Skip to main content
Agents can’t handle a real card number (PAN) without coming into PCI scope. Agent checkout lets an agent pay with a user’s card while it only ever sees a credential that’s limited to one purchase. Pick a method by how the user approves spending and how the merchant takes the card: Browser tokens and agent tokens are for agents: call them with an agent key and the X-Instance-ID header.

Choose a method

Use browser tokens by default, and switch to agent tokens when a browser token can’t complete the checkout. Browser tokens work at most checkouts, and the owner doesn’t need to create a mandate on the dashboard first. Whether the user is needed depends on the card:
  • Saved cards: the user approves every purchase and types the card’s security code (CVV) each time. Only use a browser token when the user can respond during checkout.
  • Natural-issued cards (coming soon): no approval step for each purchase.
Agent tokens need a mandate the owner created and verified with their card issuer on the dashboard. Once it’s active, the agent can pay within the budget without the user. Use agent tokens when:
  • The checkout doesn’t send the raw card number. The proxy swaps in the real card only when the stand-in number appears in the checkout’s HTTP request. If the page encrypts or tokenizes the card in the browser first, such as inside a payment provider’s iframe, the swap can’t happen and a browser token can’t pay.
  • The user can’t approve each purchase while paying with a saved card.
If the agent has no active mandate, ask the owner to create one on the dashboard.