Start with Identity
← Blog
News

Google and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate

Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent proves a user actually authorized a specific purchase, since the old assumption that a human is present at checkout no longer holds.

By SWI Community TeamMay 26, 2026Updated Aug 6, 2026

FIDO Alliance CTO Nishant Kaushik detailed, on May 26, 2026, how Google's Agent Payments Protocol (AP2) and Mastercard's Verifiable Intent framework, both contributed to the Alliance for standardization, address a problem regular payment authentication never had to solve: proving a human authorized a specific transaction when an AI agent, not the human, is the one at checkout. AP2 defines Checkout and Payment "mandates," verifiable digital credentials that capture exactly what a user authorized an agent to do and move between open and closed states as a transaction progresses. Verifiable Intent complements it by turning that authorization into portable, cryptographically verifiable evidence that an issuer, network, or merchant can validate independently, without depending on any one party's proprietary system. Identity binding, linking the mandate to a cryptographic key anchored in device-based authentication, plus selective disclosure to limit what each party sees, are both built into the design.

Why it matters

"The user was present at checkout" has been an unstated assumption behind most payment fraud controls, and it stops being true the moment an agent can place the order on a user's behalf. A mandate that's cryptographically bound to the user's device and scoped to a specific authorization is the direct fix: instead of trusting that the agent behaved correctly, every party in the chain can independently verify what was actually authorized.

This is the payments-specific version of the same problem covered in securing AI agent identities: an agent acting on a person's behalf needs credentials that are scoped, delegated, and independently verifiable, not standing access that assumes good behavior.

Source: FIDO Alliance

Independent analysis. No vendor sponsorship.