Google and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent proves a user actually authorized a specific purchase, since the old assumption that a human is present at checkout no longer holds.
FIDO Alliance CTO Nishant Kaushik detailed, on May 26, 2026, how Google's Agent Payments Protocol (AP2) and Mastercard's Verifiable Intent framework, both contributed to the Alliance for standardization, address a problem regular payment authentication never had to solve: proving a human authorized a specific transaction when an AI agent, not the human, is the one at checkout. AP2 defines Checkout and Payment "mandates," verifiable digital credentials that capture exactly what a user authorized an agent to do and move between open and closed states as a transaction progresses. Verifiable Intent complements it by turning that authorization into portable, cryptographically verifiable evidence that an issuer, network, or merchant can validate independently, without depending on any one party's proprietary system. Identity binding, linking the mandate to a cryptographic key anchored in device-based authentication, plus selective disclosure to limit what each party sees, are both built into the design.
Why it matters
"The user was present at checkout" has been an unstated assumption behind most payment fraud controls, and it stops being true the moment an agent can place the order on a user's behalf. A mandate that's cryptographically bound to the user's device and scoped to a specific authorization is the direct fix: instead of trusting that the agent behaved correctly, every party in the chain can independently verify what was actually authorized.
This is the payments-specific version of the same problem covered in securing AI agent identities: an agent acting on a person's behalf needs credentials that are scoped, delegated, and independently verifiable, not standing access that assumes good behavior.
Source: FIDO Alliance
Related on Start with Identity
- BlogMCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension le
- BlogDiscovering AI agents isn't security. Enforcing what they can do is.
A survey of AI agent security practice argues visibility without enforcement creates false confidence, and that the real question isn't which agents exist but w
- BlogOkta ships Agent SSO, making AI agents first-class identities instead of static API keys
Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App
- TechniqueAgent instruction injection
An AI coding agent reads whatever text is in front of it, an issue, a title, a comment, and treats it as instruction. If that runner also holds workflow secrets
- RankingBest AI Agent Identity Tools: Top 5 for Autonomous Access
The best AI agent identity tools in 2026: Aembit, SlashID, P0 Security, Corsha, and Astrix Security. Ranked for secretless workload access, delegation, and agen
- RankingBest Zero Trust Tools: Top 5 ZTNA and SSE Platforms
The top 5 Zero Trust tools (Cloudflare, Zscaler, Tailscale, Palo Alto Prisma Access, Netskope), scored on a 10-dimension rubric.