
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
ap2-iso20022
Advanced tools
Bridge AP2 (Agent Payments Protocol) and x402 agent-payment mandates into wire-valid ISO 20022 pain.001 / pacs.008 records, with spending-cap, expiry and authorisation guardrails. Includes an MCP server.
Bridge AP2 (Google's Agent Payments Protocol) and x402
(Coinbase's HTTP-402) mandates into ISO 20022 pain.001 / pacs.008 records —
with spending-cap, expiry and authorisation guardrails, and an MCP
server. These agentic-payment protocols authorise a payment; this library
turns that authorisation into the bank-rail message that actually settles it
— the rail the card networks and stablecoins don't cover.
Latest release: v0.0.1 — 5 MCP tools over stdio, pure-Python (only
mcp), 100% branch coverage, for Python 3.10+. Output feeds straight intopain001/pacs008to generate wire-valid XML. Part of the ISO 20022 MCP suite.
An agent with a signed AP2 mandate (or an x402 payment authorisation) can prove
it's allowed to pay — but nothing in those protocols emits the pain.001 a
bank needs to move the money. ap2-iso20022 is that missing hop. And because
moving money is consequential, it only transforms and validates — producing
the ISO record is deliberately separate from generating and sending it, so the
actual payment stays an explicit, guarded step.
pip install ap2-iso20022
# or run the MCP server without installing:
uvx ap2-iso20022
MCP client config (e.g. Claude Desktop):
{
"mcpServers": {
"ap2-iso20022": {
"command": "ap2-iso20022-mcp"
}
}
}
from ap2_iso20022 import bridge
# 1. Normalise the protocol payload into a canonical mandate.
mandate = bridge.from_ap2({
"intent_id": "AP2-CoffeeRun-7",
"payer": "Alice's Shopping Agent",
"payer_account": "DE89370400440532013000",
"merchant_name": "Blue Bottle Coffee",
"payee_account": "GB29NWBK60161331926819",
"amount": "12.50", "currency": "EUR", "memo": "oat latte",
"spending_limit": "50.00",
"signature": "eyJ...", "signature_type": "jws",
})
# 2. Guardrail before it becomes a payment.
check = bridge.check_mandate(mandate, as_of="2026-03-02T09:00:00")
assert check["ok"] # required fields ok, within cap, not expired, signed
# 3. Convert to a pain.001 record that feeds pain001 -> wire-valid XML.
record = bridge.to_pain001(mandate) # exact pain001 field names + JSON number amounts
normalize_ap2 — AP2 mandate payload → canonical mandate.normalize_x402 — x402 payment payload → canonical mandate.check_mandate — Guardrail: required fields, spending cap, expiry (with as_of), authorisation proof.to_pain001 — Canonical mandate → pain.001 record (customer credit transfer).to_pacs008 — Canonical mandate → pacs.008 record (FI-to-FI).The output field names and types match what pain001 / pacs008 expect
(validated against their JSON schemas), so to_pain001(mandate) → pain001
generate_message → XSD-valid pain.001 with no glue.
check_mandate returns {ok, violations, warnings}:
amount <= max_amount when a cap is presentas_ofproof_type/proof_value is presentIt never moves money; it tells you whether the mandate is safe to act on.
Part of a family of vendor-neutral, Python-native ISO 20022 MCP servers:
iso20022-mcp — unified gateway across the families.pain001-mcp · pacs008-mcp — generate the XML this bridge feeds.reconcile-mcp — statement/payment reconciliation.camt-exceptions — E&I messages (cancellation, investigation).git clone https://github.com/sebastienrousseau/ap2-iso20022
cd ap2-iso20022
python -m venv .venv && . .venv/bin/activate
pip install -e . && pip install pytest pytest-cov ruff black mypy
pytest # 100% branch coverage gate
ruff check ap2_iso20022 tests && black --check ap2_iso20022 tests && mypy ap2_iso20022
Licensed under the Apache License, Version 2.0.
mcp-name: io.github.sebastienrousseau/ap2-iso20022
FAQs
Bridge AP2 (Agent Payments Protocol) and x402 agent-payment mandates into wire-valid ISO 20022 pain.001 / pacs.008 records, with spending-cap, expiry and authorisation guardrails. Includes an MCP server.
We found that ap2-iso20022 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.