What is Mastercard Agent Pay?
Mastercard announced its Agentic Payments Program, Mastercard Agent Pay, on April 29, 2025, and said it would work with Microsoft first, with other AI platforms to follow. The idea is narrow and worth stating precisely: a registered, verified AI agent is allowed to present a card credential on a consumer’s behalf, and the merchant, the issuer and the network all get a way to tell that agent apart from a bot scraping a checkout page. Mastercard’s own product page puts the condition plainly, that only registered agents can transact, governed and traceable with Mastercard network tokens. Everything else in the program hangs off that one requirement.
How does Mastercard agent pay work?
A consumer’s card is tokenized, and the token is bound to a named agent rather than to a device or a merchant file. When that agent reaches a checkout, it presents the Agentic Token instead of a card number. The merchant’s acquirer passes it through the same authorization and settlement path a normal card-not-present transaction takes, which is the entire point: no new rail, no new acquirer, no separate reconciliation. Mastercard’s framing is that the agent is a new kind of credential holder, not a new kind of payment. That design choice is why adoption can move quickly on the acceptance side and why it inherits every limitation of a card authorization at the same time.
What are Mastercard Agentic Tokens?
An Agentic Token is a Mastercard network token carrying extra fields that bind it to one named AI agent and one consent policy. It is built on the same tokenization plumbing that already runs mobile contactless payments, secure card-on-file and Mastercard Payment Passkeys, which is the reason Mastercard could ship it fast rather than inventing a credential format from scratch. The properties that matter operationally are that these tokens are network-issued, time-scoped and revocable, and that scoping is per agent. If one person runs a shopping agent in Copilot and a second custom agent of their own, those are two tokens with two policies, and revoking one does nothing to the other. We cover the mechanics in more depth in agentic tokens explained.
What is the Mastercard Agent Pay Acceptance Framework?
This is the piece almost no coverage mentions, and for a merchant it is the piece that decides whether any of this reaches you. The Acceptance Framework is the merchant-side half of Agent Pay: a set of technical and governance standards for letting an agent-initiated purchase through the existing card system, including a way to judge whether an agent is authorized to act for a user and whether the transaction sits inside pre-agreed parameters. In January 2026 Fiserv said it would integrate the framework across its merchant acceptance infrastructure, including Clover, and act as a network token requestor for merchants and partners. The practical claim is that merchants on that infrastructure can accept agent-initiated payments without changing their checkout or their back end.
What is Mastercard Verifiable Intent?
On March 5, 2026 Mastercard introduced Verifiable Intent, built with Google, as an open, standards-based trust layer for agentic commerce. It creates a tamper-resistant record linking three things into one privacy-preserving object: the identity of the cardholder who authorized the agent, that person’s specific instructions, and the interaction between agent and merchant that produced the purchase. It is aligned with Google’s AP2 and UCP but deliberately protocol agnostic, and it is built on existing specifications from the FIDO Alliance, EMVCo, the IETF and the W3C. Privacy is handled with Selective Disclosure, defined in RFC 9901, so no single party in the chain sees the whole profile. Mastercard open sourced the specification and a reference implementation at verifiableintent.dev. Note the sequencing, because it is routinely reported wrong: at announcement Verifiable Intent was not yet inside Agent Pay. Mastercard said it would be integrated into Agent Pay’s intent APIs in the coming months.
Why did Mastercard donate Verifiable Intent to the FIDO Alliance?
On April 28, 2026 the FIDO Alliance announced an Agentic Authentication Technical Working Group, with Mastercard contributing Verifiable Intent and Google contributing AP2 on the same day. The group is chaired by CVS Health, Google and OpenAI, with Amazon, Google and Okta as vice-chairs. Pablo Fourez, Mastercard’s chief digital officer, framed the reason as making user intent explicit, verifiable and trusted before agent-initiated commerce can scale. The strategic read is more interesting than the press-release read. A card network handing its trust spec to a neutral standards body, alongside its largest platform rival, is an admission that no single network can own agent identity, because the agent will shop across all of them.
What is Mastercard Agent Pay for Machines?
Announced June 10, 2026, Agent Pay for Machines extends the program past consumer shopping into machine-to-machine payments, letting agents and connected devices transact autonomously across cards, bank accounts and regulated stablecoins. Jorn Lambert, Mastercard’s chief product officer, described the target as very high volumes at very small values, very fast and at extremely low latency. That combination is exactly why stablecoin settlement appears here at all: card economics stop working below a certain ticket size, so a network that wants sub-cent machine payments has to settle some of them somewhere other than the card rail. This is the same architectural fork Stripe hit with its own machine payments track, and it is covered further in Mastercard Agent Pay for Machines.
Who are the Mastercard Agent Pay partners?
Mastercard named more than thirty initial participants for Agent Pay for Machines, and the list is a fair map of the agent-payments industry: Aave Labs, Adyen, Alchemy, Anchorage Digital, Ant International, Basis Theory, BVNK, Catena, Checkout.com, Cloudflare, Coinbase, Coinflow, Crossmint, Getnet by Santander, Global Payments, Lovable, Mastercard Merchant Cloud, MoonPay, Nevermined, OKX, PayOS, Polygon, Rain, Ripple, Sapiom, Skyfire, Solana Foundation, Stripe, t54 Labs, Tempo, Turnkey and Utila. On the consumer side, the original April 2025 announcement led with Microsoft. Worth noting that Crossmint described its own role as PSP of the agent, which tells you the network is not trying to occupy every layer itself.
Is there a Mastercard Agent Pay API?
Yes, though it is gated rather than openly self-serve, and it is reached differently depending on which side of the transaction you sit. Issuers and agent platforms work through Mastercard Developers and the Agent Pay program itself, including the intent APIs that Verifiable Intent is being folded into. Merchants generally do not integrate directly at all: they inherit acceptance through an acquirer or processor that has adopted the Acceptance Framework, which is precisely what the Fiserv arrangement is for. If you are a developer looking for the open, readable artifact, the Verifiable Intent specification and reference implementation are the parts Mastercard has actually published in the open.
Is Mastercard agentic commerce live yet, or still a pilot?
It is real, it is running, and it is early. The credential format, the acceptance standards and the machine-payments extension have all been announced with named partners rather than as concepts, and a processor the size of Fiserv committing its acceptance stack is a stronger signal than partner counts. What Mastercard has not published is volume. There is no disclosed transaction count for Agent Pay, and no published pricing for Agent Pay for Machines. Treat anyone quoting a rate card for either as guessing. The honest summary is that acceptance is arriving faster than demand, which is the normal order for a card network and the opposite of how the coverage reads.
Mastercard Agent Pay versus Visa Intelligent Commerce
The two programs rhyme more than they differ. Both networks concluded that the credential, not the checkout, is where agentic commerce needed fixing, and both shipped a scoped, revocable, tokenized credential plus an identity layer for proving an agent is legitimate. The differences are in emphasis and sequencing rather than architecture. We keep the detailed side-by-side on a dedicated page, Visa Intelligent Commerce vs Mastercard Agent Pay, and a full breakdown of the Visa side at Visa Intelligent Commerce. The operationally important point for a business is that you do not get to pick one. If your agents buy across the open web they will touch both networks, plus x402 and stablecoin rails that belong to neither.
What Mastercard Agent Pay does not do
Everything Mastercard has built here points at a single transaction and at the question of whether it was authorized. Agentic Tokens answer whether this agent may use this instrument. Verifiable Intent answers whether this purchase reflects what the human asked for. The Acceptance Framework answers whether a merchant should trust the request. All three are genuinely useful, and none of them is a budget. Nothing in the stack tracks cumulative spend across transactions, which means an agent can make two hundred individually valid, individually tokenized, individually intent-verified purchases and still destroy a monthly budget without a single rule firing. The same structural gap exists in AP2, and it is not an oversight in either case. Networks authorize transactions one at a time, because that is what a network is for.
Where a control plane fits alongside Mastercard Agent Pay
None of this is an argument against Agent Pay. If your agents pay by card, you want the tokenization and you want the intent proof. The gap is above the transaction, and it is where governance lives. That means a running budget an agent cannot exceed no matter how many valid authorizations it strings together, a human approval step above a threshold you choose, scoped virtual cards per vendor or per task, an immutable audit trail that survives the vendor relationship, and one spend policy that applies identically whether a given purchase settled over Mastercard, over Visa, or over a stablecoin rail. A network can only govern its own rail. A business runs on all of them at once, which is the whole reason a rail-neutral layer exists. If you are evaluating that layer specifically against this program, we keep an honest comparison at Mastercard Agent Pay alternative.
What to watch next
Three things are worth tracking. First, whether Verifiable Intent actually lands inside Agent Pay’s intent APIs as promised, since the March 2026 announcement described it as forthcoming and a spec donated to a standards body can drift from a spec shipped in a product. Second, whether the FIDO working group produces something Visa also implements, because a shared agent-identity standard across both networks would matter far more than either program alone. Third, whether Agent Pay for Machines publishes pricing, since sub-cent machine payments are an economics claim before they are a technology claim, and nobody can model them against a blank rate card.