---
title: "From consent to mandate: why a login is not authority to pay"
type: podcast episode 1
published: 2026-10-05T06:00:00.000Z
url: https://agenticopenfinance.com/podcasts/week-2026-10-05
audio: https://agenticopenfinance.com/podcasts/audio/week-2026-10-05.mp3
voices: synthetic (AI-generated speech)
---

# From consent to mandate: why a login is not authority to pay

> Authenticating a customer proves who they are, not what an agent may do for them. A mandate states the action, amount, payee and time window, and travels with the request.

## Transcript

**Nora:** Hi! This is Two Minutes of Agentic Finance, from AgenticOpenFinance™. I'm Nora, here with Theo.

**Theo:** Hello everyone!

**Nora:** Theo, if a customer is logged in and their agent works inside that session, is that enough authority to pay?

**Theo:** No. Logging in proves who the customer is. It says nothing about what an agent may do for them, how much it may spend, or until when.

**Nora:** But the customer could make that payment themselves. Why is it different for the agent?

**Theo:** Because payment law ties authorisation to consent for a payment, in the agreed form. An open session is not consent to every payment an agent might decide to make.

**Nora:** So what should the agent carry instead?

**Theo:** A mandate. It names the action, the limits, the payee or merchant, and the time window. It can travel in an OAuth token or as a signed credential, as in the Agent Payments Protocol.

**Nora:** And who actually checks it?

**Theo:** Whoever executes the action: the bank, the payment provider or the merchant. They compare the request with the mandate and refuse anything outside it, without relying on the agent.

**Nora:** The written version and the details are on the AgenticOpenFinance™ blog.

**Theo:** Our voices were made with AI. See you next week, bye!
