Swiggy has added Swiggy Money to its Model Context Protocol (MCP) integrations, allowing AI agents to complete payments for orders across Swiggy Food, Instamart and Dineout. The update, announced by Swiggy’s head of agentic commerce on X, lets users add money to Swiggy Money once and then allow an agent to use that balance during subsequent transactions, removing the need to interrupt the conversational flow at the payment stage. MediaNama tested the new functionality on ChatGPT, using Swiggy’s Food MCP to place an actual order. 

Ordering works, but there is still friction: In our test, we asked ChatGPT to select a chocolate dessert within a budget of Rs 300 using the account’s order history and pay using Swiggy Money. However, it was not able to retrieve the order history. After we specified that we wanted to order cookies, it successfully searched for a chocolate cookie, selected a product, added it to the cart, and ultimately placed and paid for the order using Swiggy Money. The process was substantially smoother than the payment-limited experience we tested in January, which allowed only cash on delivery

However, it was not entirely seamless. First, ChatGPT needed the user to select a delivery address rather than autonomously deciding which saved address to use. It also could not use the user’s order history to personalise the recommendation, despite Swiggy exposing account-level ordering functionality. More significantly, after the payment was completed, ChatGPT initially returned an error indicating that the order had not been paid, even though the order had been completed and confirmed.

What we found when Swiggy first integrated MCP with ChatGPT: When Swiggy launched its MCP integration in January, MediaNama found that the underlying capabilities were real but unevenly implemented. We manually connected Swiggy’s Food, Instamart, and Dineout MCP servers to ChatGPT. We found that the AI could access saved addresses, search for restaurants, interpret natural-language requests, and attempt to build carts. However, execution remained inconsistent.

 In Food, ChatGPT could discover restaurants but frequently failed to retrieve menus, including at large outlets such as Third Wave Coffee and Starbucks, preventing orders from progressing. Payments were also limited to cash on delivery, making the transactional layer deliberately constrained. Instamart could understand shopping requests but could not complete checkout, while Dineout could search availability but initially failed to complete reservations before succeeding in a later test.

Overall, the January test showed that Swiggy had exposed the infrastructure, but reliability and transaction completion remained the key gaps. The new Swiggy Money functionality addresses one of those gaps directly: payment. However, our latest test suggests that making an agent truly autonomous will require more than adding a stored balance. The remaining challenge is getting the agent to reliably carry context from discovery through fulfilment without repeatedly asking the user to intervene.

Why does this matter? Swiggy’s move matters because payment is where an AI assistant stops being a recommendation engine and starts becoming an agent. In July, MediaNama founder Nikhil Pahwa’s shopping experiment with an AI agent showed why that distinction matters: the agent could search for products, but price ambiguity, login failures, address selection, unstable sessions, and lost transaction state repeatedly forced human intervention. As Nikhil Pahwa pointed out, “an autonomous purchase for which I’d have to block out time isn’t an autonomous purchase.”

Swiggy Money removes one major interruption by giving the agent a pre-funded payment rail. However, it also raises the stakes. Once agents can spend money without a payment handoff, clear spending limits, transaction state, confirmation, and liability become essential, not optional safeguards. Friction in agentic commerce is not inherently negative; it can serve as a safety mechanism. The goal should therefore be to remove unnecessary friction without removing the boundaries that protect users.

Also read: