Urgent.News

What's breaking now, across thousands of outlets.

Tech

The payment authorization pattern: giving an agent a wallet without giving it your bank account

§ 01 · Why this matters now Agent-initiated payments stopped being hypothetical this year. Protocols for autonomous agent transactions are shipping with real adoption, and industry alliances are forming specifically around agent-driven commerce. If your agent roadmap touches purchasing, subscriptions, refunds, or vendor payments, even narrowly, you need an authorization architecture before you…

This story explains a new approach to handling payments made by autonomous agents, such as virtual assistants or chatbots that can make purchases or manage subscriptions on behalf of users. The key idea is to separate the agent's ability to request payments from actually executing those payments, using a wallet or virtual card designed specifically for this purpose.

The naive method of giving an agent direct access to a real bank account or stored payment method is shown to be problematic. Because agents must interpret ambiguous instructions, they can mistakenly request payments that are larger, less frequent, or unauthorized than intended. A scope limit that restricts where the money can go does not prevent the agent from making errors in amount, frequency, or whether a human should have approved it first.

The recommended pattern involves three independent limits placed outside the agent's control: a hard ceiling on how much can be charged per transaction, a velocity limit capping the total amount spent per run, per day, or per vendor, and a human gate that automatically routes payments above a certain threshold to an approval queue rather than executing them. These limits ensure the agent can never request a payment that exceeds reasonable expectations.

Rather than connecting the agent to your main payment account, a dedicated "wallet" or virtual card is created with a pre-set maximum balance. This capped wallet becomes the only account the agent can transact with, limiting the potential financial damage if the agent is misconfigured or compromised.

All agent-initiated payments must be logged with detailed machine-readable records, including the instruction that authorized the payment, by whom (or by what AI system), and the approval status if it went through an approval queue. This reconciliation step is critical for auditing and correcting any errors that may arise weeks or months later.

The article concludes with a checklist to verify that these key safeguards have been implemented correctly before deploying an autonomous payment-enabled agent. The story emphasizes that building these payment controls is essential before developing the agent's use cases, to prevent the costly mistakes that can occur when the agent is allowed direct access to real money.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Why I Only Show One Weather Metric in the Chrome Toolbar

One of the weirdly difficult decisions I ran into while building SkyFeels was deciding what the toolbar icon should show. Temperature was obvious. Then I added AQI. Then UV.

  • Initially considered showing all three metrics (temperature, AQI, UV) simultaneously in toolbar
  • Realized small toolbar size and limited user attention made multi-metric display ineffective
  • Decided to show only one metric at a time, with others accessible upon clicking icon

Lagos Life maker Vatar raises $500,000 one week after launch

Vatar Inc., the company behind the viral Nigerian browser game Lagos Life, has closed a $500,000 pre-seed round at a $10 million valuation.

  • Vatar Inc. raises $500,000 pre-seed investment one week after launching Lagos Life game.
  • Game valued at $10 million post-investment, led by Flutterwave CEO Olugbenga GB Agboola.
  • Lagos Life game has 4.3 million users, with majority from US, UK, Ghana, Canada, and Netherlands.

More from Friday 9 October →