# Mastercard Agent Pay
source: https://developer.mastercard.com/mastercard-agent-pay/documentation/index.md

## Overview {#overview}

Agentic Commerce enables new purchasing experiences where Agents can assist Cardholders during checkout or, with the Cardholder's authorization, independently discover and purchase products on their behalf while adhering to approved checkout constraints.

As these interactions become more autonomous, participants across the payment ecosystem need a reliable way to verify the Cardholder's authorization, secure payment credentials, and maintain visibility into agent-initiated transactions.

**Mastercard Agent Pay** is Mastercard's program for enabling secure and verifiable agent-facilitated payments. It provides the services, credentials, and transaction signals required to support Agentic Commerce while helping ecosystem participants establish trust, maintain transparency, and manage risk throughout the transaction lifecycle.

Agent Pay is built on four core capabilities that work together throughout the transaction lifecycle:

* **Network tokenization:** Uses the Mastercard Digital Enablement Service (MDES) to replace Funding Primary Account Number (FPAN) data with Agentic Tokens.

* **Strong authentication:** Supports Mastercard payment passkeys and other Mastercard-approved authentication methods to verify the Cardholder.

* **Intent:** Captures what the Cardholder has authorized and links that authorization to authentication and transaction execution.

* **Fraud and cybersecurity:** Provides capabilities to help participants identify, assess, and manage risks associated with agent-mediated activity.

Together, these capabilities help ensure that an Agentic Commerce Transaction reflects the Cardholder's approved Intent, uses protected payment credentials, and carries the identifiers and context needed for issuer visibility, servicing, and dispute support.

## Why Use Mastercard Agent Pay {#why-use-mastercard-agent-pay}

Agent Pay enables Agents to assist Cardholders or act on their behalf while preserving the trusted relationship between the Cardholder, Merchant, and Issuer.

### Key Principles {#key-principles}

Agent Pay is built around three principles:

* **Trust**: Ensures the Cardholder's instructions are accurately represented and executed.

* **Security**: Protects transactions through network tokenization, strong authentication, and cybersecurity controls.

* **Transparency**: Provides participants with the context needed to understand who acted, what was intended, and what occurred during the transaction.

### Benefits by Stakeholder {#benefits-by-stakeholder}

Agent Pay provides benefits across the Agentic Commerce ecosystem:

#### Agents and Agentic Commerce Providers (ACPs) {#agents-and-agentic-commerce-providers-acps-br}

Enables ACPs to build and scale Agentic Commerce experiences using Mastercard acceptance, Agentic Tokens, Cardholder authentication, Intent validation, and participant identifiers. These capabilities help reduce agent-driven errors and fraud while maintaining accountability for the Agents and commerce activity they enable.

#### Cardholders {#cardholders-br}

Enables more personalized and convenient shopping experiences through Agents while keeping Cardholders in control of what they authorize. Cardholders can use their preferred Mastercard payment credentials, supported by tokenization, authentication, and Intent validation for safer transactions.

#### Issuers {#issuers-br}

Allows Agentic Commerce Transactions to use existing token-enabled authorization flows while providing additional agentic identifiers and Intent context. This helps Issuers identify agent-mediated transactions, strengthen fraud and authorization decisioning, improve customer servicing, and support dispute prevention and resolution.

#### Merchants, PSPs, and Acquirers {#merchants-psps-and-acquirers-br}

Enables participation in agent-driven commerce through richer data exchange, enhanced order and Intent context, and clearer transaction identification. These capabilities can help Merchants maintain customer relationships, deliver brand and loyalty experiences, and reduce servicing and dispute-related friction.

### Agent Pay Ecosystem Participants {#agent-pay-ecosystem-participants}

The following entities participate in the Agent Pay ecosystem.

|                     Role                      |                                                                                                                                                                    Description                                                                                                                                                                    |
|-----------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Cardholder**                                | Owns the Mastercard credential, defines purchase instructions with the Agent, and provides Affirmative confirmation and authentication for immediate or delegated purchases.                                                                                                                                                                      |
| **Agent**                                     | Software that assists or acts on the Cardholder's behalf to discover, assemble, or complete a purchase within the Cardholder's approved Intent.                                                                                                                                                                                                   |
| **Agentic Commerce Provider (ACP)**           | An Agentic Commerce Provider (ACP) is a registered participant that performs agentic commerce functions on behalf of a Cardholder, including capturing and presenting the Cardholder's Intent. Entities that only request tokens or facilitate checkout are not ACPs. The ACP is accountable for the agent's security, compliance, and behaviour. |
| **Merchant**                                  | Sells goods or services, receives tokenized payment data, and submits authorization requests. Merchants may also provide Agent-facing interfaces for product discovery, Intent validation, and checkout.                                                                                                                                          |
| **Payment Service Provider (PSP) / Acquirer** | Processes transactions for the Merchant and may support Merchant registration, transaction routing, and acceptance of Agentic Commerce payloads.                                                                                                                                                                                                  |
| **Credential Provider**                       | Provides the payment credentials available for Cardholder selection within an agentic commerce experience. In some implementations, this may be a pass-through digital wallet.                                                                                                                                                                    |
| **Issuer**                                    | Issues payment credentials, approves tokenization requests, authorizes transactions, and uses agentic identifiers and Intent context to support decision-making, servicing, and dispute support.                                                                                                                                                  |
| **Mastercard**                                | Enables and governs the Agent Pay program, supports tokenization, Intent and checkout validation, and provides network-visible identifiers for agentic activity.                                                                                                                                                                                  |

### Program Roles {#program-roles}

Participants in the Agent Pay ecosystem may perform one or more of the following roles.

|           Role           |                                                                                                                                                                                                                                                       Description                                                                                                                                                                                                                                                       |
|--------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Token Requestor**      | Enrolls payment credentials, provisions Agentic Tokens, performs identity verification (ID\&V), and protects token credentials throughout their lifecycle. Issuers identify the Token Requestor through a Token Requestor ID (TRID).                                                                                                                                                                                                                                                                                    |
| **Checkout Facilitator** | Provides cardholders with access to tokenized credentials, initiates cardholder authentication, facilitates checkout interactions with merchants, and communicates transaction outcomes. A Checkout Facilitator may verify the cardholder but must not store tokens or access the PAN, CVV, or expiry date. Retrieved tokens can be used only for the specific cardholder-initiated transaction for which they were obtained. Issuers identify the Checkout Facilitator through a Digital Service Provider ID (DSP ID). |
| **Token Aggregator**     | Also known as an On-Behalf Token Requestor (OBTR), requests and manages Mastercard tokens through the Mastercard Digital Enablement Service (MDES) on behalf of downstream ACPs. It may also provide registration, token enablement, data management, and related services. Mastercard assigns each ACP its own DSP ID, which identifies the ACP rather than the Token Aggregator.                                                                                                                                      |

## How Mastercard Agent Pay Works {#how-mastercard-agent-pay-works}

Mastercard Agent Pay uses a structured workflow to help Cardholders authorize Agents to make purchases securely and within defined boundaries.

![Agent Pay Ecosystem](https://static.developer.mastercard.com/content/mastercard-agent-pay/documentation/images/Agent_Pay_New.png "Agent Pay")

### 1. Registration and Onboarding {#1-registration-and-onboarding}

Before using Agent Pay, the ACP must complete Mastercard registration and onboarding for itself and its agents. Mastercard verifies participants, establishes the participation model, and assigns each approved agent a unique identifier for use throughout the transaction lifecycle. For onboarding instructions, see [Onboarding Guide](https://developer.mastercard.com/mastercard-agent-pay/tutorial/onboarding-sandbox/index.md).

### 2. Credential Access and Tokenization {#2-credential-access-and-tokenization}

The Cardholder selects an eligible Mastercard payment credential. The Token Requestor then provisions or enables an Agentic Token for use within the program. Where supported, an existing eligible cloud token may be used instead of provisioning a new token. The Token Requestor also performs identity verification (ID\&V) during enrollment when required.

### 3. Intent Establishment {#3-intent-establishment}

The Cardholder and Agent define the purchasing parameters that govern what the agent is authorized to buy. These intent parameters may include the maximum purchase amount, a description of the goods or services, the intent validity period, and eligible merchants or merchant categories. For delegated (autonomous) purchases, the Cardholder must, at a minimum, specify a budget limit, a description of the goods or services to be purchased, and the intent validity period.

### 4. Affirmative Confirmation {#4-affirmative-confirmation}

The Cardholder reviews the defined Intent and actively confirms the authority granted to the Agent.

### 5. Authentication {#5-authentication}

The Cardholder is authenticated using a Mastercard-approved authentication method that complies with Token Authentication Framework (TAF) requirements.
Supported methods may include a Mastercard payment passkey or other authentication methods permitted under TAF. Participants that are already registered and onboarded with Mastercard for Agent Pay and the applicable Token Requestor role can use the Token Authentication Service (TAS) to authenticate Cardholders for tokenized Agentic Commerce transactions. Additional registration, onboarding, or approval may be required before certain participants can use TAS.

### 6. Intent Registration and Validation {#6-intent-registration-and-validation}

The Intent is registered and made available for validation. This allows participating parties to verify that the requested checkout and transaction execution remain within the Cardholder's approved scope.

### 7. Checkout and Transaction Execution {#7-checkout-and-transaction-execution}

The Agentic Commerce Provider (ACP) selects the appropriate payment payload based on the merchant's capabilities. A Digital Secure Remote Payment (DSRP) cryptogram is used when the merchant can process enhanced token data, while a Dynamic Token Verification Code (DTVC) is used when the merchant supports only basic card data.

The ACP then requests a tokenized payment payload using the current intent details and available merchant information. Mastercard returns the payload only when the checkout request aligns with the approved intent. The payload can be delivered through a web checkout experience, a payment acceptance API, a Model Context Protocol (MCP) server, or a merchant agent. The merchant then submits the authorization request, and the transaction is processed using Mastercard's tokenized payment flow.

### 8. Identification and Outcome Visibility {#8-identification-and-outcome-visibility}

Agentic identifiers, such as the Token Requestor ID (TRID) and Digital Service Provider ID (DSP ID), enable issuers to identify transactions initiated through an Agent.

Issuers receive the DSP ID and Order ID in the transaction message and can use the Order ID to retrieve additional intent details that support customer servicing, dispute resolution, and transaction investigations. Through the Commerce Event Notification Service, Mastercard can also relay transaction outcomes to the intent submitter, which can then communicate those outcomes to the Cardholder.

## Intent and Authentication {#intent-and-authentication}

### Intent in Agent Pay {#intent-in-agent-pay}

Intent is the scope of the Cardholder's commerce instructions to an Agent and the data object that describes that scope. It may include details such as:

* Maximum purchase amount
* Description of the goods or services to be purchased
* Intent validity period
* Merchant information or Merchant categories
* Selectively disclosed order details, such as items, SKUs, product attributes, and references to product assets
* A summary of the Cardholder's instructions or prompt provided to the Agent
* Additional checkout constraints

Once an intent is registered, it cannot be modified. Any further changes require the creation of a new intent, followed by renewed affirmative confirmation and Cardholder re-authentication.

Before an Agentic Commerce transaction can proceed, the intent must be clearly presented to the cardholder and affirmatively approved.

### Affirmative Confirmation and Authentication {#affirmative-confirmation-and-authentication}

Affirmative Confirmation is the Cardholder's clear, voluntary, active, and informed agreement for an Agent to act within the presented Intent. It may be given only when the Cardholder is made explicitly aware of the specific scope of authority being granted.

Authentication establishes that the person granting that authority is the Cardholder or an authorised user. All Agentic Commerce transactions require Cardholder authentication. Authentication requirements, assurance levels, and approved authentication methods are defined by the Token Authentication Framework (TAF).

Agent Pay combines these concepts so participants can connect:

* What was intended
* Who approved it
* What transaction was executed

### Supported Intent Models {#supported-intent-models}

Agent Pay supports the following intent models:

**1. Amount Validation Service**
Mastercard validates that the transaction amount submitted in the authorization request does not exceed the amount approved by the Cardholder at checkout.

**2. Verifiable Intent**
Verifiable Intent combines Cardholder authentication with a trust framework that establishes, validates, and enforces cardholder authorization. It creates a cryptographically verifiable record of the purchase details approved by the Cardholder and supports both Immediate and Delegated purchasing experiences.

References to intent apply to either model unless a specific intent model is identified.

### Supported Purchasing Modes {#supported-purchasing-modes}

Agent Pay supports two purchasing modes:

**1. Immediate Purchasing**
In an Immediate Purchase flow, the Cardholder remains in session while the Agent retrieves a payment credential and checkout is completed. Intent review, affirmative confirmation, authentication, and checkout can occur in a single session.

**2. Autonomous or Delegated Purchasing**
In an Autonomous or Delegated Purchase flow, the Cardholder defines and authenticates the Intent in advance. The Agent can then execute purchases at a later time, provided each purchase remains within the approved constraints.
The Cardholder must at least specify the following:

* Budget limits
* Description of the goods or services to be purchased
* Intent validity period

The Merchant limits or Merchant categories may also be included.

Each order within an intent may result in a separate Agentic Commerce transaction and may be fulfilled by a different merchant. An agent must not combine multiple orders within an intent into a single transaction unless it determines that the orders can be fulfilled by the same merchant in accordance with the intent.

This model allows Agents to act on the Cardholder's behalf while ensuring that purchases remain within the authority the Cardholder previously approved.

For more information, see [Verifiable Intent](https://developer.mastercard.com/mastercard-agent-pay/documentation/verifiable-intent/index.md).

## Implementation Considerations {#implementation-considerations}

An eligible Network Cloud Token is required to process any Agentic Commerce transaction within the program.

### Payment Credentials and Token Usage {#payment-credentials-and-token-usage}

Agentic Tokens are MDES cloud network tokens enabled for Agentic Commerce. They support two primary payment payload formats:

* **Digital Secure Remote Payment (DSRP) cryptograms**: The preferred payload format when the Merchant can accept enhanced token data.
* **Dynamic Token Verification Codes (DTVCs)**: One-time-use, three-digit dynamic codes used when a Merchant interface accepts only a PAN, expiration date, and security code.

### Credential Access Options {#credential-access-options}

Cardholders can access eligible payment credentials through:

* Card-on-file network tokens
* Pass-through digital wallets are currently the only supported wallet type and use MDES cloud tokens.
* Mastercard Credential Services

The Cardholder must directly choose the card used for each Agentic Commerce transaction. ACPs are required to present all available payment credentials and ensure that the Cardholder explicitly chooses the credential used for a transaction. While agents can follow preferences or rules specified by the Cardholder, they cannot independently optimize or decide which credential to use.
Note: **Mastercard Credential Services** is the recommended credential-access approach for new integrations.

### Transaction Identifiers {#transaction-identifiers}

Agent Pay includes program identifiers that help ecosystem participants recognize and process agent-mediated transactions.

|                 Identifier                 |                                                      Used For                                                       |
|--------------------------------------------|---------------------------------------------------------------------------------------------------------------------|
| **Token Requestor ID (TRID)**              | Identifying the entity that requested and manages the Agentic Token.                                                |
| **Digital Service Provider ID (DSP ID)**   | Identifying the participant performing specific activities, such as checkout, authentication, or intent submission. |
| **Agentic Commerce and Intent indicators** | Indicating that a transaction was initiated through an agent and that associated intent information is available.   |

Issuers receive the DSP ID and Order ID as part of the transaction data. The Order ID can be used to retrieve additional intent details that support customer servicing, dispute resolution, and transaction investigations. Through the Commerce Event Notification Service, Mastercard can communicate transaction outcomes to the intent submitter, enabling those outcomes to be shared with the cardholder.

## Use cases {#use-cases}

|                                                                  Use Case                                                                  |                                                                              Description                                                                              |
|--------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| [**Card Enrollment**](https://developer.mastercard.com/mastercard-agent-pay/documentation/use-cases/card-enrollment/index.md)              | Enroll and tokenize a cardholder's payment credential, including any required identity verification, to provision an Agentic Token for use in Agent Pay transactions. |
| [**Agentic Transaction Flow**](https://developer.mastercard.com/mastercard-agent-pay/documentation/use-cases/agentic-transaction/index.md) | Complete an immediate or delegated purchase using an authenticated intent, tokenized payment credentials, and Mastercard payment acceptance interfaces.               |

## Next Steps {#next-steps}

Now that you understand Mastercard Agent Pay, explore the related use cases and API operations:

* Explore the [Verifiable Intent](https://developer.mastercard.com/mastercard-agent-pay/documentation/verifiable-intent/index.md) use case.
* Review the [Card Enrollment](https://developer.mastercard.com/mastercard-agent-pay/documentation/use-cases/card-enrollment/index.md) flow.
* Review the [Agentic Transaction](https://developer.mastercard.com/mastercard-agent-pay/documentation/use-cases/agentic-transaction/index.md) Flow.
* Visit the [API Reference](https://developer.mastercard.com/mastercard-agent-pay/documentation/api-reference/index.md#verifiable-intent) section to explore available endpoints and sample requests.
