Visa, Mastercard Launch Agent Trust Protocols — But Key Verification Gaps Remain
Visa has introduced its Trusted Agent Protocol (TAP), an open-spec framework where every agent request carries a cryptographic signature with a timestamp, session ID, and key identifier bound to a specific merchant domain and operation. Mastercard followed with Verifiable Intent (VI), enabling merchants to verify signed intent credentials in real time within the authorization flow before any funds move. Both initiatives are part of a broader industry convergence that also includes Coinbase's x402 protocol and the AP2 coalition involving Google, Visa, Mastercard, PayPal, and around 60 partners. However, critics note that neither protocol allows external parties to audit the verifier logic, reproduce credentials from public bytes, or access an immutable third-party log proving what was published and when. Proposed complementary approaches, such as offline-verifiable attestation using Ed25519 checks and Sigstore's Rekor transparency log, aim to fill these gaps without requiring network membership or API keys.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in