Verifiable Intent: The Missing Primitive for Agentic Commerce

As agentic commerce evolves, the emergence of Verifiable Intent offers a crucial control layer to ensure that AI-driven transactions align with user intent. This article unpacks the significance of this new framework, its implications for identity and fraud teams, and why it matters in the rapidly changing landscape of digital payments.

Verifiable Intent: The Missing Primitive for Agentic Commerce

Agentic commerce is no longer just a buzzword; it's moving from demos to actual production. AI can now discover products, assemble carts, and complete purchases on real payment rails. But here's the catch: the biggest hurdle isn’t about making an AI agent pay. Nope. The real challenge lies in ensuring the ecosystem is confident that the agent was supposed to pay — for that item, at that price, and within the rules defined by the user.

This is the gap Mastercard is tackling with Verifiable Intent, an open, standards-based specification that creates a tamper-resistant record linking: 1. The user’s authorization and constraints. 2. The agent’s action. 3. What actually settled.

If you work in identity, fraud, or disputes, pay attention: this is a significant development. We’re moving beyond just asking if the credential was valid to whether the transaction matched the user’s intent.

---

What Mastercard Introduced (and What It Is Not)

To get a proper grip on Verifiable Intent, it's essential to understand what it actually offers:

- It’s not a new payment rail. - It’s not an agent-authentication protocol. - It’s not tokenization.

What it is, however, is a proof layer that enables transaction parties — merchants, issuers, wallets, and agent platforms — to answer the pressing question that will dominate the upcoming wave of AI-driven chargebacks: “Did the user authorize this specific outcome?”

Mastercard has open-sourced the specification, including a reference implementation, with the aim for interoperability across various ecosystems and protocols. This is a thoughtful move in an industry notoriously plagued by silos.

---

How It Works in Plain English

At a high level, Verifiable Intent accomplishes three critical tasks:

1. Captures delegation as a structured “intent object.” When a user delegates a task (like, “Book me a flight under $500 on these dates”), the constraints are recorded in a standardized, signed format.

2. Binds the intent object to the transaction outcome. When the agent executes, the purchase is cryptographically linked to the original constraints, making it easier to spot mismatches, such as exceeding a price limit.

3. Shares only what each party needs via selective disclosure. There’s no need for merchants to see the user’s entire instruction history. Verifiable Intent is designed to reveal only the minimal necessary data for risk decisions and dispute resolution.

Underneath it all, Mastercard has built this specification on widely adopted standards to avoid vendor lock-in, utilizing frameworks from FIDO, EMVCo, IETF, and W3C.

---

Where Verifiable Intent Fits in the Agentic Stack

Think of the agentic commerce ecosystem as a 3-layer trust stack:

1. Agent identity: “Is this a legitimate agent?” - Visa’s Trusted Agent Protocol aims to help merchants tell approved agents from malicious bots using signals and cryptographic means.

2. Payment credential delegation: “Can this agent transact safely?” - Mastercard’s Agent Pay framework utilizes tokenization concepts and strong user verification mechanisms like passkeys to ensure delegated payments are bounded and retrievable.

3. Intent proof: “Did the agent do what the human authorized?” - This is where Verifiable Intent comes in. It provides a shared, tamper-resistant record that can navigate the complexities of disputes, customer service issues, and issuer chargebacks.

These layers are complementary. Agent authentication mitigates bot abuse, tokenization reduces the risk of credential theft, and intent proof clarifies ambiguities around user authorization.

---

Why Identity, Fraud, and Disputes Teams Should Care

Fraud Shifts from “Stolen Credential” to “Instruction Drift”

In traditional card-not-present (CNP) fraud scenarios, the focus is primarily on whether the payer is legitimate and if credentials are compromised. However, in the realm of agentic commerce, the real losses often stem from:

- A legitimate user broadly delegating tasks. - An agent acting quickly, resulting in plausible yet unauthorized purchases.

Verifiable Intent provides a mechanism for adjudicating such mismatches with verifiable evidence instead of competing logs — a much-needed shift in approach.

Chargebacks Will Become “Policy Disputes”

Get ready for disputes to morph into a new category: - “I authorized ‘under $X’ but it exceeded the limit.” - “I authorized ‘airline A’ but it booked airline B.” - “I authorized ‘shipping tomorrow’ but it chose 5–7 days.” - “I authorized ‘renew subscription’ but it added an upsell.”

Expect networks and issuers to seek portable artifacts capable of answering the critical question: Was this transaction within the delegation scope?

Privacy Posture Becomes a Competitive Advantage

Let’s face it: selective disclosure isn’t just a gimmick. It’s crucial for establishing a shared trust layer that doesn’t force all parties to ingest full behavioral profiles. This added privacy can be a significant competitive edge.

---

Proof It’s Moving Beyond Slides: Live Pilots

Mastercard's initiatives are already showing tangible results through live pilots: - A Malaysia pilot involving CIMB, Maybank, and RHB showcased Mastercard Agent Pay in a ride-booking scenario, using tokenized credentials and Mastercard Payment Passkeys for robust verification. - European deployments have indicated end-to-end agentic payments operating through Mastercard's stack (via bank rails and Agent Pay).

While skeptics may argue that not every pilot will lead to mass adoption, the direction is clear: the design of disputes, liability, and evidence handling is actively in progress now, not later.

---

“Signal-First” Implementation Guidance: Cost-Aware, Progressive Proofing

If you're considering building an agentic checkout or delegated payments system, think of intent proof as part of a progressive proofing ladder:

Step 0: Low-Cost Baseline Signals (always-on) - Email/phone intelligence - Device + IP reputation - Geo velocity + anomaly checks - Account tenure + behavior history - Merchant/category risk

Step 1: Intent Capture with Explicit Constraints - Spending caps (per transaction / per day) - Merchant category allow/deny - Time windows (e.g., “valid for 2 hours”) - Item-level rules (brand, size, delivery SLA)

Step 2: Step-Up Only When Risk Says So - Implement strong re-authentication for high-risk delegations or first-time agent activations, consistent with how Mastercard is promoting passkeys in Agent Pay flows. - Consider step-ups when execution approaches policy edges (e.g., price close to cap, new merchant).

Step 3: Bind + Store the Evidence You’ll Need Later - Store intent object references alongside order, authorization, capture, and settlement metadata. - Generate clear internal reason codes for easy identification: - (eligible for streamlined acceptance) - - - - (requires manual review/post-purchase confirmation).

This approach helps maintain low friction for regular purchases while creating a robust paper trail for exceptions.

---

What to Watch Next

To determine if Verifiable Intent will become the standard plumbing of agentic commerce or just another well-marketed concept, keep an eye on these indicators: - Open-source adoption velocity: Look for real implementations rather than just theoretical discussions. - Issuer dispute workflows: Are they accepting intent artifacts as valid evidence? - Acquirer/PSP embedding: Will merchants access this framework without needing bespoke integrations? - Convergence vs. Fragmentation: Are other networks aligning with this approach or developing competing formats?

---

Bottom Line

Agentic commerce will only scale if accountability scales alongside it. Verifiable Intent is a credible effort to make delegated payments disputable, auditable, and privacy-preserving — essentials that identity, fraud, and compliance teams need to embrace autonomy without risking skyrocketing loss rates and customer trust.

---

Sources 1. How AI Assistants are Moving the Security Goalposts 2. Growing Fraud Risks Complicate Banks’ Push Toward Instant Payments 3. Bankers Tell Lawmakers Fraud Is Growing Faster Than Defenses 4. The fusion of authentication and fraud prevention is here. Are you ready for it? 5. HHS and state AGs fine ambulance firm over $500,000, require enhanced security, privacy, and data minimization practices

Sources