Virtual Cards for AI Agents Compared (2026): Which Card Issuers Let an Agent Spend Under Limits
Last updated 2026-09-29.
There is no single best virtual card for an AI agent — it depends on whether you want a card platform that happens to have good spend controls, or one that was actually built for agents. Privacy.com and AgentCard ship an MCP server or agent-native card API out of the box; Lithic added an MCP server on top of its existing card-issuing platform; Ramp, Brex, Marqeta, and Stripe Issuing are general business/API card platforms with strong spend controls but no agent-specific product; Crossmint issues agent-scoped, revocable card allowances for crypto-native agent stacks. The right pick depends on whether you need a card today for one agent, or a compliance-grade program for many.
How we picked
Every provider below had to clear three bars, checked against the provider's own documentation, developer site, or product page — never a third-party blog or directory:
- A real virtual/programmable card product exists, described in the vendor's own docs, not a roadmap item.
- Programmatic or self-serve access is documented — an API, CLI, MCP server, or a signup flow an individual or business can reach without a mandatory sales call.
- Spend controls are named in the vendor's own text — a limit, lock, or approval mechanism, not just "enterprise-grade security" marketing copy.
We excluded two candidates that don't clear bar 1 for this specific question: Skyfire funds agents over cards, ACH, wires, or USDC but does not itself issue a card, per its product page; Mastercard Agent Pay and Visa's Trusted Agent Protocol are network-level programs that other issuers implement (see our separate guides on Mastercard Agent Pay and the Visa Trusted Agent Protocol) — a developer can't sign up for one directly to get a card.
This guide is published by PinkWallet, which is building Pink Agentic AI Payment (early access). We are not neutral in this space, which is why every factual claim links to a primary source.
Comparison table
| Provider | What it is | Who can sign up | How an agent gets a card | Controls documented | MCP server / agent SDK | Pricing |
|---|---|---|---|---|---|---|
| Privacy.com | Consumer/small-business virtual card issuer with a dedicated AI-agent product page | Individuals and small businesses (US) | Dashboard, API, CLI, or MCP server | Per-card spend_limit (with ANNUALLY/FOREVER/MONTHLY/TRANSACTION duration), MERCHANT_LOCKED and SINGLE_USE card types, pause/close |
Yes — MCP Server docs at agents.privacy.com | API access requires a paid Privacy plan; consumer plans not disclosed on the pages checked |
| Ramp | Corporate card + spend-management platform | US businesses, no personal credit check | Apply with a work email; cards issued via dashboard/API after approval | Merchant and category restrictions, real-time visibility, credit limits based on business financials | Not found on the pages checked | Not disclosed on the pages checked |
| Brex | Global corporate card platform (Capital One-owned) | Businesses, cards issued in 50+ countries | Dashboard/API; policies auto-apply per card | Per-category, per-merchant spend limits with policy auto-application, per-transaction AP controls on purchase cards | Not found on the pages checked | Plans start at $0 per user, per month (site footer); some products have fees |
| Stripe Issuing | Programmatic card-issuing API, part of Stripe's platform | Businesses via Stripe account (US, UK, EEA commercial; 30+ countries for stablecoin-backed cards) | Stripe API — create cardholders, issue virtual/physical cards | "Flexible spending controls": dynamic spending limits, merchant category restrictions, geographic controls; real-time authorization webhooks | Stripe has a separate MCP server (docs.stripe.com/mcp) for its general API, not Issuing-specific; see our payment APIs guide |
Not disclosed on the pages checked |
| Lithic | Card-issuing infrastructure platform explicitly marketed for "agentic commerce" | Businesses/developers, self-serve API sandbox | Lithic API — create virtual cards, assign to accounts, set rules | "Authorization Intelligence controls," merchant-category/transaction-limit/velocity rules, merchant locking, single-use cards | Yes — Lithic MCP Server, plugs into MCP-aware editors and chat clients | Not disclosed on the pages checked |
| Marqeta | Open-API card-issuing/processing platform | Businesses, sales-assisted ("Contact us"); no visible self-serve signup on the page checked | Marqeta Core API / Open API — issue debit, credit, or prepaid cards | Open API & webhooks for card programs; specific agent-facing spend-limit language not found on the page checked | Not found on the page checked | Not disclosed on the page checked |
| Crossmint | Agent-payments infrastructure spanning wallets and cards, crypto-native | Developers via API/SDK | Crossmint issues a scoped card or wallet allowance per agent | "Every allowance is scoped, explicit, and revocable"; "Card limits hold at Visa and Mastercard, wallet limits hold onchain"; one-time/encrypted card credentials | Documented agent SDK/overview at docs.crossmint.com/agents | Not disclosed on the page checked |
| AgentCard (agentcard.sh) | Purpose-built card-issuing product for AI agents | Individuals fund a balance via Apple Pay/Google Pay; companies use a separate Companies API with client credentials | Agent calls create_card over MCP or the API; single-use by default |
single_use (default) or multi_use cards, per-card amount_cents limit, scope_preset merchant locks (e.g., ai_labs), CLI cards set-limit and cards preset for spend caps/merchants/hours |
Yes — dedicated MCP server at mcp.agentcard.sh/mcp, plus a CLI (agent-cards) |
Production card creation requires an active Agentcard subscription (402 subscription_required per the API docs); consumer pricing not disclosed on the pages checked |
Pick by use case
A solo developer testing one agent. Start with AgentCard or Privacy.com — both let an individual fund a balance and issue a single-use card through an MCP server or CLI without a business entity, per AgentCard's issuing docs and Privacy's AI-agent page. Privacy.com requires a paid API plan to unlock programmatic access; AgentCard's individual flow is funding-first (Apple Pay/Google Pay into a USDC-backed balance) with production cards gated behind a subscription.
A US company letting agents buy SaaS or vendor subscriptions. Ramp and Brex are corporate-card platforms built around exactly this: merchant/category restrictions, real-time visibility, and manager-approved limits that a finance team sets once and an agent (or employee) spends within, per Ramp's card page and Brex's card page. Neither documents an agent-specific API on the pages we checked, so an agent would act through whatever expense-management integration or API access the company already has — read our spending-controls guide for how to wrap policy around that.
Non-US companies or companies wanting multi-region cards. Brex documents local cards and acceptance in 50+ countries; Stripe Issuing documents commercial issuing in the US, UK, and EEA, plus stablecoin-backed card programs in 30+ additional countries across Latin America, the Caribbean, and Africa, per Stripe's Issuing docs. Neither Privacy.com nor AgentCard's pages we checked specify availability outside the US.
High-volume, programmatic card issuance (many cards, machine-driven). Lithic and Stripe Issuing are built for this: both are API-first platforms designed to mint large numbers of virtual cards with authorization rules (merchant category, velocity, transaction limits) evaluated in real time, per Lithic's agentic-commerce page and Stripe's Issuing docs. Lithic goes further with a dedicated MCP server so an AI coding assistant can configure and test authorization rules directly, per Lithic's MCP announcement.
Crypto-native or wallet-first agent stacks. Crossmint issues per-agent card or wallet allowances that are "scoped, explicit, and revocable," with card limits enforced at the network (Visa/Mastercard) and wallet limits enforced onchain, per Crossmint's agent overview — a fit if your agent already holds a wallet and you want the same permissioning model to extend to card spend.
Limits of cards for agents
Cards are not a frictionless rail for autonomous spend, and every provider above inherits the same underlying constraints of the card networks:
- 3-D Secure and OTP challenges assume a human is present. Visa's own Trusted Agent Protocol materials exist specifically because merchants have "typically blocked" agent traffic the same way they block bots, and the protocol's fix is a cryptographic signature scheme — not a way for an agent to click through an SMS code or app-based 3DS prompt, per Visa's developer overview. Any card flow that triggers step-up authentication still needs a human in the loop unless the merchant has adopted an agent-verification scheme.
- Some providers gate production card creation behind an approval step, not an instant issuance. AgentCard's API returns
202 approval_pendingin production, requiring the cardholder to confirm with a passkey before the card goes live, per AgentCard's card-creation reference — by design, but it means "the agent gets a card" is not always synchronous. - Card-network minimums and per-transaction economics don't suit micropayments. AgentCard's own card-creation API sets a $1.00 minimum (
amount_centsminimum 100) per card, per its OpenAPI reference — workable for a SaaS subscription or a one-off purchase, not for sub-cent, pay-per-call API pricing. For that use case, see our comparison of stablecoin and x402-style payment APIs, which don't route through card rails at all. - Agent-specific pricing is largely undisclosed. None of the eight providers compared here publish an agent-specific rate card on the pages we checked; card economics (interchange, subscription fees, or per-card fees) are either general business pricing or not disclosed.
FAQ
Can an AI agent get its own virtual card?
Yes, on providers built or adapted for it. AgentCard's agent creates a card by calling create_card over its MCP server, and Privacy.com documents an MCP server that connects AI agents to its card API, per AgentCard's issuing docs and Privacy's MCP Server docs. On general business-card platforms like Ramp or Brex, the card is issued to the company or employee, and the agent spends within policy rather than holding its own agent-titled card.
What's the difference between a merchant-locked card and a spending-limit card?
A merchant-locked card only authorizes at one merchant — Privacy.com's MERCHANT_LOCKED card type "is locked to first merchant that successfully" charges it, per Privacy's Cards API docs — while a spending-limit card can be used anywhere but declines above a set amount, tracked over a duration like MONTHLY or FOREVER in the same docs. Several providers here, including Lithic and AgentCard, support both mechanisms on the same card.
Do any of these cards work outside the US? Partially. Stripe Issuing documents commercial issuing in the US, UK, and EEA, with stablecoin-backed card programs in 30+ additional countries, and Brex documents cards in 50+ countries, per Stripe's Issuing docs and Brex's card page. Ramp, Privacy.com, and AgentCard's pages we checked don't specify non-US availability.
Does a card stop an agent from overspending, or just flag it after the fact? Where documented, the limit is enforced at authorization time, not after settlement — Privacy.com states "Transaction requests above the spend limit will be declined," and Lithic's Authorization Intelligence "keep[s] every transaction within your spending parameters instead of relying on basic approve/decline logic," per Privacy's Cards API docs and Lithic's agentic-commerce page. That's a hard stop at the card network, which is different from a policy an agent could talk its way around if the enforcement lived only in the agent's own code — see our spending-controls guide for why that distinction matters.
Pink Agentic AI Payment (early access) enforces per-agent spending caps, allowlists and approval thresholds at the MCP layer, before a payment executes.






