Skip to main content

For payment providers

Accept agent payments with proof of approval.

Your merchants will start to receive orders from AI agents. Check that a human approved each one, before your normal authorisation runs.

Agent presents Deluxe 10-Piece Set ยท EUR 149.00

  • Issued on human approval issuer signature
  • This order, this shop: not the order the human approved offer_digest_mismatch
  • Still valid time window
  • From the right agent key binding
  • EUR 149.00 is over the EUR 50.00 limit over_limit
Refused over the EUR 50.00 limit
Refused before authorisation shop.example

01 / What the check confirms

Four checks, run before the charge.

The verifier reads the mandate and a published key set. Then your own rule compares the charge with the largest amount the human approved.

  1. Issued on human approval

    The mandate carries a valid OID4Pay signature, made when a human approved the payment.

    Refused when the signature is missing or not valid. invalid_mandate_signature

  2. This order, this shop

    The mandate names one shop and one order. The order at checkout must be that order.

    Refused for another shop or another order. audience_mismatch, offer_digest_mismatch

  3. Still valid

    A mandate lasts 24 hours or less, and the human sees that time when approving.

    Refused after it expires. invalid_mandate_claims

  4. From the right agent

    The mandate is bound to the key of one agent. The agent proves that it holds the key.

    Refused when another agent presents it. kb_jwt_jkt_mismatch

02 / Where it runs

On your platform, before your authorisation.

Verifier SDKs for Node, Python and Go, under the MIT licence. They make no payment call and hold no funds.

  1. Agent carries the mandate
  2. Merchant checkout receives the order
  3. OID4Pay verifier on your platform Checked here
  4. Your authorisation runs as it does today
The verifier only reads. It cannot charge, refund or move money.

03 / Evidence trail

Four signed records for every payment.

When a human says they did not buy something, logs are not enough. A signed trail shows what was offered, what was approved, who presented it and what was accepted.

  1. Merchant

    Signed offer

    The merchant signs the offer: what is for sale, and at what price.

  2. OID4Pay

    Signed mandate

    OID4Pay signs the mandate when the human approves it.

  3. Agent

    Proof of the key

    The agent proves that it holds the key the mandate is bound to.

  4. Merchant

    Signed receipt

    The merchant signs the receipt for the payment it accepted.

04 / Standards

Built on open standards.

OAuth 2.0 and SD-JWT verifiable credentials today. We are adding AP2 mandate verification, shaped with design partners.

A quiet canal-side street in Amsterdam in early morning light

05 / Pilot

We are choosing our first design partners.

We would like to run the verifier beside one of your merchant checkouts, in test mode. Then we learn what your team needs from it.

What we do together
Run the verifier beside one merchant checkout, in test mode, for about 6 to 8 weeks.
What you get
The verifier SDKs, support from the people who wrote them, and a say in how AP2 mandates are verified.
What we need
One engineer and one product owner, about an hour each per week.

Status: developer preview. Test mode only. No real money moves and no merchant is live yet.

A flower stall vendor hands a bouquet of tulips to a customer in an Amsterdam street

06 / Questions

What payment providers ask first.

Does OID4Pay move money?

During the developer preview, no real money moves. The verifier itself only reads the mandate and checks it. It cannot charge, refund or move money.

Do we have to change our processing?

No. The check runs before your normal authorisation. Your authorisation flow and your scheme rules stay as they are.

Does the verifier call OID4Pay for every payment?

No. It checks the signature on your own platform against OID4Pay's published public keys. It fetches and caches them, or you can load them yourself.

Which standards does it use?

OAuth 2.0, SD-JWT verifiable credentials, HTTP message signatures and DPoP. We are adding AP2 mandate verification, shaped with design partners.

What does it cost?

During the developer preview we agree pilot terms directly.

Can we see the code?

The verifier SDKs for Node, Python and Go are open source under the MIT licence. You can read them and run the example first.