Autonomous Agent Payments - AgentPass

4 min read Original article โ†—

AgentPass -- Secure MCP for Regulated Finance. MCPS + Agent Identity for the Agent Economy. IETF Draft

๐Ÿ“„ NEW: Read the AgentPass Case Study โ€” Securing the $5 Trillion Agentic Economy โ†’

OPENAPI INITIATIVE ยท APPROVED EXTENSION

The security layer for AI agents in financial services.

Secure agent access for banking and payments. Verified identity. Signed responses. Sanctions screening. SOC 2 mapped. Integrated into moov-io/watchman.

MCPS -- Secure MCP built for regulated finance. Learn more โ†’

๐Ÿ›ก OFAC + HMT Sanctions (75K entries)

๐Ÿ“ฑ Mobile SDKs (iOS, Python, Node)

๐Ÿ”’ ECDSA P-256 Signed Payments

โš– L0-L4 Behavioural Trust Scoring

๐Ÿ” Challenge-Response Identity

๐Ÿ“‹ Hash-Chained Audit Trail

Integrated with:

moov-io/watchman

LIVE

SOC 2 Control Mapping

14 Trust Service Criteria mapped to AI agent operations. Submitted to AICPA, CSA, ISACA, and NIST. View mapping

McKinsey, October 2025

$3Tโ€“$5T in global agentic commerce value by 2030. Up to $1T of US retail revenue directed by AI agents. 75% of NRF 2026 retailers implementing agentic commerce.

๐Ÿ“ฑ iOS SDK for Mobile Agent Payments -- Live Now

Live Demo -- AgentPass iOS SDK

Standards & Compliance

Built on open standards. 10 IETF Internet-Drafts including ATTP (Agent Trust Transport Protocol) and MCPS. OWASP MCP Top 10 contributor. OpenAPI Extensions Registry entry. Submitted to EBA, FCA, and PCI SSC.

๐Ÿ”’

Signed Payments

Every transaction signed with ECDSA P-256. Non-repudiable receipts proving which agent authorised what.

๐Ÿ“Š

Trust Scoring

5-dimension behavioural trust score (0-100). Agents earn spending authority through proven behaviour.

๐Ÿ›ก

Spend Limits

Per-transaction and daily limits enforced by trust level. Agents cannot exceed their authority.

๐Ÿ”„

Replay Protection

Unique nonce per transaction. Captured payment requests cannot be re-sent.

๐Ÿ“‹

Audit Trail

Hash-chained tamper-evident log. JSON + RFC 5424 syslog. SIEM-ready.

โš 

Anomaly Detection

Magnitude, velocity, recipient, and timing anomalies detected. Trust automatically adjusts.

๐Ÿ›ก

OFAC + HMT Sanctions

75,784 sanctions entries screened on every payment. UK HMT (57K) + US OFAC SDN (18K). Sanctioned recipients blocked in real time.

๐Ÿ“ฑ

Mobile Payments

Native iOS SDK with Keychain-secured ECDSA keys. Python and Node.js SDKs for server-side. Agents pay from any platform.

๐ŸŒ

Agent Registry

DNS for agents. Register, resolve, and search agent identities. Anti-squatting protection. AgentSign-certified.

Deploy Your Way

Cloud or on-premise. Your compliance, your infrastructure.

โ˜

SaaS

Managed by us. Sign up, get an API key, start verifying agents in minutes. Zero infrastructure.

  • โœ“ Free sandbox with $10K test balance
  • โœ“ agentpass.co.uk API
  • โœ“ Automatic sanctions updates
  • โœ“ No ops required

New

๐Ÿข

Self-Hosted

Deploy in your own infrastructure. Docker image with everything included. Your data never leaves your network.

  • โœ“ Single Docker container
  • โœ“ Sanctions data baked in
  • โœ“ License key activation
  • โœ“ Full regulatory control

Contact us for access

Agent PKI

Built-in certificate authority for AI agents. Issue, revoke, and verify agent identity certificates with OCSP and CRL -- no external CA required.

๐Ÿ“œ

X.509 Agent Certificates

Issue short-lived identity certs with trust level, scopes, and issuer embedded. ECDSA P-256 signed.

๐Ÿ›ก

OCSP + CRL

Real-time certificate status checks. Instant revocation propagation. Verifiers query status before trusting any agent.

๐Ÿ”

HSM Key Storage

CA keys stored in AWS KMS, GCP Cloud KMS, Azure Key Vault, or HashiCorp Vault. Your keys never touch disk.

Issue

Agent creates cert on registration

Verify

Third parties verify cert + trust score

Revoke

Instant revocation with CRL + OCSP

Renew

Auto-renew or manual with new trust level

PKI API

GET/pki/caDownload CA certificatePublic
GET/pki/status/:serialOCSP certificate statusPublic
GET/pki/crlCertificate revocation listPublic
GET/pki/cert/:serialFetch certificate by serialPublic
POST/pki/verifyVerify a certificate PEMPublic
GET/pki/certsList your certificatesAuth
POST/pki/renew/:serialRenew certificateAuth
GET/pki/statsCA statisticsPublic

Available in Self-Hosted Pro and Enterprise tiers. Every agent created automatically receives an X.509 certificate.

AgentPass Self-Hosted

Docker container with license key. Deploy in minutes. Your infrastructure, your control.

Starter

10

agents

  • Built-in CA
  • Trust levels L0-L4
  • Scope enforcement
  • Sanctions screening
  • Agent dashboard
  • Signed audit trail

Get Starter

Pro

50

agents

  • Everything in Starter
  • Priority support
  • Custom CA subject
  • CRL distribution
  • Integration support

Get Pro

Enterprise

โˆž

unlimited agents

  • Everything in Pro
  • Unlimited agents
  • KMS integration
  • AEBA monitoring
  • Dedicated support
  • Custom trust models

Contact Us

Trust Levels

LevelScorePer TransactionDaily LimitUse Case
L00-19$0$0No financial access
L120-39$10$50Micro-payments
L240-59$100$500Standard transactions
L360-79$1,000$5,000Enterprise purchasing
L480-100$50,000$200,000Full access (audited)