AWS has detailed a production use of Amazon Bedrock AgentCore payments where AI agents purchase model inference one request at a time. Incarna uses the service to pay BlockRun, an inference router offering more than 90 models from over 15 providers through the x402 payment protocol.
The design targets a new economic pattern: agents making frequent purchases worth fractions of a cent inside an automated loop. Traditional card systems and monthly subscriptions do not fit that granularity well, while direct wallet code creates security, protocol and spending-control work for every developer.
Each model call can carry its own price
When an Incarna agent needs inference, BlockRun returns an HTTP 402 payment challenge with a quote. AgentCore payments checks the amount against the current session budget, signs an authorisation from the agent’s wallet and returns cryptographic proof. BlockRun verifies the proof, serves the model call and records the charge.
This lets the agent pay only for the inference it uses and avoids maintaining subscriptions or API credentials with every provider. It can also support routing where model choice changes according to task quality, latency and price.
Budgets sit outside the model
The most important control is the payment session. It defines a maximum spend and expiry that the service enforces outside the agent’s code and prompt. Even if a prompt is manipulated or a retry loop misbehaves, the model cannot increase its own ceiling.
Infrastructure enforcement is essential because language models are probabilistic and can misunderstand an instruction as authority to spend. Developers should still add application checks, alerts and human approval for unusual purchases, but those controls no longer bear the entire burden of preventing an unlimited transaction loop.
Managed wallets keep ownership with the customer
Incarna provisions a wallet for each agent using a Coinbase CDP connector. The customer owns the wallet and grants delegated authority for the agent to use it. Payment credentials can be stored in AWS Secrets Manager rather than application code.
Ownership and revocation paths matter as much as convenient payment. Customers need to know how to withdraw funds, disable an agent, rotate credentials and investigate disputed activity. Dedicated agent identities also make transactions easier to attribute than payments made through a shared organisational wallet.
Two x402 schemes cover fixed and variable charges
AgentCore payments supports exact pricing when the amount is known before the request and an upto scheme for dynamic cost. With upto, the agent authorises a ceiling and the provider settles the actual usage at the end, without exceeding that limit.
Variable pricing suits inference because token consumption may not be known until generation finishes. The ceiling gives buyers a predictable worst case, while metered settlement avoids charging the maximum for every call. Applications should display both the authorised limit and final charge in audit records.
Stablecoin settlement makes microtransactions practical
The production flow settles in USDC on the Base network, with each transaction verifiable on-chain. During the beta, agents processed more than 1,000 payments ranging from US$0.001 to US$0.05 per call.
On-chain verification provides a settlement record, but organisations still need accounting, tax, consumer-protection and jurisdictional review. A technically successful payment may require reconciliation to the user, task, model and business purpose that authorised it.
Integration time fell from months to days
Incarna completed the full integration in three days, including two days of testing, and wrote about 200 lines of application code. The team had initially estimated two to three months to build equivalent x402 support, wallets, signing and spending controls itself.
That reduction shows the value of moving common payment infrastructure into a managed layer. It does not eliminate integration risk: developers must still test price challenges, partial failures, duplicate requests, expired sessions and the behaviour of an agent when a payment is denied.
Agents become economic actors with bounded authority
Pay-per-inference can let an agent select specialist models or paid services at runtime instead of relying on a fixed stack. Similar patterns could apply to data, content, software tools and calls to other agents. The architecture makes payment another tool action governed by identity and policy.
That flexibility also creates new attack surfaces. Untrusted content could try to steer an agent towards an expensive endpoint or a merchant it controls. Allow lists, quote validation, per-merchant limits and anomaly detection should complement the overall session budget.
Safe autonomy depends on independent limits
The BlockRun and Incarna example demonstrates that tiny autonomous purchases can work in production without giving a model open-ended access to funds. Customer-owned wallets, expiring sessions and externally enforced ceilings provide a more credible foundation than asking an agent to obey a budget written in its prompt.
Amazon Bedrock AgentCore payments makes that pattern easier to adopt. Its broader importance lies in separating economic authority from model judgement. As agents gain the ability to buy services, the surrounding infrastructure must decide exactly how much they can spend, for how long and with whom.