Skip to main content
Agent tokens let an agent pay from a budget the card owner approved once, instead of asking for approval on every purchase. The owner creates a mandate (amd_*) on the dashboard for one of their saved cards. A mandate is a budget for one agent: a total amount, a per-purchase limit and an expiry. For each purchase, the agent claims a tokenized card issued against the mandate. It isn’t the saved card’s number, so the agent stays out of PCI scope. Agent tokens are for agents: call them with an agent key and the X-Instance-ID header. Support for Natural-issued cards is coming soon.

Flow

  1. Get approved. The owner creates a mandate for the agent on the dashboard and verifies it with their card issuer.
  2. Find a mandate. GET /agentic-payments/mandates lists the agent’s mandates. Use one with status active and enough available budget.
  3. Create a purchase. POST /agentic-payments/purchases with the mandateId, the amount, the merchant (name, https URL and country code) and a ttlSeconds of 60 to 600. This reserves the amount from the mandate. Send an Idempotency-Key, and retry with the same key.
  4. Claim. POST /agentic-payments/purchases/{purchaseId}/claim returns the card number, expiry and CVC for this purchase. It succeeds once; the credential can’t be fetched again. Don’t log or store it.
  5. Check out. Enter the card details in the merchant’s checkout before expiresAt.
If the agent won’t check out, cancel the purchase before claiming it to release the reserved budget. A claimed purchase still counts against the mandate, even if no order was placed.

Limits

  • A purchase covers one checkout. For another checkout, create a new purchase.
  • amount can’t exceed the mandate’s perPurchaseLimit or its available budget. Amounts are in USD minor units.
  • The credential stops working at expiresAt, or when the mandate expires or is revoked, whichever comes first.