AWS Bedrock AgentCore Payments Ships: Agents Buy Services Mid-Task While the Platform Enforces the Limit
Amazon Bedrock AgentCore payments gives agents managed wallets, x402 signing and spending ceilings enforced by AWS infrastructure. Incarna cut a two-to-three-month build to 200 lines and three days, and LangChain's Restock shows the build-it-yourself path with Stripe Link.
Agents keep hitting the same wall mid-task: the next step costs a fraction of a cent, and nobody is online to approve the purchase. On October 8, 2026, AWS published a walkthrough of Amazon Bedrock AgentCore payments, a managed capability that lets an agent pay for a model inference, an API response, web content, or a call to another agent while it runs. The detail that matters to operators: spending limits are enforced by AWS infrastructure, not by the agent’s prompt or its code.

What shipped
AgentCore payments bundles what teams would otherwise assemble themselves. Per the post, it handles the payment protocol, connects to a wallet, signs each transaction, and enforces spending limits, and it works with x402-compatible endpoints, including Amazon Bedrock inference endpoints. The mechanic is an HTTP 402 “Payment Required” challenge: the paid endpoint answers with a price for that specific call, the agent calls ProcessPayment, AgentCore checks the quote against the session’s limits and signs the authorization from the agent’s wallet, the seller verifies the signature, and the call is served and charged.
Two schemes are supported. exact suits prices known up front. upto lets the agent authorize a ceiling while the provider settles actual usage under it, which maps onto dynamically priced inference.
The production proof
BlockRun is the seller: a pay-as-you-go inference router serving more than 90 models from more than 15 providers over x402, with every call quoted, paid, and settled independently. Incarna, built by SpreadX, plays the buyer with a persistent agent identity that carries its own wallet, email address, social accounts, and action history across runs, live on Base mainnet.
The numbers are the story. Incarna scoped x402 payment support at two to three months and shipped in three days — one to build, two to test — in roughly 200 lines of application code. Across the beta, agents processed over 1,000 payments ranging from $0.001 to $0.05 per call, each settling individually on-chain in USDC on Base. Wallets are provisioned through the Coinbase CDP connector; the customer owns the wallet and grants Incarna a delegated authorization to spend from it.
The ceiling lives outside the model
The control that makes this defensible is the payment session. A session sets a ceiling, the most the agent can spend, plus an expiry, and AgentCore enforces both at the infrastructure layer. AWS states that an agent cannot exceed its limits even if its prompt is manipulated. Incarna sizes sessions to a day’s budget, and AWS notes that integrations without session-level budgets today can adopt them without code changes.
Setup is mostly provisioning. Store Coinbase CDP or Stripe Privy credentials as a payment credential provider, which keeps secrets in AWS Secrets Manager instead of your code. Create a Payment Manager and connector, set a default spending limit, then create the payment instrument, the embedded wallet the agent pays from. The end user funds it and grants signing permission through a redirect URL; on a test network you can fund it with testnet USDC. A guided path runs through the AgentCore payments skill in the Agent Toolkit for AWS, in Claude Code, Kiro, or Codex, or via the AgentCore CLI, SDK, or AWS SDK. AgentCore itself is AWS’s platform for building, connecting, and optimizing production agents with any framework and any model, per the product page.
The build-it-yourself twin
The same day, LangChain published Restock, a sample office-supply agent that runs in Slack on Managed Deep Agents, searches real products through Zinc, and pays through Link, Stripe’s consumer wallet, over the Machine Payments Protocol. The same two principles recur. The model never touches payment credentials: the Link session lives in a user-owned MDA Connection, the payment token is deleted after use, and only a public summary returns to the model. And spending stays inside a budget the model cannot raise: the user approves an amount up to a set ceiling, and a Slack review interrupt pauses the run until someone clicks Approve or Reject. Nothing the model writes into a tool call can approve the purchase.
| AgentCore payments | Restock on Managed Deep Agents | |
|---|---|---|
| Rail | x402, settled in USDC on Base | Machine Payments Protocol with Link |
| Wallet | Coinbase CDP embedded wallet, customer-owned | Link session in a user-owned Connection |
| Spend control | Session ceiling enforced by infrastructure | User-approved amount plus Slack review |
| Best fit | Pay-per-call services at scale | Consumer purchases driven from chat |
In the documented run, a $25 pens request became a $23 Link approval, a $21.18 retailer order, a $22.18 payment with Zinc’s fee, and an $0.82 refund. Restock ships three modes — rehearsal, link-test, and live — selected with RESTOCK_MODE, with sample code on GitHub.
What to do with it
- Size a session ceiling per task, the way Incarna sizes one per day, and let the platform block the agent instead of hoping the prompt does.
- Keep approvals and limits in code the model cannot touch. That is LangChain’s closing rule, and it is AgentCore’s design.
- Reconcile per-call charges against the meters you already keep, as with any other agent billing meter, and wire anomalies to cost alerts that can auto-pause a lane.
- Before any agent gets checkout power, run the pre-authorization checklist and decide who holds the keys when one token can call thousands of paid tools.
The shape is settling: agents that spend money get wallets they do not control, ceilings they cannot raise, and receipts that settle per call. AWS will run that for you inside Bedrock; LangChain shows the same architecture is buildable in an afternoon.