Early · built in public

Give agents economic agency. Keep humans in control.

AG Pay is the payment control plane for AI agents—distinct identities, explicit permissions, and attributable purchases, without putting card details in model context.

Human-supervised by default Model-safe payment boundary Designed in public
EXAMPLE PROPOSALPurchase request
Awaiting review
A3
REQUESTED BYResearch agent 03
PAIRED
MERCHANTData API · Pro plan
TOTAL$29.00/ month
AGENT RATIONALE

Required to validate supplier data for the current research task.

POLICY TRACE
IDENTITYVerified
POLICYReview required
DECISIONWaiting for human
PAYMENT BOUNDARYSecrets stay outside the model.
PROTOTYPE PRINCIPLE / 001

Autonomy should be earned, configurable, and visible.

Continue

Intelligence can choose. Trust must authorize.

Agents can research products, compare providers, and recommend subscriptions. But the moment they need to spend, capability runs into a trust problem.

“A card in a prompt is not a permission system.”

Economic action needs identity, limits, human judgment, and a record that survives the agent session.

01

Identity

Know which exact agent installation initiated the request.

02

Authority

Assign approved payment methods and review rules per agent.

03

Context

See the merchant, rationale, amount, and recurrence before deciding.

04

Accountability

Keep the agent and payment method attached to every outcome.

Agents are moving from answers to actions.

Payments are the hard boundary between what an agent can reason about and what people can responsibly let it do. The standards for identity, oversight, and accountability are being shaped now.

01Research

Understands intent

02Decide

Compares options

03Request

Proposes a purchase

04Authorize

Applies human policy

05Act

Records the outcome

The next leap in agent capability is not unlimited autonomy. It is governable autonomy.

One control plane. Every decision attributable.

AG Pay links each proposal to an authenticated agent, an owner-approved payment method, and a human-defined policy.

01

Pair an agent

Give each runtime a distinct, revocable identity through a one-time pairing flow.

02

Set its boundaries

Assign only approved payment methods and choose when the agent must ask for review.

03

Review with context

Understand what the agent wants, where, why, and for how much. Approve or cancel.

04

Keep the history

Trace purchases and subscriptions back to the originating agent and payment method.

Useful to agents. Invisible to secrets.

The model gets the context it needs to make a request—not the credentials needed to move money. Raw card details stay out of model context and persistent AG Pay storage.

Separate human and agent identities Provider references instead of stored card numbers Human review is the fail-safe default
MODEL CONTEXT
Purchase intentitem · reason · amount
Sanitized outcomeapproved · failed · complete
AG PAY CONTROL PLANE
NO RAW CARD DATA
TRUSTED BOUNDARY
Payment provideropaque reference · safe metadata
Human policyidentity · rules · decision

IMPLEMENTED PROTOTYPESupervised autonomy, agent pairing, per-agent review rules, payment-method assignment, approvals, and attributable history. Broader live payment execution still requires provider integrations, compliance review, and production hardening.

Trust needs daylight.

Payments, identity, and agent autonomy are too consequential for opaque defaults. We believe this infrastructure should be built in the open—where the community can inspect the threat model, challenge approval boundaries, and help shape what comes next.

AG Pay is early. That is the invitation.

THE PAYMENT LAYER FOR AGENTS

Help us build it right.