Session

Beyond the Transaction: Securing Intent, Identity and Trust in the Agentic Commerce Stack

AI agents are no longer just answering questions but acting on them. Autonomous agents are initiating real payments on real card rails, on behalf of real users. The commerce layer above those rails is fragmenting into at least four competing protocols (AP2, ACP, UCP, and the card networks' agent-aware tokenization). The hard question is not which protocol wins, but how you build a system that is safe regardless of which one, or combination, you speak.

This is my working architect's tour of the Agentic Commerce Stack: payment rails, AP2/ACP/UCP mandates, agent identity, merchant integration, and the seams between them. Where identity lives, where intent lives, where trust must be cryptographically proven, how liability flows.

From an independent security analysis of AP2, eight attack classes are understood. Three are universal across every protocol and framework: intent drift, mandate replay, and over-broad delegation. I frame all eight; I go deep on three.

The industry's response has converged on three frontiers, each mapping to one failure:
Cryptographic proof of intent (signed, scoped mandates) answers intent drift.
Decentralized agent identity (Know-Your-Agent registries, FIDO attestation) answers impersonation and over-broad delegation.
Accountable audit trails across buyer,agent,developer,merchant answer mandate replay and dispute.

I walk an end-to-end transaction for each: discovery, intent capture, delegation, authorization, settlement, dispute. Marking every place a control belongs. Halfway through, I leave the slides. The reference at github.com/phanipendurthi/ap2-jwt-security (Apache 2.0) demonstrates JWT mandate signing, replay defenses, intent-binding tests, and a runnable buyer-agent-merchant-network loop. I run it live, then break each defense.

AP2 and Verifiable Intent landed at FIDO in April 2026. ChatGPT Instant Checkout went live with Stripe in September 2025. Walmart × Google launched UCP at NRF 2026. Builders need a shared threat model fast.

Phani Pendurthi

Mastercard, Principal Software Engineer

Union, Missouri, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top