On September 30, Mastercard added trust and intelligence services to Agent Pay, its agentic payments program. The first service, now testing with U.S. issuers, is a probability score that estimates whether a transaction was initiated by an AI agent, so banks can approve legitimate agent-led purchases instead of declining them out of caution.
This is a real milestone: the card networks now treat agent-initiated commerce as a first-class category. But the score says an agent was probably involved. It does not say which agent, whether that agent has a history worth trusting, or whether the merchant on the other side is legitimate.
Which agent: verifiable identity
An agent that can spend money needs an identity that can be checked, not just asserted. Our TAP verifier checks agent identity claims the way the web already checks servers: HTTP message signatures (RFC 9421), Ed25519 keys resolved through JWKS, and a reputation record accumulated under the agent's key ID.
Is the other side dirty: composite scoring
Identity answers which agent. It does not answer whether the merchant, the link, or the wallet on the other side is legitimate. That is a corpus problem.
POST /v1/composite-check
Takes a URL, a wallet address, an email, or any combination, and returns one risk score from 0 to 100. Every signal is cross-correlated against our threat-intelligence corpus: 123 monitored Telegram marketplaces, 661K+ indicators, 8.4M+ citations. When the corpus has seen an indicator, the response says so. When it has not, it says nothing is known, which is not the same as clean.
We also fingerprint the kits behind phishing pages: deterministic kit_<sha256> IDs for phishing and smishing kits, live in production.
Both halves
Mastercard's score keeps legitimate agents from being declined. The relying party's problem is the mirror image: knowing which agent is asking, whether it has earned trust, and whether the counterparty is legitimate. The agent economy needs both halves.
Full post: https://blog.relayshield.net/mastercard-agent-pay-trust
Top comments (1)
Knowing it was an agent is only half the dispute. The other half is proving what the human actually authorized: scope, spend cap, payee allowlist, and expiry, captured before the purchase and signed. Without that mandate record, "the agent did it" just moves the argument from the cardholder to the agent vendor. Do you see the mandate living with the agent platform or with the issuer?
iin1005h1928