Skip to content
Agentic commerce · AI agent payments

Let agents pay.
Keep humans in charge.

Agentic payments infrastructure for issuers, neobanks and fintechs: every AI agent gets its own virtual card under a signed, revocable mandate, with merchant locks, budgets and expiry enforced on the authorization path. Built alongside Visa Intelligent Commerce and Mastercard Agent Pay, and ready for AP2-style mandates and MCP-driven agents.
mandate · mnd_4c9asigned · active
principal
ch_8k2m · Acme Ltd
agent
agent_procure_01
merchant_allow
aws · vercel · openai
merchant_lock
first_use
per_transaction_max
€500.00
total_budget
€4,000.00
not_after
2026-10-31T23:59Z
signature
JWS · kms:rigid/mandates
POST /v1/mandates/mnd_4c9a/cards → card_7q2eagent credential
agent_procure_01 · this month3 approved · 1 stopped
aws · eu-central-1budget 3,687.60 left€312.40approved
vercel · pro seatmerchant locked on first use€20.00approved
openai · api credit3 of 3 merchants in use€150.00approved
figma · team planmerchant_not_allowed · trace 9f31€45.00declined
budget used€482.40 / €4,000.00
US agentic commerce by 2030 (McKinsey)
$1T
US agentic commerce by 2030 (McKinsey)
of consumers already comfortable with agents buying for them (Salesforce)
24%
of consumers already comfortable with agents buying for them (Salesforce)
European issuers running live agent transactions (Visa, Jul 2026)
30+
European issuers running live agent transactions (Visa, Jul 2026)
AGENT · MANDATE · CARD

Three objects. One line an agent cannot cross.

Every public demo shows an agent succeeding. Nobody shows the agent being stopped. An issuer's job is the second one, so that is what we built.

01

Agent

A first-class subject with its own API credential, scoped to a programme. Not a cardholder, never a KYC subject, never holding money. One agent can serve many principals; one principal can run many agents.

02

Mandate

The signed, immutable, revocable authority: principal × agent × constraints. Merchant allow-list, lock-on-first-use, MCC and country rules, per-transaction cap, total budget, validity window. Its grammar mirrors Google's AP2 payment mandate, so the adapters are field mappings.

03

Card

The agent mints its own virtual card under the mandate with one call, single-use or n-use. It cannot widen the envelope, and it never sees a PAN, only a card reference.

04

Decision

Every authorization is checked against the mandate on the hot path, inside the authorization budget. The budget is exact and fails closed. Every decline carries the reason and the mandate clause that produced it.

FOR THE PEOPLE BUILDING AGENTS

Two calls. Then the agent spends inside an envelope it cannot widen.

The principal, or their finance team, creates the mandate. The agent authenticates with its own credential, mints a card under the mandate and pays. The platform does the rest, at authorization time, in milliseconds.

mandate.httpREST
POST /v1/mandates
{
  "principal_id": "ch_8k2m",
  "agent_id": "agent_procure_01",
  "constraints": {
    "merchant_allow": ["aws", "vercel", "openai"],
    "merchant_lock": "first_use",
    "mcc_allow": ["5734", "7372"],
    "per_transaction_max": { "amount": "500.00", "currency": "EUR" },
    "total_budget": { "amount": "4000.00", "currency": "EUR" },
    "not_after": "2026-10-31T23:59:59Z",
    "max_authorizations": 40
  }
}
// 201 · signed (JWS) · revocable · enforced at authorization

POST /v1/mandates/mnd_4c9a/cards   // called by the agent itself
// 201 · card_7q2e · single_use · PAN never returned
CONTROLS

Scoped by the human, enforced by the issuer

Merchant allow-lists matched on acceptor ID, never on a name an agent could spoof. Lock on first use for the agents that don't know the merchant in advance.

BUDGETS

Budgets that cannot drift

Cumulative spend is derived from the authorization rows themselves, so a budget of €4,000 is €4,000, not approximately €4,000. Exceed it and the authorization fails closed.

EVIDENCE

Proof the payer authorised it

A token and a cryptogram are not proof of consent under UK PSRs 2017 reg 75. A signed mandate is. It is portable evidence any third party can verify, kept with the decision trace and the scheme's agentic indicator.

REVOCATION

One call to stop everything

Revoke a mandate, or disable an agent and every mandate it holds, atomically. Live usage per mandate through the API and the console.

SCHEMES

Ready for the network programmes

Built alongside Visa Intelligent Commerce, Mastercard Agent Pay and the EMVCo agentic framework: agent identity signals decoded and retained, passkey authentication for the principal, tokenization to wallets.

RISK

Fraud AI that knows an agent when it sees one

Agent traffic is tagged, so behavioural baselines don't misfire on a bot that buys at 3am from three merchants. Correlated-fraud signals across agents feed the same in-line score.

WHAT AGENTS BUY

From a procurement bot to a car paying for its own charge.

Procurement and SaaS agents

An agent that buys cloud capacity, API credit and tooling for a company, from a fixed list of vendors, inside a monthly budget. The finance team sets the mandate; the agent never asks for a card number.

Travel and booking agents

Flights and hotels bought under a per-trip mandate: MCC-limited, capped, expiring the day after return, with a single-use card per booking.

Personal shopping assistants

A consumer's assistant reorders household goods or grabs a deal inside a weekly allowance, with the merchant locked on first use and every purchase visible in the banking app.

Machine-to-machine spend

Vehicles paying for charging, devices buying data, workloads buying compute: programmatic principals, programmatic limits, and a ledger entry for each.

Each of these runs on a disposable virtual card: single-use or n-use, merchant-locked, time-boxed, minted at the moment of purchase and closed the moment it settles.

FAQ

Agentic payments, answered

What is agentic commerce?

Commerce where an AI agent selects, negotiates and pays on behalf of a person or a business. The payment still runs on card rails; what changes is that the credential is bound to an agent and the authority to spend is captured explicitly, in a mandate, rather than assumed from possession of a card.

How is this different from a normal virtual card with spend controls?

The controls are the same primitives. The difference is the mandate: a signed, immutable record of who authorised which agent to do what, that the agent cannot widen, that can be revoked in one call, and that survives as evidence when a purchase is questioned.

Does the agent get a card number?

No. The agent mints a card under its mandate and receives a card reference. The PAN stays inside the platform's PCI scope and is delivered to the payment surface through tokenization.

Can a human approve each purchase in real time?

Card authorization has a budget of a few hundred milliseconds, so the human sets the policy ahead of time and the platform enforces it at authorization. Anything outside the policy is declined with a reason the person can read, and the mandate can be widened for next time.

Which agent frameworks and protocols does it work with?

Any agent that can call a REST API. Mandate constraints follow the AP2 payment mandate grammar, and agents driven through MCP, OpenAI's Agentic Commerce Protocol or a custom runtime integrate the same way: authenticate as the agent, mint a card under a mandate, spend.

WHO BUILDS ON IT

Who Agentic commerce is for, and what they get.

The same platform, used differently by different teams. Each card names the segment, the outcome, and the products that carry it.

AI agent builders

Cards your agents can spend but never widen

Every agent gets its own virtual card under a signed, revocable mandate: merchant locks, budgets that fail closed, expiry, and a decision trace for every purchase the agent makes or is stopped from making.

Give your agents a card. Keep the keys.

Bring an agent and one thing it should never be allowed to buy. We show you the mandate that stops it, live, in the call.