What Is the Visa Trusted Agent Protocol?
The Visa Trusted Agent Protocol is a specification that lets a merchant cryptographically verify that an incoming request comes from a legitimate, Visa-recognized AI shopping agent — rather than an anonymous bot — using signed HTTP messages, as part of Visa's broader Visa Intelligent Commerce program.
Key facts
- Announced October 14, 2025. Visa "unveiled Trusted Agent Protocol, establishing a foundational framework for agentic commerce that enables secure communication between AI agents and merchants during every step of a transaction," per Visa's press release.
- Built on established web standards, not a Visa-only cryptographic scheme. Per Visa's technical specification, the protocol uses HTTP Message Signatures compliant with RFC 9421, requiring
Signature-InputandSignatureheader fields, and is described as aligned with the web-bot-auth standard. Signatures use asymmetric cryptography: agents sign requests with a private key, and merchants verify using a public key retrieved from a trusted key store (for Visa's own implementation, published at a.well-known/jwksendpoint). - The protocol verifies three categories of information. Per Visa's developer overview: Agent Intent (confirming a Visa-trusted agent is seeking product details or a purchase), Consumer Recognition (identifying an existing customer account, using merchant tokens, device identifiers, location parameters, or wallet addresses), and Payment Information (supporting key-entry with hashed credentials, API/protocol-based transfers, or IOU-style management).
- Signatures are short-lived and tagged by interaction type. The specification defines two required signature tags —
agent-browser-authfor browsing/product-lookup interactions andagent-payer-authfor completing a purchase — and requires signatures to include@authority,@path,created,expires,keyid,alg,nonce, andtagfields, with a validation window of 8 minutes between signature creation and expiration, per Visa's specification page. - Cloudflare is named as the core development partner, with early partners including Adyen, Ant International, Checkout.com, Coinbase, CyberSource, Elavon, Fiserv, Microsoft, Nuvei, Shopify, Stripe, and Worldpay, per Visa's press release. Visa's Chief Product & Strategy Officer Jack Forestell stated: "We've worked closely with sellers, issuers and partners to make sure agent-initiated transactions are as seamless and secure as any payment today."
- Availability is described as in-progress, not fully live everywhere. Visa's developer documentation lists merchants and independent developers as the intended users, availability spanning North America, Asia-Pacific, Europe, CEMEA, and LAC, and states the protocol is "in the process of development and deployment," with materials and specifications available on the Visa Developer Center and GitHub.
How it works
- An AI shopping agent that has been onboarded to a Payment Scheme (such as Visa) generates a cryptographic key pair, with the public key published to a trusted key store.
- When the agent browses a merchant's site to check product details, inventory, or pricing, it signs its HTTP request using the
agent-browser-authtag, per Visa's specification. - The merchant's server retrieves the agent's public key from the trusted key store (matching by
keyidand algorithm) and verifies the signature, confirming the request is from a Visa-trusted agent rather than an anonymous bot. - When the agent proceeds to complete a purchase, it signs a new request using the
agent-payer-authtag, which can include Consumer Recognition data (to identify a returning customer) and Payment Information (supporting several settlement approaches). - The merchant verifies this second signature the same way, and — because both signature types embed
created/expirestimestamps with an 8-minute validity window and a single-usenonce— a captured signature cannot be replayed later to impersonate the agent. - Once verified, the merchant can treat the agent as legitimate for that interaction and proceed with the transaction under Visa Intelligent Commerce, rather than blocking it as suspected bot traffic.
Visa Trusted Agent Protocol vs. Mastercard Agent Pay vs. AP2
| Visa Trusted Agent Protocol | Mastercard Agent Pay | AP2 | |
|---|---|---|---|
| Announced | October 14, 2025 | April 29, 2025 | September 16, 2025 |
| Primary purpose | Merchant-side cryptographic verification that a request is from a legitimate agent | Issuing agent-scoped, permissioned payment tokens ("Agentic Tokens") | Cryptographically signed mandates proving a user authorized a transaction |
| Core mechanism | HTTP Message Signatures (RFC 9421), asymmetric key pairs | Tokenization extending existing mobile/card-on-file tokenization | Verifiable Digital Credentials (Open/Closed Payment Mandates) |
| Named technical partner | Cloudflare | Microsoft, IBM, Braintree, Checkout.com | Ecosystem of 60+ launch partners incl. card networks |
| Card-network specific | Yes — Visa | Yes — Mastercard | No — rail-agnostic |
| Governance | Visa | Mastercard | Donated to FIDO Alliance (April 28, 2026) |
FAQ
What problem does the Visa Trusted Agent Protocol solve? It lets merchants tell the difference between a legitimate, Visa-recognized AI shopping agent and an anonymous bot, using cryptographic signatures rather than behavioral guesswork alone, per Visa's press release.
Is Trusted Agent Protocol the same as Visa Intelligent Commerce? No. Visa Intelligent Commerce is Visa's broader program for enabling AI-driven payments; Trusted Agent Protocol is a specific verification mechanism that reinforces it, per Visa's developer documentation.
What cryptographic standard does it use? HTTP Message Signatures compliant with RFC 9421, aligned with the web-bot-auth standard, using asymmetric key pairs, per Visa's specification page.
Does the protocol include spending limits for the agent? Not specified in the primary sources reviewed for this article. The protocol as documented focuses on verifying agent identity and intent (browsing vs. paying); it does not describe a consumer-facing spending-cap feature.
Who built it with Visa? Cloudflare is named as the core development collaborator, with early partners including Adyen, Ant International, Checkout.com, Coinbase, CyberSource, Elavon, Fiserv, Microsoft, Nuvei, Shopify, Stripe, and Worldpay, per Visa's press release.
Is the protocol fully deployed today? Visa's own developer documentation describes it as "in the process of development and deployment" across North America, Asia-Pacific, Europe, CEMEA, and LAC, rather than universally live.






