Sign in

Agent Mandate: What It Is in 2026

An Agent Mandate is a digitally signed authorization a consumer issues to an AI agent that defines exactly what the agent can spend on, with what limits, and for how long.

Last updated: 2026-05-04

What Is an Agent Mandate?

An Agent Mandate is the cryptographic primitive at the heart of agentic commerce trust. It answers a simple question with auditable certainty: did the consumer actually authorize this AI agent to do this specific thing?

The Mandate concept was popularized by Google's Agent Payments Protocol (AP2) launch in September 2025 but the pattern is now used across multiple agentic commerce protocols including Visa TAP, Mastercard Agent Pay, and UCP.

A typical Mandate scopes:

  • Amount caps. Maximum per-transaction and aggregate spend.
  • Merchants or payees. Which merchants a checkout may use or which payees may receive a payment.
  • Time window. When the authorization is valid (single-use, recurring within a window, expiry date).
  • Frequency. One-shot vs recurring vs unlimited within scope.
  • Required confirmations. What thresholds require fresh consumer approval.

The Mandate is signed by the consumer (typically through their wallet, bank app, or payment provider) and travels with the transaction so merchants and payment networks can verify it cryptographically.

How an Agent Mandate Works

The consumer signs a Mandate scoping the agent's authority. The agent presents the Mandate at transaction time. The merchant or payment network verifies the transaction is in-scope before clearing.

Three flows define how Mandates operate:

1. Mandate creation. The consumer creates and signs a Mandate through a trusted source (their issuing bank, payment provider, or wallet). The Mandate is cryptographically tied to the consumer's payment credentials but does not expose them to the agent. Modern implementations support biometric signing (Face ID, fingerprint) for low-friction creation.

2. Mandate presentation. When the agent is ready to transact (e.g., after the consumer has selected a product through a UCP or ACP shopping flow), it presents the Mandate alongside the transaction request. The Mandate travels with the payload.

3. Mandate verification. AP2 assigns verification by role. The Merchant verifies the Checkout Mandate, credential providers and applicable networks verify the Payment Mandate, and the merchant payment processor verifies that the payment credential is scoped to the checkout. A role may delegate its checks to a technology provider, which then follows that role's verification rules.

The pattern is the same across protocols even when implementation details differ. AP2 specifies an open Mandate format. Visa TAP and Mastercard Agent Pay use Mandate-style primitives integrated with their tokenization frameworks.

Why Agent Mandates Matter

Mandates make agent transactions auditable. They give merchants chargeback defense, give networks fraud signals, and give consumers fine-grained control without giving up payment credentials.

Without Mandates, AI agents shopping on a consumer's behalf operate in a trust vacuum. The merchant doesn't know if the agent had authorization. The network doesn't know if the spend is in-scope. The consumer doesn't have an audit trail. Disputes default to whoever speaks loudest.

Mandates change that pattern at three layers:

  1. Consumer. Fine-grained, time-bounded control over what the agent can do. AP2 v0.2 supports expiration and constraints, but does not yet define a normative dynamic revocation mechanism.
  2. Merchant. Auditable evidence of consumer authorization. Disputes have a cryptographic record. Higher-value agent transactions become safe to accept.
  3. Network. Real-time fraud signals. A transaction that doesn't match its Mandate is denied at network authorization time, before it reaches the merchant. Mismatch patterns feed cross-network agent-fraud detection.

The Mandate is what unlocks transaction sizes beyond the small-amount cap that networks otherwise impose on agent payments. Without it, agent commerce is stuck at low-trust micro-purchases. With it, recurring orders, subscriptions, replenishment, and high-cart agent purchases all become safe to clear.

FAQ

What is an Agent Mandate?+
An Agent Mandate is a digitally signed statement that defines what an AI agent is authorized to do, including amount limits, allowed merchants or payees, items, time windows, and recurrence. In AP2, each receiving role verifies the mandate relevant to its responsibility.
Who issues Agent Mandates?+
The consumer, typically through a trusted source like their issuing bank, payment provider, or wallet. The Mandate is cryptographically tied to the consumer's payment credentials but does not expose them to the agent. Modern implementations support biometric signing (Face ID, fingerprint).
Which protocols use Mandates?+
The pattern was popularized by Google's AP2 (Agent Payments Protocol) in September 2025 and is now used across AP2, Visa TAP, Mastercard Agent Pay, and UCP. Each protocol may have implementation differences but the underlying Mandate primitive - signed scope-defining authorization - is shared.
Can a consumer revoke a Mandate?+
AP2 v0.2 supports expiration and constraints and recommends short expirations for autonomous mandates. It does not currently specify a normative dynamic revocation mechanism, so implementations should not assume revocation interoperability unless another applicable system defines it.
Why do retailers care about Mandates?+
Mandates give retailers chargeback defense and unlock higher-value agent transactions safely. Without strong agent authorization, networks throttle agent transactions to small amounts. Mandates make recurring agent purchases (subscriptions, replenishment, restocking) safe to clear at higher value bands without losing dispute coverage.

Related terms

How AI-ready are your products?

Evaluate one product URL for AI readiness and review a structured report across mapping, attributes, product context, and attribute context.

Run free report →