How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Verifiable Intent

Verifiable Intent is an open specification for cryptographic agent authorization in commerce, introduced by Mastercard with Google on 5 March 2026. It binds a consumer’s identity, their instructions to an AI agent, and the outcome of the transaction into one tamper-evident record using an SD-JWT delegation chain linking issuer, user and agent, with machine-verifiable constraints such as amount limits, merchant allowlists, budget caps and recurrence rules, and selective disclosure so each party sees only what it needs. It is protocol agnostic, with mappings for AP2, ACP and UCP, and is published under Apache 2.0.

Verifiable Intent answers a different question than card authentication has always asked. Not “are you the cardholder?” but “did the cardholder authorize this agent to do this?” It turns that delegation into a cryptographic chain anyone in the transaction can check, and can hold up later if there is a dispute.

  • SD-JWT delegation chain - Layered credentials link issuer, user and agent through key confirmation.
  • Machine-verifiable constraints - Eight constraint types, including amount limits, merchant allowlists, budget caps and recurrence rules.
  • Selective disclosure - Each party sees only the part of the intent it needs.
  • Consent separate from action - The approval and the purchase can happen at different times, which is how agents actually work.
  • Protocol agnostic - Mappings for Google’s AP2, ACP and UCP rather than a new payment protocol.

Verifiable Intent is company-originated but openly licensed, and EMVCo’s 2026 agentic payments framework names it directly as the kind of cryptographic assurance its Intent Services layer is meant to complement. That pairing — one portable proof of intent, one shared place to keep intent state — is the shape the card side of agentic commerce is taking.

Industry: Payments

Related standards

Standards this one builds on, supersedes, profiles or is commonly deployed beside.

EMV Agentic Payments Framework

EMVCo positions Intent Services as complementing Verifiable Intent's cryptographic assurance.

JSON Web Token

The token format SD-JWT extends with selective disclosure.