amd_*) on the dashboard for one of their saved cards. A mandate is a budget for one agent: a total amount, a per-purchase limit and an expiry. For each purchase, the agent claims a tokenized card issued against the mandate. It isn’t the saved card’s number, so the agent stays out of PCI scope.
Agent tokens are for agents: call them with an agent key and the X-Instance-ID header. Support for Natural-issued cards is coming soon.
Flow
- Get approved. The owner creates a mandate for the agent on the dashboard and verifies it with their card issuer.
- Find a mandate.
GET /agentic-payments/mandateslists the agent’s mandates. Use one withstatusactiveand enoughavailablebudget. - Create a purchase.
POST /agentic-payments/purchaseswith themandateId, theamount, themerchant(name,httpsURL and country code) and attlSecondsof 60 to 600. This reserves the amount from the mandate. Send anIdempotency-Key, and retry with the same key. - Claim.
POST /agentic-payments/purchases/{purchaseId}/claimreturns the card number, expiry and CVC for this purchase. It succeeds once; the credential can’t be fetched again. Don’t log or store it. - Check out. Enter the card details in the merchant’s checkout before
expiresAt.
Limits
- A purchase covers one checkout. For another checkout, create a new purchase.
amountcan’t exceed the mandate’sperPurchaseLimitor itsavailablebudget. Amounts are in USD minor units.- The credential stops working at
expiresAt, or when the mandate expires or is revoked, whichever comes first.