AI Commerce Payments: How to Secure Purchases Made by AI Agents
How AI agent purchases are paid and secured: delegated credentials, mandates, limits, fraud and disputes, and why agent and payment authorization differ.
Quick answer
When an AI agent buys something, three separate questions must each have a clear answer. Is this agent allowed to act for this person? (agent authorization). Did the person approve this purchase, or the rules it falls under? (purchase consent). May this amount be charged to this payment instrument? (payment authorization). Mixing them up is the main source of risk.
Current approaches use scoped credentials instead of raw card numbers: delegated or shared payment tokens limited by amount, merchant and expiry, network-issued agentic tokens, wallet credentials and signed mandates that record what the user authorized. The merchant remains merchant of record and handles fraud screening, refunds and disputes through its payment provider. No single payment protocol is universal yet, so build for more than one.
Agent authorization vs payment authorization
| Agent authorization | Payment authorization | |
|---|---|---|
| Question | What may this agent do for this user? | May this amount be charged to this instrument? |
| Granted by | User, via account linking or platform consent | User approval, mandate or rules, plus issuer decision |
| Mechanism | OAuth-style scopes, identity linking | Payment tokens, mandates, card authentication, issuer authorization |
| Checked by | Merchant API and agent platform | Payment provider, network and issuer |
| Example | Agent may create checkouts and view orders | Charge up to EUR 150 to this card for this checkout, today |
Key takeaway
An agent that is allowed to shop is not automatically allowed to spend. Keep spending limits in the payment credential or mandate, not only in the agent's instructions.
How agent payments work today
Delegated payment tokens. In the Agentic Commerce Protocol, the agent platform asks the merchant's payment provider for a one-time token restricted by a maximum amount and expiry, then passes it to the merchant to complete checkout. OpenAI's Delegated Payment Spec describes this, and Stripe's Shared Payment Token was the first compatible implementation (OpenAI Delegated Payment Spec).
Payment handlers. UCP lets a business declare payment handlers in its profile (for example a wallet or a processor tokenizer) and lets the platform choose one, so different credential types can be supported without changing checkout logic. Mandates. AP2 (Agent Payments Protocol), published by Google with standardization continuing in FIDO Alliance working groups, uses signed verifiable digital credentials: a checkout mandate and a payment mandate, each with an open form (constraints for autonomous execution) and a closed form (authorization for a specific checkout or amount) (AP2). UCP includes an AP2 mandates extension. Network agentic tokens. Card networks have introduced agent-specific programs, such as Mastercard Agent Pay's agentic tokens and Visa's Trusted Agent Protocol for identifying agents to merchants. Check each provider's current documentation; these programs are evolving.
Shopper ──consent / limits──▶ Agent platform
│ (agent authorization: scopes)
▼
request scoped credential
(delegated token · wallet · agentic token · mandate)
│ max amount · merchant ·
│ checkout · expiry
▼
Merchant checkout ◀── complete(session, credential, idem-key)
│ verify platform signature · totals ≤ limit
│ fraud screening (agent channel signals)
▼
Payment provider ──▶ network ──▶ issuer (payment authorization,
│ SCA if required)
▼
Order created · receipt · refunds/disputes via merchant + PSPTransaction limits
Limits belong in several layers: the credential itself (maximum amount, single use, expiry, merchant and checkout binding), the agent platform's policy (per-transaction and per-period caps set by the user), and the merchant's risk rules (order value thresholds that trigger review). Mandate-based approaches let a user pre-authorize constrained autonomous purchases ('reorder printer paper under EUR 40 monthly'), but the constraints must be explicit and verifiable, not inferred from conversation.
Authentication
Strong customer authentication rules still apply where they apply. Agent flows have to support step-up authentication: when the issuer or regulation requires it, the checkout returns an authentication-required state and the shopper completes the challenge, in the agent interface or on the merchant's site. ACP includes an authentication_required checkout status; UCP describes tokenization with a challenge as one payment-handler scenario. Design for the challenge path, not just the frictionless one.
Fraud controls and merchant verification
Agent purchases change fraud signals: device and behavioural data from the shopper's browser are missing, and orders arrive from a small number of platforms. Do not block the channel; adjust the model. Verify the agent platform (signed requests, published keys, network agent identification), bind credentials to the checkout, check that delivery details match the account where identity is linked, and route unusual orders to review. Verification runs both ways: agent platforms and networks also verify that merchants are legitimate before passing credentials. See orders placed by AI agents and ecommerce fraud detection.
Refunds and disputes
The merchant remains merchant of record, so refunds go back through the original payment provider and instrument, and disputes follow card network rules. What changes is evidence. Keep the checkout session, the totals the shopper confirmed, the agent platform identity, the credential's constraints and any mandate with the order. That record helps distinguish 'I did not authorize this' from 'the agent bought the wrong item', which are different problems with different remedies. Our guide to chargeback management covers the dispute process.
Do not bet on one protocol
Delegated tokens, payment handlers, mandates and network tokens solve overlapping problems and come from different ecosystems. Which ones you need depends on the agent channels you sell through and your payment provider. Abstract payment completion behind your checkout API, rely on your PSP for credential handling and PCI scope, and add protocols as channels demand them. The baseline controls in ecommerce payment security still apply.
Checklist
- Separate agent scopes, purchase consent and payment authorization in design and logs
- Accept only scoped credentials (amount, merchant, checkout, expiry); never raw card data from agents
- Verify platform identity and request signatures
- Re-check totals against the credential limit before charging
- Support step-up authentication paths
- Tune fraud rules for agent channels; review rather than block
- Store checkout, confirmation, credential constraints and mandates with each order
- Handle refunds and disputes through normal PSP processes with agent evidence
Adding agent payments to your checkout?
ZSpace Labs integrates payment providers, tokenized payments and checkout APIs for Shopify and custom stores. See Shopify development.
Conclusion
Securing agent purchases is mostly about keeping three authorizations distinct and enforced: what the agent may do, what the shopper approved and what the payment system allows. Use scoped credentials and verifiable records, keep the merchant's checkout and payment provider in control, adapt fraud controls and preserve evidence for refunds and disputes. For the checkout mechanics, see agentic checkout.
Common questions.
Usually with a scoped payment credential rather than raw card details: a delegated or shared payment token limited by amount, merchant, checkout and expiry, a network agentic token, or a wallet credential. The merchant's payment provider processes it like any other payment.