Flominzo

Agentic payments

What are agentic payments? AI agents that pay, within rules you set.

Agentic payments are payments an AI agent starts for a person or business: how they work on cards and bank rails, the protocols, controls and reconciliation.

By , Founder · Last updated:

Explore Flominzo AgentPay
On this page 12 sections

Agentic payments, in short

An agentic payment is a payment that an AI agent starts on behalf of a person or a business, under authority that person or business gave it in advance. The agent understands a request, works out who should be paid, how much and how, and asks a payment system to carry it out. The money still moves over ordinary rails: cards, bank transfers, instant payments, mobile money. What is new is who proposes the payment, and how the authority to pay is expressed and checked.

Two families of use have emerged. Agentic commerce is an agent buying something from a merchant for a shopper, mostly paid by card. Agent-initiated bank payments are an agent moving money for a business or a person: supplier invoices, payouts to sellers or contractors, bills, transfers home. The first is where most of the headlines are. The second is where most of the money in a business moves, and it is the side Flominzo works on.

Agentic commerce and agent-initiated bank payments

The two families share a principle, that the agent proposes and a controlled system decides, but they differ in almost everything that matters to an operations team.

Agentic commerceAgent-initiated bank payments
Who is paidA merchant selling goods or servicesSuppliers, sellers, contractors, billers, family members, your own accounts
Typical railCard networks, walletsBank transfers, instant payments, bulk files, mobile money
How authority is expressedA tokenised card credential scoped to the agent, plus the shopper’s confirmation or a pre-agreed ruleA mandate: who may be paid, how much, from which account, until when, with approvals above thresholds
If something goes wrongCard dispute and chargeback rules applyA push payment is usually final once sent; recovery depends on the rail and the receiving bank
What proves it happenedThe merchant’s order and the card settlementThe provider’s status, its settlement file and your bank statement

That last row is why reconciliation sits at the centre of agent-initiated bank payments. A card network gives both sides a dispute process. A bank push payment gives you a statement line, and you have to prove it matches what the agent was allowed to do.

The programmes and protocols so far

Card networks, payment companies and AI platforms have each published their own approach. The list below is taken from each organisation’s own material, as of September 2026. It moves quickly, so check the current documentation before you build on any of it.

ProgrammeFromWhat it does, in its own words
Mastercard Agent PayMastercard, announced April 2025Agentic Tokens that build on Mastercard’s tokenisation; trusted AI agents are registered and verified before they can pay on a user’s behalf.
Visa Intelligent CommerceVisa, announced April 2025Tokenised credentials for agents, with consumers setting spending limits and conditions. Visa’s Trusted Agent Protocol lets merchants verify an agent through signed HTTP requests (RFC 9421).
Agent Payments Protocol (AP2)Google and more than 60 organisations, September 2025Signed mandates (an Intent Mandate, then a Cart Mandate the user approves) as verifiable credentials; designed for cards, real-time bank transfers and, through an x402 extension, stablecoins. Open source under Apache 2.0.
Agentic Commerce Protocol (ACP)OpenAI and Stripe, September 2025An open standard behind Instant Checkout in ChatGPT, starting in the US. Stripe’s Shared Payment Token is scoped to one merchant and basket total. Apache 2.0, in beta.
UPI Reserve PayNPCI, IndiaDescribed by NPCI as letting users give consent once so that intelligent systems can transact on their behalf in a controlled, transparent way.

Read side by side, they converge on the same few ideas: the agent has its own verified identity, the user’s authority is captured once in a record that can be checked later, the credential the agent holds is narrower than the user’s own, and larger or unusual payments still come back to a person. We compare the two card networks in detail in Mastercard Agent Pay vs Visa Intelligent Commerce.

How an agentic payment works, step by step

Whatever the rail, a well-built agentic payment has the same shape.

  1. Authority is granted. A person or business records what the agent may pay: purposes, payees, limits, rails, expiry. On a card network this may be a scoped token; on a bank rail it is a mandate your payment system holds.
  2. The agent proposes. It turns a request ("pay this month’s approved supplier invoices") into a structured payment intent, with a unique key so it can never be sent twice by accident.
  3. The system checks. Something outside the model compares the intent with the authority: is the payee allowed, is the amount within the cap, does it need an approval? If a check cannot run, the payment does not go.
  4. The payment executes. A provider or bank moves the money over the chosen rail.
  5. The evidence is matched. The provider’s response, its settlement and the bank movement are compared with the intent and the authority. Only when they agree is the payment finished.

Steps one to three are what people usually mean by agent payment controls. Step five is what lets you prove, afterwards, that the controls worked.

The controls an agentic payment needs

The short version: limits that live outside the model, a default of refusing when a check fails, one idempotent intent per step, an allow-list of payees with a waiting period for new or changed bank details, approvals by amount and by reversibility, an expiry and a way to revoke, and a record of every decision.

We set these out as a checklist, with a test for each, in AI agent spending limits and approvals, and as a free AI agent payment policy template you can adapt.

Why reconciliation matters more when agents pay

An agent can make more payments, faster, across more rails than a person, and it retries when something times out. Each of those multiplies the ways records can drift apart: a payment with no matching intent, an intent executed twice, a payment outside the mandate, an approval that never happened. A status of "paid" from a provider does not tell you any of that.

That is why agent payments need the same independent proof as any other payment, only more of it. We explain the records and the exceptions in agentic payments reconciliation.

Where agentic payments make sense first

Business push payments are the practical starting point: the payees are known in advance, the amounts follow agreed rules, and each payment can be proven against bank evidence. Supplier invoices, seller and contractor payouts, payroll batches and recurring bills are good candidates. Consumer shopping gets more attention, but it depends on merchants, card networks and issuers moving together.

For payouts in particular, read agentic payouts. For the local picture, see agentic payments in the UK and agentic payments in India.

Where Flominzo AgentPay fits

Flominzo AgentPay works on the bank-rail and payout side, not as a card network or a wallet. People, business copilots and external AI agents ask for a payment in plain language; AgentPay turns each request into a structured payment intent under a recorded mandate that states who granted it, what it may pay, to whom, up to what limits and until when. The deterministic payment core enforces the mandate exactly as it enforces any other limit. Agents never move money, change limits or close exceptions on their own.

Every payment an agent starts is then reconciled against provider, settlement and bank evidence. We call that 100% reconciliation: every payment is matched or explained, with evidence: it ends either matched against independent evidence - the provider’s records, the settlement file and the bank statement - or as an open exception with an owner and a reason. None is silently assumed paid.

Flominzo does not hold customer funds; payments run through the licensed providers and banks you use, and the rails, markets and channels are agreed for your deployment. Early-bird pricing is $3,999 setup + $999 a month for the first 20 customers.

Explore Flominzo AgentPay

The words you will meet

Mandate
The recorded authority an agent acts under: who granted it, what it may pay, to whom, up to what limits and until when. AP2 uses the word for the signed records of a user’s intent and approved cart.
Payment intent
A structured request to pay: payee, amount, currency, timing, purpose and a unique key. The agent writes it; the payment system decides whether it executes.
Agentic token
Mastercard’s term for a tokenised card credential issued for an agent, narrower than the card itself and revocable on its own.
Know your agent
The principle that an agent is identified, registered and owned before it can pay, as a customer is before they can open an account.
Human present, human not present
AP2’s two flows: the user approves in real time, or the agent acts later on authority given earlier.
Idempotency key
A unique value sent with a payment so that a retry of the same request can never create a second payment.
Fail closed
If a check cannot run, the payment does not go. The opposite, carrying on when a check breaks, is how agents overspend.

Questions

Are agentic payments the same as agentic commerce?

Agentic commerce is one kind of agentic payment: an agent buying from a merchant for a shopper, usually by card. Agentic payments also include agents paying suppliers, sellers, contractors and bills over bank rails.

Does an AI agent hold my money or my card?

It should not. In the programmes published so far the agent holds a narrower credential or acts under a mandate, and a payment system outside the model decides whether each payment goes.

Which rails can agents use?

Any rail a payment system can reach: cards, bank transfers, instant payments such as Faster Payments or UPI, bulk files and mobile money. The rail changes how the payment is proven and how it can be recovered, not the need for controls.

Who is responsible if an agent pays the wrong person?

It depends on the rail, the contract and how the authority was recorded. We cover the evidence you need in the audit trail guide below. Nothing here is legal advice.

Sources

Let’s make it specific to you.

Bring your systems, payment flows, and questions. We’ll help define the next step.

Talk to the team