ap2-agent-authorization
Installation
SKILL.md
AP2 Agent Authorization Framework
Before writing code
Fetch live docs:
- Fetch
https://ap2-protocol.org/ap2/agent_authorization/for the framework itself — this is the foundational model everything else sits on. - Fetch
https://ap2-protocol.org/ap2/specification/for the current mandate types and their schemas. - Fetch
https://ap2-protocol.org/glossary/— AP2's terminology has changed across releases and the glossary is the fastest way to catch a rename. - Web-search
site:github.com google-agentic-commerce AP2 mandate open closedfor reference types undercode/.
Terminology warning: AP2 renamed and restructured core objects between releases. Confirm the current names against the live glossary before writing any type. Never carry an object name forward from an older tutorial, blog post, or this skill.
Conceptual Architecture
The problem it solves
Even well-behaving agents need to have their behavior tightly constrained above what a normal authorization model would require of human users.
A human authenticating to a site is authorizing themselves. An agent acting for a human is a delegation, and delegation needs an explicit, verifiable, bounded grant. The Agent Authorization Framework is that grant.