Trusted Agent Protocol readiness
Trusted agents are live. Is your authorization layer ready?
Visa and 30+ European issuers are supporting live agent-initiated purchases. LoginID verifies the human, scopes approval to the transaction, and returns signed proof of consent.
{"agent": "tap_verified","human": "passkey_verified","merchant": "approved_merchant","amount": "129.00","purpose": "customer_instruction","consent_proof": "signed","result": "authorized"}
A trusted agent still needs an authorized human.
Visa’s Trusted Agent Protocol helps merchants recognize approved agents. Visa Payment Passkeys authenticate the cardholder. LoginID closes the remaining gap by proving who authorized the agent, what it may do, and which transaction the person approved.
Three questions make an agent transaction defensible.
Production systems need verified identity, scoped approval, and durable evidence.
Can you prove which human is behind the agent?
LoginID verifies the person with a phishing-resistant, FIDO2-certified passkey before the agent executes a sensitive action.
Is the approval scoped to the exact action?
A login proves access, not fresh consent. LoginID binds approval to the merchant, amount, purpose, action, and time.
What evidence survives fraud, disputes, and audit?
Every approval produces a timestamped, cryptographically verifiable record of who approved what.
How the trust layers work together.
Visa infrastructure and LoginID solve complementary parts of the agentic commerce trust chain.
| Trusted Agent Protocol | Visa Payment Passkeys | LoginID authorization layer | |
|---|---|---|---|
| Primary role | Recognize approved agents | Authenticate the cardholder for payment | Authorize a specific agent action |
| Cryptographic signal | Agent identity, intent, request integrity, freshness | FIDO-based payment authentication | Signed, scoped proof of consent |
| Human-to-agent attribution | Agent-level | Cardholder authentication | Verified human bound to agent action |
| Transaction scope | Signed request context | Payment authentication | Merchant, amount, purpose, and permitted action |
| Operational evidence | Trusted agent request | Authenticated payment | Timestamped authorization record |
Add human authorization to every sensitive agent action.
Verify the person
Authenticate the human with a phishing-resistant passkey before money moves.
Scope the mandate
Restrict approval to the merchant, amount, purpose, and action the customer intended.
Return signed proof
Create verifiable evidence for fraud review, disputes, reconciliation, and audit.
Keep credentials away from agents
Let agents complete approved purchases without receiving reusable customer credentials.
How LoginID fits a TAP-aligned transaction.
- 01
Recognize the agent
The merchant validates the trusted agent signal and applies its own access and commerce controls.
- 02
Verify and authorize
LoginID verifies the human with a passkey and binds consent to the merchant, amount, purpose, and permitted action.
- 03
Execute with proof
The agent completes the approved transaction using constrained credentials, while a signed consent record is retained for audit and disputes.
Give customers clear control
Let people review and approve the exact action without giving the agent reusable credentials.
Learn more- See the merchant, amount, and purpose
- Approve with a phishing-resistant passkey
- Create a signed record of the instruction
Frequently asked questions
- Does Trusted Agent Protocol already solve human authorization?
- No. TAP addresses agent recognition and signed agent-to-merchant communication. LoginID adds the verified human, scoped authority, and durable proof of consent.
- Why is an existing login or 3DS flow not enough?
- A session proves access, not fresh consent for a specific autonomous action. LoginID binds approval to the merchant, amount, purpose, and time with a passkey gesture.
- How does LoginID support Visa Payment Passkeys?
- Visa Payment Passkeys authenticate the cardholder. LoginID binds that verified human’s approval to the merchant, amount, purpose, and permitted action.
- Can teams prepare before launching agent payments?
- Yes. Map agent recognition, human authentication, spend controls, credential handling, and audit evidence before choosing a complete payment path.
- Is LoginID FIDO2 certified?
- Yes. The FIDO Alliance lists LoginID as a FIDO2-certified authentication solution.
Close the agent authorization gap.
Bring your payment flow. We’ll map agent recognition, human verification, scoped consent, credential handling, and audit evidence.

