🇫🇷 Cet article est aussi disponible en français.

Agentic Commerce Leaves the Sandbox: Verifiable Intent, Agent Pay and Europe's First Live Agent Payments

Agentic Commerce Leaves the Sandbox: Verifiable Intent, Agent Pay and Europe's First Live Agent Payments
🇫🇷 Cet article est aussi disponible en français.
📑 Table of Contents

TL;DR

  • Mastercard and Google open-sourced Verifiable Intent, a standards-based layer that produces a tamper-resistant record of what a user actually authorised when an agent buys on their behalf.
  • Alchemy wired Mastercard Agent Pay into AgentCard, letting developers provision an agent with an email, a phone number, a stablecoin wallet and one-time-use card credentials in under a minute.
  • Worldline and ING ran Europe’s first live end-to-end agentic payment in production on Mastercard rails, with French and Visa proof points following.
  • The remaining question is no longer technical feasibility but accountability: who is liable, and how a bank proves intent, when the buyer is not human.

For the past two years, agentic commerce has been a roadmap slide: a pie chart of discovery, cart and checkout, with an asterisk reading soon. In 2026 the asterisk came off. Payment networks, processors and acquirers stopped demoing agent checkout and started shipping the unglamorous half of it — authorisation, traceability and dispute logic — onto live infrastructure.

That shift matters more than any model release in the same window, because payment rails are where agent autonomy stops being a benchmark and starts carrying financial consequences. The interesting engineering is no longer “can an agent buy a thing” but “can an issuer prove, after the fact, exactly what a human agreed to”.

From pilots to production rails

Worldline, ING and Mastercard completed what the three companies describe as Europe’s first live end-to-end agentic payment in a production environment, announced at Money20/20 Europe. An ING cardholder looking online for a wedding anniversary gift had a merchant-side agent find concert tickets inside a defined budget, present a curated selection, and complete the purchase only after explicit consumer approval. The transaction ran between cardholder and merchant in the Netherlands, on the same infrastructure across Belgium, over the Mastercard network.

The architectural detail that made it a product rather than a demo is that ING kept authentication and authorisation, while Worldline processed the payment end-to-end across its issuing and acquiring platforms. Explicit network-level identifiers flagged the transaction as agentic, giving the issuing bank visibility over every step of the chain. (Source : Payments Industry Intelligence — ING, Worldline and Mastercard Deliver Agentic Payment Milestone)

The model then replicated. Worldline and ING ran a comparable live flow in Germany with Visa, where the consumer set the purchase conditions and confirmed intent biometrically through Visa Payment Passkey, retaining the option to complete the order up to 48 hours after authorisation. Worldline, Crédit Agricole and Mastercard completed the first agent payment in production in France on a festival-ticket scenario. Worldline’s scale is what makes this more than a pilot: the processor reported roughly €4 billion in revenue in 2025 across an enterprise client base exceeding 1.2 million merchants. (Source : Worldline — Agentic Commerce & Agent-Driven Payments in Europe)

Worth noting for anyone planning on this being frictionless: Worldline itself frames these as proof points, not broad commercial availability, and says general availability depends on continued alignment between merchants, banks, networks and regulators.

Verifiable Intent: making authorisation provable

The harder problem is not moving money, it is evidence. If an agent initiates a purchase, three parties need to agree on what was authorised: the consumer, the merchant and the issuer. Disputes on card rails have always rested on a human having clicked, tapped or signed. Agents remove the human from the moment of decision while keeping them legally responsible for it.

Mastercard’s answer, co-developed with Google, is Verifiable Intent — a trust layer that creates a tamper-resistant record of what a user authorised when an agent acted for them, providing cryptographic proof of authorisation that consumers, merchants and issuers can all rely on. It is aligned with Google’s Agent Payments Protocol (AP2) and Universal Commerce Protocol (UCP), deliberately protocol-agnostic, and built on specifications from the FIDO Alliance, EMVCo, the IETF and the W3C rather than on anything proprietary. Mastercard open-sourced both the specification and an initial reference implementation, and plans to integrate Verifiable Intent directly into Agent Pay’s intent APIs. (Source : Mastercard — How Verifiable Intent builds trust in agentic AI commerce)

The signalling here is strategic rather than technical. A payments network that wants to sit in the middle of agentic commerce has to be the party that defines what “authorised” means, and the cheapest way to win that position is to give the definition away. Google’s Stavan Parikh, VP and GM of Payments, framed the collaboration as trust infrastructure compatible with AP2 which “is a natural accelerator for scaling agentic commerce”. (Source : Mastercard — Verifiable Intent)

AgentCard: provisioning an agent in under a minute

Standards need a developer path, and that is where Alchemy’s AgentCard comes in. AgentCard exposes a single command-line interface through which a developer equips an agent with an email address, a phone number, a stablecoin wallet and one-time-use Mastercard payment credentials. Alchemy says an agent can be provisioned with all four in under a minute.

The design choices are the interesting part. The one-time-use credentials are tokenised and linked to a user’s existing Mastercard account, so rewards, credit lines and card benefits survive without a new account or credential being issued. Issuers and users can set spending limits, restrict merchant categories and define where an agent is allowed to transact, and the integration supports Verifiable Intent so that a transaction carries evidence the agent stayed inside those instructions. Consumers register an agent through AgentCard.ai; businesses can embed the identity, wallet and payment capabilities into their own products. (Source : The Paypers — Alchemy adds Mastercard Agent Pay to AgentCard)

Sherri Haymond, EVP of Digital Commercialization at Mastercard, positions Agent Pay as the framework bringing “trust, safeguards, and consumer control to agentic commerce as it moves from experimentation toward broader use”. (Source : The Paypers — Alchemy adds Mastercard Agent Pay to AgentCard)

The protocol race underneath the product news

If Verifiable Intent is the trust layer, the surface it sits on is still contested. Mastercard joined Google on the Universal Commerce Protocol while continuing to work across Google’s AP2 and Agent2Agent protocols and OpenAI’s Agentic Commerce Protocol, and is working with Microsoft to bring Agent Pay to Copilot Checkout, alongside OpenAI, Cloudflare and PayPal. It is also expanding Start Path, its startup programme, toward agentic payments — a distribution play layered on top of a standards play. (Source : Mastercard — Building trust in AI commerce: Mastercard’s agentic protocols)

Visa is running a parallel track through its Agentic Ready Programme, which Worldline and ING joined, and Worldline has hedged across all of them: its approach is explicitly scheme- and protocol-agnostic, spanning Google’s AP2, OpenAI’s ACP and the Visa and Mastercard frameworks. It also shipped a Worldline MCP Server connecting payment capabilities to agents over the Model Context Protocol, so developers can trigger payment actions in natural language instead of integrating scheme-by-scheme. (Source : Worldline — Agentic Commerce)

Read together, the pattern is familiar from every protocol war: the products are launching before the standards settle, and each network is betting that being permissive across rivals’ protocols is cheaper than enforcing its own.

What is still unresolved

Three things are not, despite the announcements. First, liability. Explicit agentic identifiers give issuers visibility, and Verifiable Intent gives them evidence, but neither yet answers who eats the loss when a correctly authenticated agent buys something the human regrets. Visa’s 48-hour completion window points at the design tension: the further authorisation drifts from execution, the more the dispute surface grows.

Second, agent identity at scale. Spending limits and merchant-category restrictions are account-level controls applied to a non-human actor. Alchemy’s one-minute provisioning is attractive precisely because it is cheap, and cheap provisioning of transacting identities is the kind of thing that looks fine at a thousand agents and very different at ten million.

Third, consumer comprehension. The flows described so far all preserve deliberate human approval, biometric or explicit. That is the safe design, and it is also the one that limits the value proposition, since the whole promise of agentic commerce is the removal of checkout friction. Agents that confirm every purchase are not meaningfully autonomous; agents that do not confirm every purchase are not yet covered by litigation precedent.

The infrastructure question is largely settled. The governance question moved to the front of the queue this quarter, and the answer will be written by whoever manages to define “authorised” without owning it.

FAQ

Is agentic commerce actually live, or still experimental?

It is live in a narrow, controlled sense. Worldline completed end-to-end agent-driven payments in production with ING on Mastercard rails, with ING on Visa rails, and with Crédit Agricole in France. Worldline itself describes these as proof points rather than broad commercial availability, since general rollout depends on alignment between merchants, banks, networks and regulators.

What problem does Verifiable Intent solve?

It gives consumers, merchants and issuers cryptographic evidence of what a user authorised when an agent acted on their behalf. It creates a tamper-resistant record of intent, which is the missing piece when dispute resolution assumes a human clicked something.

Which specifications is Verifiable Intent built on?

It draws on specifications from the FIDO Alliance, EMVCo, the IETF and the W3C, and is aligned with Google’s AP2 and UCP. Mastercard open-sourced the specification and an initial reference implementation, and designed it to be protocol-agnostic so it can work across wallets, platforms, devices and other networks.

How does an agent get payment credentials?

Through provisioning products such as Alchemy’s AgentCard, which issues one-time-use tokenised Mastercard credentials alongside an email address, phone number and stablecoin wallet. Credentials link to a user’s existing card account, preserving rewards and credit lines, with issuer-set limits on spend and permitted merchant categories.

Does the bank lose control when an agent pays?

That is the design constraint the current architecture explicitly addresses. In the Worldline, ING and Mastercard flow, ING retained authentication and authorisation while Worldline processed the payment, and explicit identifiers flagged the transaction’s agentic nature so the issuer kept visibility and control.

Further Reading

— The Agent Report