LangChain built an agent that pays real merchants with Stripe's Link. The spending limit lives in code the model cannot touch
Letting an agent find products is easy. Letting it pay is where most teams should slow down. LangChain just published a blueprint worth copying.
What happened
LangChain released Restock, a sample office supply agent that runs in Slack on its Managed Deep Agents platform. It searches products, builds a cart and pays through Link, Stripe's consumer wallet, using an API that supports the Machine Payments Protocol (MPP). MPP is an open standard for payments over HTTP 402: the merchant replies "Payment Required" with instructions, and the client retries with a payment credential.
The safety design is the interesting part:
- The agent never sees a card number. Stripe's documentation says Link Agent Wallet returns a one time use credential after the customer approves a spend request.
- A user's budget is a ceiling, not an amount to charge. In LangChain's illustrative example, a $25 budget becomes a $23 approved payment, the order costs $22.18 with fees and $0.82 is refunded.
- The user approves twice: the purchase in Slack, then the payment in Link. The Slack review pauses the run, and nothing the model writes into a tool call can approve it.
- The payment tool deletes the token after use, checks the order against what the user reviewed and confirms the approval is still fresh.
- An order only counts as placed when the merchant confirms it.
Restock has rehearsal, test approval and live modes. As a sample it supports US delivery and USD only.
My take
Most businesses will not let an agent buy office pens soon. But the pattern applies to every automation that moves money: paying supplier invoices, issuing refunds, topping up ad accounts.
LangChain's own summary is the rule I follow: let the agent search and build the cart, keep the spending limit and approvals in code the model cannot touch, and count an order as placed only when the merchant says so.
In practice that means three things. Payment credentials live outside the model, in a vault or a wallet like Link. Limits are enforced by the payment layer, not by a sentence in the prompt. And the automation confirms the result from the merchant or the bank before it updates your CRM or books.
Start in rehearsal mode, exactly like Restock does, and only go live after a few weeks of clean runs.
More posts
- Deno is joining Cloudflare and Deno Deploy shuts down in about six months. Check where your webhooks and scripts runOct 10, 2026
- AI coding agents added 23% more pull requests but no more finished features. Review is the bottleneck in your automations tooOct 10, 2026
- Anthropic's test agents filed a fake police tip and worked around paywalls. Tell your agents what they must never doOct 10, 2026
