Identity
Know which exact agent installation initiated the request.
AG Pay is the payment control plane for AI agents—distinct identities, explicit permissions, and attributable purchases, without putting card details in model context.
Required to validate supplier data for the current research task.
Agents can research products, compare providers, and recommend subscriptions. But the moment they need to spend, capability runs into a trust problem.
“A card in a prompt is not a permission system.”
Economic action needs identity, limits, human judgment, and a record that survives the agent session.
Know which exact agent installation initiated the request.
Assign approved payment methods and review rules per agent.
See the merchant, rationale, amount, and recurrence before deciding.
Keep the agent and payment method attached to every outcome.
Payments are the hard boundary between what an agent can reason about and what people can responsibly let it do. The standards for identity, oversight, and accountability are being shaped now.
Understands intent
Compares options
Proposes a purchase
Applies human policy
Records the outcome
The next leap in agent capability is not unlimited autonomy. It is governable autonomy.
AG Pay links each proposal to an authenticated agent, an owner-approved payment method, and a human-defined policy.
Give each runtime a distinct, revocable identity through a one-time pairing flow.
Assign only approved payment methods and choose when the agent must ask for review.
Understand what the agent wants, where, why, and for how much. Approve or cancel.
Trace purchases and subscriptions back to the originating agent and payment method.
The model gets the context it needs to make a request—not the credentials needed to move money. Raw card details stay out of model context and persistent AG Pay storage.
IMPLEMENTED PROTOTYPESupervised autonomy, agent pairing, per-agent review rules, payment-method assignment, approvals, and attributable history. Broader live payment execution still requires provider integrations, compliance review, and production hardening.
Payments, identity, and agent autonomy are too consequential for opaque defaults. We believe this infrastructure should be built in the open—where the community can inspect the threat model, challenge approval boundaries, and help shape what comes next.
AG Pay is early. That is the invitation.
Payments + security
02Agents + protocols
03Product + design
04Infrastructure + tools