Issuance and redemption — the coin is a redeemable liability
A fiat-backed stablecoin is not a currency; it is a liability of its issuer, redeemable for the reference asset. The primary market works in two directions. To mint, a vetted counterparty wires fiat to the issuer, the issuer records the deposit and mints an equivalent quantity of tokens to an address on a chain. To redeem, tokens are sent back and burned, and the issuer wires fiat out. Most participants never touch this path — they buy and sell on secondary venues, where the price is whatever the order book says.
That two-tier structure is what actually holds the peg. When the secondary price drifts below par, redeeming at par is profitable, so tokens are pulled out of circulation until the gap closes; above par, minting is profitable. The arbitrage only works if redemption is genuinely available at par, promptly, at scale. Every peg failure is, at bottom, a failure of that assumption.
Reserves — composition is the peg
If redemption is the mechanism, the reserve is the fuel. What backs the tokens determines whether redemption can be honoured on the day everyone asks at once. Reserve assets sit on a spectrum: bank deposits and overnight government repo at one end, short-dated treasury bills next, then longer duration, commercial paper, corporate credit, and other tokens at the far end. Each step away from cash adds one of three risks — duration (the asset must be sold at a loss if rates moved), credit (the issuer of the asset may not pay), and liquidity (there may be no buyer at the price you modelled).
Distinguish an attestation from an audit. An attestation reports that holdings matched a stated figure at a point in time; an audit is a broader opinion on financial statements. Point-in-time attestations say little about the days between them. Treat reserve disclosure as an input to a credit assessment you perform, not a guarantee you inherit.
Custody — who actually controls the agent’s balance
On-chain, control is the private key. Whoever holds it can move the funds; nothing else matters. So the custody question for an agent payment system is blunt: which process, on which machine, can produce a valid signature?
Three broad models. Self-custody means your infrastructure holds keys — maximum control, and the entire operational burden of key generation, backup, and rotation. Third-party custody moves keys to a specialist and converts a cryptographic problem into a counterparty and contractual one. Omnibus arrangements hold many customers' balances in shared addresses with entitlements tracked on the custodian's internal ledger — simple to operate, but your claim is a book entry, not an on-chain position. Whichever you pick, agents should never hold raw keys. Make each agent an authenticated client of a signing service that enforces policy, and split hot operating balances from cold reserves so a compromised agent bounds the loss.
Finality and the missing chargeback
A confirmed transfer cannot be pulled back. There is no acquirer to file against, no issuer to arbitrate, no representment cycle. This is the single most consequential difference from card rails, and it inverts where controls live.
Finality itself is not binary. Proof-of-work style chains offer probabilistic finality that strengthens with confirmation depth; chains with explicit finality gadgets mark a block irreversible after a defined process; layer-2 networks often give a fast soft confirmation that only becomes hard once state is settled to the layer below. Pick a confirmation policy per chain and per value band, and be honest that a low-latency soft confirmation is a risk decision, not a fact.
The consequence for AP2 is that every meaningful control must run before the signature. A refund is not a reversal — it is a fresh payment back, which requires the counterparty's cooperation and cannot be compelled.
Pre-transaction controls — where the mandate binds
Because after is too late, the mandate has to do its work before. An AP2 cart mandate expresses a signed, verifiable statement of what the user authorized; on a stablecoin rail that statement has to bind to the specific things that make a transfer unique — the amount and token, the destination address, the chain, and an expiry. A mandate that authorizes 'pay the merchant' without pinning chain and address authorizes far more than the user meant.
The signing service is the choke point, and it should refuse rather than warn. Practical gates: check the mandate signature and expiry; confirm the destination is on an allowlist or has passed screening; enforce per-transaction, daily, and cumulative velocity caps; simulate the transaction and reject on unexpected state changes; and require human approval above a threshold. Each of these is cheap before broadcast and impossible after.
Gas, fees, and who pays them
The asset you send and the asset that pays for sending it are not the same thing. Transfers consume a chain's native gas token, priced by demand for block space, so a payment can fail for lack of gas while the balance being paid is untouched. That is a real operational trap for autonomous agents: an address funded entirely with stablecoin cannot spend a cent of it.
Mitigations exist. Account-abstraction style designs let a paymaster sponsor gas on the user's behalf, and some tokens support delegated transfers where a relayer submits the transaction and is compensated in the token itself. Both move the cost rather than removing it, so decide explicitly whether payer, merchant, or platform bears it. Two more details bite: a reverted transaction still consumes gas, and per-address ordering means one stuck transaction can block every later payment from that address until it is replaced.
Depeg — the failure mode to design for
A depeg is a divergence between the secondary market price of a token and its reference unit. It can be triggered by doubt about reserve quality, by loss of banking access on the redemption path, by a liquidity squeeze in the venues where the token trades, or simply by redemption being gated or slowed. Historically these episodes have ranged from brief and shallow to permanent, and the difference has tracked reserve quality and redemption access rather than sentiment.
What matters is how a payment system behaves during one. Price the obligation in the unit of account, not in tokens, so a discount is visible instead of silently shifted onto the merchant. Attach a validity window to quotes. Define a tolerance band with an automatic response — widen spreads, cap exposure, then suspend the rail — so the decision is pre-agreed rather than improvised. And keep a second rail configured, because a suspended rail with no alternative is an outage.