LangChain opened Stripe Link agent payments to developers on October 8, 2026. The launch is a worked example, not a new product: a Slack agent called Restock that finds office supplies, prepares a cart and pays for the order, while a person approves every order.
Most agent demos stop at "found the product." Paying is the hard part. It moves real money, it needs credentials the model must never see, and it is hard to undo. LangChain's post shows one way to build the payment step so the model can request a payment but cannot approve one. The same pattern applies to any agent that spends money.
What did LangChain and Stripe actually release?
LangChain published "Agents that can pay: building Restock with Stripe's Link and Managed Deep Agents" on October 8, 2026. The authors are Srimanth Tangedipalli, Sydney Runkle and Nathan Drezner. On X, LangChain summarized it this way: build an agent that finds real products, prepares purchases and pays, with a person approving every order. You ask in Slack, review the order, and approve in Stripe's Link agent wallet. It is built on MPP and Managed Deep Agents.
Stripe's Jeff Weinstein wrote on X that LangChain developers can now build agents that pay with Link, which he said works across any checkout online and across programmatic payments over MPP. LangChain's Sydney Runkle added that agents such as Muse and Instinct popularized payments for personal agents, and that Managed Deep Agents (MDA) makes this easy for enterprise.
| Item | Detail |
|---|---|
| Date | October 8, 2026 |
| What shipped | Restock sample agent, code in langchain-samples/restock-agent, and a build guide |
| Runtime | Managed Deep Agents (LangSmith), with Slack as the interface |
| Wallet | Stripe Link, with a person approving each spend request |
| Payment rail | Machine Payments Protocol (MPP) over HTTP |
| Merchant API in the sample | Zinc (retail product search and order API) |
| Status | Sample code. US delivery and USD only |
The coverage trail matters, so here is what is and is not claimed. The Brainbase team announced a similar Stripe integration for its own agents on October 6, per its X post. LangChain's version is aimed at developers who build their own agents.
How does the Restock flow work, step by step?
The post follows one request from the first message to the confirmed order. The request is: "We're running low on pens. Can you find a 12-pack of blue ink pens for the office, under $25 altogether?"

LangChain splits the system into four pieces:
- Link holds the user's payment methods and asks the user to approve payments.
- MPP defines the payment exchange over HTTP. The merchant answers with
402 Payment Requiredand payment instructions. The client retries with a payment credential. - Zinc searches products and places retailer orders through its MPP order API.
- Managed Deep Agents hosts the agent and handles Slack, human review, credentials and saved state.
The flow then runs in six stages.
Stage 1: search and cart
Restock uses custom tools for Zinc search, the cart and payment, plus an instructions.md file that shapes the conversation. The agent definition lists six tools: product search, prepare_restock_order (save the cart), set_restock_payment_amount, request_restock_payment, wait_for_restock_approval and check_restock_order. In the sample code the model is read from an environment variable, and the default shown in the post is gpt-5.6-sol. Search is paid from a funded Zinc search account, not through Link.
Stage 2: set the upfront amount
Restock treats the $25 budget as a ceiling, not as the charge. Tax and shipping are not known from a product listing, so the total only settles once the retailer order is placed. The user picks an upfront amount, up to $25. Zinc takes that amount when the order goes in, pays the retailer out of it and refunds the rest. For the pens, the user picks $23. Zinc keeps a $1 base fee, which leaves a $22 retailer allowance for the item, tax and shipping. Before the review, Restock requests the order without payment and reads the real fees from Zinc's 402 challenge.
Stage 3: Slack review
Before anything is paid, the user reviews the cart, office label, fees and upfront amount in Slack. The delivery address stays private. The run pauses on an interrupt until the user clicks Approve or Reject.
Stage 4: Link approval
Restock then posts a Link approval link in the Slack thread for exactly the amount in Zinc's challenge, here $23. The user approves it on the Link website. LangChain describes this as the wallet's own consent to pay.
Stage 5: the paid request
After Link approves, Restock sends the paid request to Zinc. A Link shared payment token is the credential, and Zinc processes the payment through Stripe. The pympp library handles the MPP formatting.
Stage 6: confirmation
In the worked example, the retailer order comes to $21.18: $14.99 for the pens, $1.20 tax and $4.99 shipping. That is inside the $22 allowance. The user pays $22.18 including Zinc's fee, and Zinc refunds the other $0.82. Restock confirms in Slack once Zinc reports order_placed, and shares tracking when the retailer ships. LangChain says the prices are illustrative, and that it ran Restock end to end on a hosted deployment, where a live order reached order_placed and the expected refund arrived.
How does Restock keep credentials away from the model?
This is the part to copy first. LangChain lists the following controls.

| Risk | Control in Restock |
|---|---|
| Model sees card data | Link holds payment methods. The agent never sees a card number. |
| Shared wallet session | The Link session lives in a user-owned MDA Connection, so each person's wallet stays theirs. |
| Leaked service keys | Delivery address, notification email and Zinc API key sit in agent-owned Connections. |
| Session at rest | The Link CLI runs the login inside MDA's managed sandbox. A helper keeps the saved session in the user's Connection and places it in the sandbox only while a command runs. |
| Token reuse | The payment tool reads the Link token from a private sandbox file, deletes it after use and returns only a public summary to the model. |
| Model approves itself | An interrupt pauses the run. Nothing the model writes into a tool call can approve the review. |
| Wrong cart paid | The token does not enforce cart details, so the payment tool checks the order against what the user reviewed and confirms the approval is still fresh. |
| False "done" | An order counts as placed only when the merchant says so (order_placed). |
Connecting Link does not approve a purchase, and later conversations reuse the session. The user also approves a spend request up to a set amount, and the agent cannot spend above it.
LangChain's own summary of the pattern is short: let the agent search and build the cart, keep the spending limit and the approvals in code the model cannot touch, and count an order as placed only when the merchant says so.
Why use MPP instead of a browser checkout?
LangChain names the tradeoff directly. An agent can pay by driving the retailer's checkout in a browser, but that is fragile. Pages change, sites block automated checkouts, and payment details must be entered without exposing them to the model.
An MPP API avoids that. It tells the agent exactly what to pay and accepts the payment directly. The cost is coverage: the agent can only buy through MPP-enabled APIs. LangChain says the list is growing, with aggregators such as Apify and Mercator joining vertical providers such as Zinc for retail. Restock uses Zinc, but the pattern does not depend on it.
| Approach | Strength | Weakness |
|---|---|---|
| Browser checkout by the agent | Works on any site that lets it in | Fragile pages, bot blocking, hard to hide card entry from the model |
| MPP API with a Link token | Exact amount, direct payment, no card entry | Only merchants with an MPP API |
| Human buys, agent only recommends | Safest | No automation of the last step |
For background on the rails, read our guide to Stripe's directory of agent-commerce and MPP services and the August launch coverage of Stripe Link for agents and Grok shopping. Other rails are growing in parallel: Solana payment channels for agents and Cloudflare wallets for agent payments.
How do I try Restock?
The code is at langchain-samples/restock-agent, and the README walks through setup and deployment. You set RESTOCK_MODE to one of three modes. LangChain suggests trying them in order.

| Mode | What it does | What you need |
|---|---|---|
rehearsal | Fictional products and a simulated approval | OpenAI API key, a LangSmith workspace with Managed Deep Agents access |
link-test | Real Zinc search and a real Link approval, no purchase | Adds a Link wallet, a Zinc API key, a funded Zinc search account and delivery details |
live | A real payment and a real retailer order | Everything above, and real money |
You also need the Slack app connected. LangChain points to the Managed Deep Agents Slack setup guide for that step. If you already run MDA agents, our earlier posts cover user memory in Managed Deep Agents 0.8 and schedules and cron in Managed Deep Agents. The first explains the per-user memory model that makes user-owned wallets natural. The second matters if you want a recurring restock job. LangChain's related-content list on the same page also shows a Managed Deep Agents v0.9 post from October 7 on schedules, per-run configuration and Slack reactions.
What should you copy into your own agent?
Even if you never buy pens, the design transfers. Use this checklist.
- Put the limit in code. The $25 ceiling lives in tool logic, not in the prompt.
- Separate "prepare" from "pay." The model saves a cart. A different tool requests payment. Nothing pays without the interrupt.
- Ask for approval twice when money moves. One approval reviews the cart. One approval authorizes the exact amount in the wallet.
- Bind approval to the amount. The Link request is for exactly the amount in the merchant's challenge.
- Treat a token as single use. Read it from a private file, delete it, return a summary.
- Recheck before paying. Compare the final order to what the person reviewed, and check the approval is still fresh.
- Trust the merchant, not the model, for "done." Only
order_placedcounts.
These ideas also answer a worry that shows up in our own coverage of agent shopping. Research on agents that recommend pricier options to wealthy users is a reminder that a payment-capable agent needs spend limits, not just good intentions.
Limits and open questions
- It is a sample. LangChain says Restock supports US delivery and USD only, one office per deployment, and payment from the requester's own wallet.
- Coverage depends on MPP. If a merchant has no MPP API, this route does not apply.
- Setup is real work. You need a LangSmith workspace with Managed Deep Agents access, a Zinc key, a funded search account and a Link wallet.
- The tool list is small by design. Six tools cover search, cart, amount, approval request, wait and status. A production buyer would add returns, disputes and multi-user budgets.
- Prices are illustrative. Do not treat the pens example as a price quote.
- Model choice is yours. The sample reads the model name from an environment variable.
- We have not run it. This post describes the LangChain post and the Stripe and LangChain X posts. explainx.ai has not run Restock in live mode.
Bottom line
LangChain and Stripe did not just say agents can pay. They showed a design where the model can ask for money but cannot release it. A Slack review, a Link approval tied to an exact amount, single-use tokens and a merchant-confirmed order status give a concrete pattern to copy. Start in rehearsal mode, move to link-test, and go live only after you have read the payment tool's checks.
Related reading
- Agentic commerce goes live: Stripe Link for agents and Grok shopping
- Stripe directory for agent commerce and machine payments
- Shopify and Meta agentic Shop Pay checkout
- Managed Deep Agents 0.8 user memory
- Managed Deep Agents schedules and cron
- What is an agent harness?
- What is MCP?
Sources
- LangChain: Agents that can pay, building Restock with Stripe's Link and Managed Deep Agents (October 8, 2026)
- LangChain on X, Jeff Weinstein on X, Sydney Runkle on X
- Brainbase on X (October 6, 2026)
- HuggingNews summary
Details are accurate as of October 9, 2026, and come from LangChain's published post and public X posts. Code, modes and limits can change. Check the restock-agent README before you deploy.
