Trusted Agent Protocol readiness

Trusted agents are live. Is your authorization layer ready?

Visa and 30+ European issuers are supporting live agent-initiated purchases. LoginID verifies the human, scopes approval to the transaction, and returns signed proof of consent.

FIDO2 certified·Scoped authorization·Signed consent
authorization · trusted agent purchase
{
"agent": "tap_verified",
"human": "passkey_verified",
"merchant": "approved_merchant",
"amount": "129.00",
"purpose": "customer_instruction",
"consent_proof": "signed",
"result": "authorized"
}

A trusted agent still needs an authorized human.

Visa’s Trusted Agent Protocol helps merchants recognize approved agents. Visa Payment Passkeys authenticate the cardholder. LoginID closes the remaining gap by proving who authorized the agent, what it may do, and which transaction the person approved.

Three questions make an agent transaction defensible.

Production systems need verified identity, scoped approval, and durable evidence.

Can you prove which human is behind the agent?

LoginID verifies the person with a phishing-resistant, FIDO2-certified passkey before the agent executes a sensitive action.

Is the approval scoped to the exact action?

A login proves access, not fresh consent. LoginID binds approval to the merchant, amount, purpose, action, and time.

What evidence survives fraud, disputes, and audit?

Every approval produces a timestamped, cryptographically verifiable record of who approved what.

How the trust layers work together.

Visa infrastructure and LoginID solve complementary parts of the agentic commerce trust chain.

Trusted Agent ProtocolVisa Payment PasskeysLoginID authorization layer
Primary roleRecognize approved agentsAuthenticate the cardholder for paymentAuthorize a specific agent action
Cryptographic signalAgent identity, intent, request integrity, freshnessFIDO-based payment authenticationSigned, scoped proof of consent
Human-to-agent attributionAgent-levelCardholder authenticationVerified human bound to agent action
Transaction scopeSigned request contextPayment authenticationMerchant, amount, purpose, and permitted action
Operational evidenceTrusted agent requestAuthenticated paymentTimestamped authorization record

Add human authorization to every sensitive agent action.

Verify the person

Authenticate the human with a phishing-resistant passkey before money moves.

Scope the mandate

Restrict approval to the merchant, amount, purpose, and action the customer intended.

Return signed proof

Create verifiable evidence for fraud review, disputes, reconciliation, and audit.

Keep credentials away from agents

Let agents complete approved purchases without receiving reusable customer credentials.

How LoginID fits a TAP-aligned transaction.

  1. 01

    Recognize the agent

    The merchant validates the trusted agent signal and applies its own access and commerce controls.

  2. 02

    Verify and authorize

    LoginID verifies the human with a passkey and binds consent to the merchant, amount, purpose, and permitted action.

  3. 03

    Execute with proof

    The agent completes the approved transaction using constrained credentials, while a signed consent record is retained for audit and disputes.

For people

Give customers clear control

Let people review and approve the exact action without giving the agent reusable credentials.

Learn more
  • See the merchant, amount, and purpose
  • Approve with a phishing-resistant passkey
  • Create a signed record of the instruction

Frequently asked questions

Does Trusted Agent Protocol already solve human authorization?
No. TAP addresses agent recognition and signed agent-to-merchant communication. LoginID adds the verified human, scoped authority, and durable proof of consent.
Why is an existing login or 3DS flow not enough?
A session proves access, not fresh consent for a specific autonomous action. LoginID binds approval to the merchant, amount, purpose, and time with a passkey gesture.
How does LoginID support Visa Payment Passkeys?
Visa Payment Passkeys authenticate the cardholder. LoginID binds that verified human’s approval to the merchant, amount, purpose, and permitted action.
Can teams prepare before launching agent payments?
Yes. Map agent recognition, human authentication, spend controls, credential handling, and audit evidence before choosing a complete payment path.
Is LoginID FIDO2 certified?
Yes. The FIDO Alliance lists LoginID as a FIDO2-certified authentication solution.

Close the agent authorization gap.

Bring your payment flow. We’ll map agent recognition, human verification, scoped consent, credential handling, and audit evidence.