same architecture is buildable in an afternoon.

Sources

  1. Pay-per-inference for AI agents: How BlockRun and Incarna use Amazon Bedrock AgentCore payments | Artificial Intelligence
  2. Amazon Bedrock AgentCore - AWS
  3. Agents that can pay: building Restock with Stripe's Link and Managed Deep Agents