SShortSingh.
Back to feed

How One Firm Is Locking AI Agent Payments to Buyer-Approved Offers Only

0
·1 views

Brand Design has developed a five-step business-to-agent (B2A) commerce flow designed to ensure AI agents cannot process payments beyond what a buyer has explicitly authorised. The system uses hashed offer records, versioned terms, and a separate buyer-authorised payment capability to prevent manipulation — such as a supplier page injecting unauthorised fees into a transaction. Each purchase step is verified against recorded state rather than the AI model's own interpretation of a page, closing a key vector for prompt-injection-style fraud. The approach aligns with principles published on 22 September by six major banks, including Bank of America and NatWest, on trusted agentic commerce, as well as W3C and GS1 discussions on agent identity and payment credentials. The firm has also deployed adapters for the ACP and UCP protocols, while noting that platform-level constraints — such as ChatGPT's Instant Checkout being restricted to approved partners — remain a practical consideration.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

CodePic lets developers create clean code screenshots entirely offline in browser

A developer has released CodePic, a free, open-source tool for generating polished code screenshots without any backend or data uploads. Built with Svelte 5, the browser-based app auto-detects programming languages, offers five syntax themes, and supports PNG and SVG exports at multiple resolutions. All highlighting, layout rendering, and file export happen locally in the user's browser, meaning code is never transmitted to a server. The tool also works offline after a single visit and can be installed as a standalone app. A companion command-line utility allows users to generate matching images directly from the terminal without opening a browser.

0
ProgrammingDEV Community ·

Umami, Plausible, or PostHog: A Practical Guide to Self-Hosted Analytics Costs

A hands-on comparison of three popular self-hosted analytics tools — Umami, Plausible, and PostHog — reveals that infrastructure costs and complexity vary significantly depending on use case. Umami is the lightest option, running on a single small VPS with Postgres, but offers only basic pageview and referrer reporting. Plausible adds goal and funnel tracking but requires running a ClickHouse instance alongside Postgres, a resource overhead many users underestimate. PostHog delivers advanced features like session replay, feature flags, and cohort analysis, but its multi-component stack makes it unsuitable for small-server deployments. The core advice is to choose a tool based on the analytical questions your team actually needs to answer, rather than the appeal of its dashboard screenshots.

0
ProgrammingDEV Community ·

What AI Agents Are and How They Differ From Traditional Chatbots

AI agents are software systems that use large language models to understand goals, select appropriate tools, take actions, and iterate until a task is completed — going beyond simple text generation. Unlike traditional chatbots that lack access to external systems, agents can call APIs, retrieve data, and reason across multiple steps autonomously. A key distinction is that the AI model handles reasoning and language, while the surrounding application manages access to databases, business tools, and security controls. However, experts caution that production-ready agentic systems must operate within defined boundaries, including permissions, cost controls, and human oversight. The concept represents a shift in software design — from explicitly programmed step-by-step instructions to goal-oriented systems that determine their own path to completion.

0
ProgrammingDEV Community ·

How to Build a Salesforce Copilot Agent in Microsoft Teams in 20 Minutes

Developers can set up a read-only Microsoft Copilot Studio agent that connects to Salesforce and answers plain-English questions by auto-generating and running SOQL queries. The agent returns structured data, such as quote line items and margin figures, directly within Microsoft Teams. A key technical challenge involves Salesforce CPQ's managed package field names, which use the SBQQ__ prefix and do not match their display labels, causing the agent to guess incorrectly if not properly instructed. Placing the correct field names in the agent's Instructions box — rather than the tool's description field — reduced tool calls per query from four to six down to just one. The setup takes roughly 20 minutes and uses a single 'Execute a SOQL query' tool, keeping the agent strictly read-only.