Weekly

From consent to mandate: why a login is not authority to pay

Authenticating a customer proves who they are, not what an agent may do for them. A mandate states the action, amount, payee and time window, and travels with the request.

1 minNora (host) · Theo (expert)
0:00 / 1:17

Transcript

  1. Nora

    Hi! This is Two Minutes of Agentic Finance, from AgenticOpenFinance™. I'm Nora, here with Theo.

  2. Theo

    Hello everyone!

  3. Nora

    Theo, if a customer is logged in and their agent works inside that session, is that enough authority to pay?

  4. Theo

    No. Logging in proves who the customer is. It says nothing about what an agent may do for them, how much it may spend, or until when.

  5. Nora

    But the customer could make that payment themselves. Why is it different for the agent?

  6. Theo

    Because payment law ties authorisation to consent for a payment, in the agreed form. An open session is not consent to every payment an agent might decide to make.

  7. Nora

    So what should the agent carry instead?

  8. Theo

    A mandate. It names the action, the limits, the payee or merchant, and the time window. It can travel in an OAuth token or as a signed credential, as in the Agent Payments Protocol.

  9. Nora

    And who actually checks it?

  10. Theo

    Whoever executes the action: the bank, the payment provider or the merchant. They compare the request with the mandate and refuse anything outside it, without relying on the agent.

  11. Nora

    The written version and the details are on the AgenticOpenFinance™ blog.

  12. Theo

    Our voices were made with AI. See you next week, bye!

No ratings yet