What the Trusted Agent Protocol is
Stores see more and more automated traffic and cannot tell from it who they are dealing with: a real shopper’s agent or a scraper. The Trusted Agent Protocol (TAP) is Visa’s answer to that problem. It was introduced on 14 October 2025, developed together with Cloudflare, and extends the Visa Intelligent Commerce programme (see agent payment networks for more on it). An agent registered with Visa signs its requests, and the store verifies the signature and decides whether to let it through to the catalogue and the checkout.
How the signature works
TAP is built on HTTP Message Signatures (RFC 9421) and aligned with Web Bot Auth. According to Visa’s specification, the signature is made up as follows:
| Element | What it does |
|---|---|
Signature-Input and Signature headers |
The signature metadata and the signature itself |
tag |
agent-browser-auth when the agent views product pages; agent-payer-auth when it checks out and pays |
@authority, @path |
Bind the signature to the store’s domain and the specific page |
created, expires |
The validity window, no more than 8 minutes |
nonce |
A session identifier that prevents the signature being reused |
keyid, alg |
The key in Visa’s directory (mcp.visa.com/.well-known/jwks) and the algorithm, such as Ed25519 or PS256 |
What the agent passes to the store
Visa describes three kinds of data. Intent — the agent is trusted and wants to retrieve details of a specific product or buy it. Consumer recognition — signals that the person already has an account with the store or has interacted with it before. Payment information — optionally, the agent carries payment data to support the payment method the store prefers.
Where TAP sits in the agent stack
TAP does not place orders. It answers the question of who has arrived, while other protocols run the transaction:
- Trust: TAP, Mastercard Agent Pay, Web Bot Auth — all rely on request signatures.
- Ordering: ACP, UCP — basket and checkout.
- Payment: card networks’ agent tokens, x402.
Important: TAP identifies agents that Visa has registered. Agents from other operators are verified against their own key directories, so TAP is best treated as one part of a wider Know Your Agent practice rather than the only filter.
Practical steps for a store
- Find out whether your CDN or WAF can verify TAP signatures — cheaper than building the check yourself.
- Verify not only the signature but also the domain and path match, the time window and that the nonce is single-use.
- Keep separate rules for
agent-browser-authandagent-payer-auth: browsing can be opened more widely, checkout more strictly. - Do not show a signed agent a CAPTCHA on the way to payment: it will fail, and the order goes to a competitor.
- Log the keyid and the signature tag together with the order.