The problem Verifiable Intent solves
In an ordinary online purchase, intent is obvious: the person presses “Pay” themselves. When the purchase is delegated to an AI agent that moment disappears, and no party to the transaction can check that the agent carried out the user’s wishes rather than picking the wrong product or overspending.
| Ordinary purchase | Purchase via an agent | |
|---|---|---|
| Identity | Proves who you are | Proves who you are and who authorised the agent |
| Consent | Given at the moment of payment | Given in advance, before the agent acts |
| Scope | One transaction | Many purchases from different merchants over days or weeks |
| Signals for the store | 3-D Secure, fraud scoring | New ones needed: the agent’s authority, its limits, who granted it |
How the chain of trust works
VI consists of three layers of signed credentials, each cryptographically constraining the next:
- Identity. The credential provider signs the user’s details and binds the key of the user’s device; the credential lives for about a year.
- Intent. The user signs the constraints: the amount range, approved merchants and payees, the permitted basket items.
- Action. The agent signs the outcome: the payment for the payment network and, separately, the checkout for the merchant; this layer lives for about five minutes.
The specification has two modes. In Immediate mode the user confirms the final basket and amount themselves, and two layers are enough. In Autonomous mode the user sets the limits and the agent buys on its own, which requires the third layer. Selective disclosure ensures that the merchant sees the basket and the payment network sees the payment, but not the other way round.
Where it sits among agent protocols
VI does not handle transport or place orders — its credentials travel inside existing protocols. For AP2 it provides a concrete format for the verifiable credentials that AP2 only describes architecturally. In UCP VI data can travel in the fields of the AP2 mandates extension, and in ACP through the protocol’s extension mechanism. A payment mandate says what is allowed; VI proves the agent stayed within those limits.
What it means for a store
- Disputes and chargebacks. The store gets evidence that the agent’s purchase was authorised — evidence shared with the issuer and the payment network.
- When to ask for confirmation. VI data helps decide when an autonomous purchase needs extra consent from the shopper.
- Privacy. The store receives only the basket data, with no unnecessary payment details.
- What to do now. Ask your PSP about support for VI and for card network agent programmes, and check that your checkout records the order contents unambiguously.