What Is an Agent Mandate?
An Agent Mandate is the cryptographic primitive at the heart of agentic commerce trust. It answers a simple question with auditable certainty: did the consumer actually authorize this AI agent to do this specific thing?
The Mandate concept was popularized by Google's Agent Payments Protocol (AP2) launch in September 2025 but the pattern is now used across multiple agentic commerce protocols including Visa TAP, Mastercard Agent Pay, and UCP.
A typical Mandate scopes:
- Amount caps. Maximum per-transaction and aggregate spend.
- Merchants or payees. Which merchants a checkout may use or which payees may receive a payment.
- Time window. When the authorization is valid (single-use, recurring within a window, expiry date).
- Frequency. One-shot vs recurring vs unlimited within scope.
- Required confirmations. What thresholds require fresh consumer approval.
The Mandate is signed by the consumer (typically through their wallet, bank app, or payment provider) and travels with the transaction so merchants and payment networks can verify it cryptographically.
How an Agent Mandate Works
The consumer signs a Mandate scoping the agent's authority. The agent presents the Mandate at transaction time. The merchant or payment network verifies the transaction is in-scope before clearing.
Three flows define how Mandates operate:
1. Mandate creation. The consumer creates and signs a Mandate through a trusted source (their issuing bank, payment provider, or wallet). The Mandate is cryptographically tied to the consumer's payment credentials but does not expose them to the agent. Modern implementations support biometric signing (Face ID, fingerprint) for low-friction creation.
2. Mandate presentation. When the agent is ready to transact (e.g., after the consumer has selected a product through a UCP or ACP shopping flow), it presents the Mandate alongside the transaction request. The Mandate travels with the payload.
3. Mandate verification. AP2 assigns verification by role. The Merchant verifies the Checkout Mandate, credential providers and applicable networks verify the Payment Mandate, and the merchant payment processor verifies that the payment credential is scoped to the checkout. A role may delegate its checks to a technology provider, which then follows that role's verification rules.
The pattern is the same across protocols even when implementation details differ. AP2 specifies an open Mandate format. Visa TAP and Mastercard Agent Pay use Mandate-style primitives integrated with their tokenization frameworks.
Why Agent Mandates Matter
Mandates make agent transactions auditable. They give merchants chargeback defense, give networks fraud signals, and give consumers fine-grained control without giving up payment credentials.
Without Mandates, AI agents shopping on a consumer's behalf operate in a trust vacuum. The merchant doesn't know if the agent had authorization. The network doesn't know if the spend is in-scope. The consumer doesn't have an audit trail. Disputes default to whoever speaks loudest.
Mandates change that pattern at three layers:
- Consumer. Fine-grained, time-bounded control over what the agent can do. AP2 v0.2 supports expiration and constraints, but does not yet define a normative dynamic revocation mechanism.
- Merchant. Auditable evidence of consumer authorization. Disputes have a cryptographic record. Higher-value agent transactions become safe to accept.
- Network. Real-time fraud signals. A transaction that doesn't match its Mandate is denied at network authorization time, before it reaches the merchant. Mismatch patterns feed cross-network agent-fraud detection.
The Mandate is what unlocks transaction sizes beyond the small-amount cap that networks otherwise impose on agent payments. Without it, agent commerce is stuck at low-trust micro-purchases. With it, recurring orders, subscriptions, replenishment, and high-cart agent purchases all become safe to clear.
FAQ
What is an Agent Mandate?+
Who issues Agent Mandates?+
Which protocols use Mandates?+
Can a consumer revoke a Mandate?+
Why do retailers care about Mandates?+
Related terms
Agent Payments Protocol (AP2): What It Is and How It Works
The Agent Payments Protocol (AP2) is an open-source protocol, created by Google and being donated to the FIDO Alliance, that defines how an AI agent obtains signed, verifiable authorization to initiate a payment on a consumer's behalf.
Visa Trusted Agent Protocol (TAP): 2026 Guide
Visa TAP is Visa's agent-payment authorization protocol that verifies AI agents at transaction time and lets them initiate payments on behalf of cardholders.
Mastercard Agent Pay: How It Works in 2026
Mastercard Agent Pay is Mastercard's agent-payment infrastructure that authenticates and authorizes AI-initiated transactions on the Mastercard network.
Universal Commerce Protocol (UCP)
UCP is an open standard by Google and Shopify that enables AI agents to handle the full commerce journey from discovery to post-purchase.
Agentic Commerce
Agentic commerce is the emerging category where AI agents autonomously discover, compare, and purchase products on behalf of consumers across platforms like ChatGPT, Google AI Mode, and Perplexity.
How AI-ready are your products?
Evaluate one product URL for AI readiness and review a structured report across mapping, attributes, product context, and attribute context.
Run free report →