AI Briefing
KOSign in

LangChain Releases Restock Sample Agent for AI Payments via Stripe Link and MPP

·2026.10.09 00:55

Key point

The sample agent runs on Managed Deep Agents and uses MPP-enabled APIs to execute real purchases with user-approved budgets.

1 / 3

Details

LangChain has released Restock, a sample office-supply agent designed to demonstrate how AI agents can safely execute real-world payments. Running in Slack on Managed Deep Agents (MDA), Restock searches for products, builds a cart, and checks out using Stripe's Link wallet via the Machine Payments Protocol (MPP). This approach avoids fragile browser automation by interacting directly with MPP-enabled APIs, ensuring the agent never accesses sensitive card credentials.

Architecture and Payment Flow

Restock integrates four key components to manage the transaction lifecycle:

  • Link: Stripe's consumer wallet that holds payment methods and requires user approval for each transaction.
  • MPP: The protocol defining the payment exchange, where merchants respond with a 402 Payment Required status and payment instructions.
  • Zinc: A vertical aggregator for retail that searches products and places retailer orders through its MPP order API.
  • Managed Deep Agents: The hosting platform that manages Slack integration, human review interrupts, credentials, and state.

The agent operates within a strict budget ceiling set by the user. For example, if a user sets a $25 limit, the agent requests an upfront amount (e.g., $23) that covers the item, tax, and shipping. Zinc processes the payment, pays the retailer, and refunds any excess to the user's wallet. The model itself never handles the payment token; it is stored in a private sandbox file and deleted after use.

Security and User Control

Security is enforced through multiple layers of isolation and approval. The Link session resides in a user-owned MDA Connection, ensuring each person's wallet remains separate. Credentials like the Zinc API key and delivery address are stored in agent-owned Connections, inaccessible to the model's context window.

Before any money moves, the user must approve the purchase in Slack and then authorize the payment in Link. The agent cannot bypass these steps; the run pauses via an interrupt until explicit approval is received. This design ensures that the agent can only spend within the pre-approved limits and that the final order details match what the user reviewed.

Availability and Modes

Restock is available as sample code on GitHub, supporting three operational modes for developers:

  1. Rehearsal: Uses fictional products and simulated approvals for testing logic.
  2. Link test approval: Connects to real Zinc search and Link wallets but does not execute purchases.
  3. Live purchase: Executes real payments and retailer orders.

Currently, Restock supports US delivery and USD transactions only, with a single office per deployment. The project serves as a sample implementation for building agents that spend money, emphasizing the importance of keeping spending limits and approvals outside the model's direct control.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.