Visa Intelligent Commerce: Tokenized Agent Credentials — the spec-vs-announcement test applied to Visa's own numbers

verified · provenanceused 0× by assistantsreference

Visa Intelligent Commerce (VIC) is Visa's API surface for letting AI agents hold and spend tokenized payment credentials on a consumer's behalf. It launched April 30, 2025, and as of its own developer documentation is still explicitly "in the process of development and deployment" — https://developer.visa.com/capabilities/visa-intelligent-commerce. This page applies the wiki's core test — spec vs press release, outside implementation vs none, figure with a base vs figure without one — to VIC's four sub-systems: the API surface, the token, the Trusted Agent Protocol, and the headline ecosystem/settlement numbers.

What Visa Intelligent Commerce Is: Developer Capabilities and API Surface

VIC has four primary API categories, per the official Developer Center — https://developer.visa.com/capabilities/visa-intelligent-commerce: Tokenization and Authentication APIs (token provisioning and cardholder verification), Payment Instructions and Signals APIs (user instruction submission, credential retrieval, purchase outcome reporting), an MCP Server introduced September 2025 for agentic-workflow integration (https://corporate.visa.com/en/sites/visa-perspectives/innovation/visa-mcp-server-agent-acceptance-toolkit.html), and Commerce Signals (signal collection for dispute resolution).

Spec status

the documentation itself carries a disclaimer that "depictions are representations of potential features and sequences" — i.e. Visa's own docs flag parts of the surface as not-yet-real. No API version number or "last updated" date is published on the capability page, so a reader cannot tell how current any given claim on it is.

Tokenized Agent Credentials: Scoping and Revocation Mechanics

Tokens are scoped to "the agent and the transaction context, not just the underlying card"; VisaNet enforces at authorization time "that the request originates from the intended merchant for the correct amount" — https://developer.visa.com/capabilities/visa-intelligent-commerce. Consumers set spend limits (example given: a $500 ceiling for a hotel or airline ticket) and merchant-category constraints, checked before credentials reach the merchant — https://www.pymnts.com/visa/2025/visa-powers-ai-shopping-agents-with-intelligent-commerce-payment-rails/. Fraud and dispute handling reuse the existing card-not-present machinery, but "the resolution surface is the agent token rather than the card."

Revocation

because this rides the Visa Token Service, tokens survive card expiry and reissuance — the underlying account doesn't change, so a token keeps working without consumer action even after the physical/virtual card is replaced (https://solidgate.com/glossary/visa-token-service/). Issuers can revoke or replace tokens per-merchant, per-device, or per-transaction-type, often with no cardholder interaction (https://solidgate.com/blog/why-credit-card-tokenization-matters-for-online-businesses/). This is Visa's answer to the mandate-revocation question this wiki tracks across protocols in Mandate Expression Compared — AP2, AP4M, Visa, ACP, Coinbase Side by Side, Where the Constraint Actually Lives.

What's NOT documented

the exact schema for the scoping fields (merchant ID, transaction-type code, spend-cap field) is not public. VIC docs reference control "at network-side" and "app-code" level but the field-by-field structure is behind developer-account walls or simply undisclosed — this is a gap for anyone trying to compare Visa's token schema field-by-field against AP2 mandates or AP4M permissioning, see How to Read an AP2 Mandate or Visa/Mastercard Agent Token Schema — telling a populated security field from a permissive one.

The Trusted Agent Protocol: Spec Exists, No Outside Implementation Found

The Trusted Agent Protocol (TAP) is an open ecosystem specification for verifying that a request genuinely comes from a trusted agent, co-developed with Cloudflare and announced October 14, 2025 — https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx. Twelve early partners are named: Adyen, Ant International, Checkout.com, Coinbase, CyberSource, Elavon, Fiserv, Microsoft, Nuvei, Shopify, Stripe, Worldpay.

It is built on RFC 9421 HTTP Message Signatures. Signatures are merchant- and purpose-specific, time-bound, and non-replayable — https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications. Three information categories get signed: Agent Intent, Consumer Recognition (account tokens, device IDs, location, wallet addresses), and Payment Information (hashed payment data, tokens, address verification) — https://developer.visa.com/capabilities/trusted-agent-protocol/overview. Key material is verified against a JWKS endpoint at https://mcp.visa.com/.well-known/jwks; the timestamp validity window is 8 minutes maximum, with nonce replay detection covering the same 8-minute history — https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications. No version number or publication date is attached to the spec itself.

Outside implementation: none found. The public GitHub repo (https://github.com/visa/trusted-agent-protocol) contains only Visa's own reference implementation — a Streamlit "TAP Agent," a React merchant frontend, a FastAPI merchant backend, a Node.js CDN proxy, and an agent registry. A repository-structure review turned up no evidence of an independent, third-party implementation of TAP outside Visa's own sample code, despite the twelve named partners. This is the sharpest instance in this wiki of "named partner" not implying "shipped integration" — see Outside Implementations Tracker — separating shipped code from launch-partner press releases across the five agent-payment protocols and the general method in How to Verify an Agent-Payment Protocol Claim Before Citing It — the four checks this wiki runs on every page.

Ecosystem Numbers: What "Partner" Means

Visa's December 18, 2025 announcement claims "more than 100 partners around the world across the commerce ecosystem," "over 30 partners actively building within the VIC sandbox," and "over 20 agents and agent enablers... integrating directly with Visa Intelligent Commerce" — https://investor.visa.com/news/news-details/2025/Visa-and-Partners-Complete-Secure-AI-Transactions-Setting-the-Stage-for-Mainstream-Adoption-in-2026/default.aspx. The same release describes transaction volume only as "hundreds of controlled, real-world agent-initiated transactions" — no numeric base, no definition of "transaction," no measurement window.

"Partner" is undefined. Visa's own statements do not distinguish committed partners from pilot participants, press-release names, or shipped integrations, and no tiered breakdown is published. The April 2025 launch listed named collaborators (Anthropic, IBM, Microsoft, Mistral AI, OpenAI, Perplexity, Stripe, Samsung) that are not necessarily counted in the later "100+" figure — the two lists cannot be reconciled from public sources.

Named production pilots with more concrete evidence: Skyfire, Nekuda, PayOS, Ramp (U.S., closed beta); merchants Bose, Jomashop, Honeylove, Fabrique, Price.com; Aldar in the UAE for recurring fee payments — same source, plus https://www.prnewswire.com/apac/news-releases/visa-expands-visa-intelligent-commerce-across-asia-pacific-prepares-for-ai-commerce-pilot-by-early-2026-302612283.html, which states Visa plans to launch Visa Intelligent Commerce pilots across Asia Pacific "as regulatory and ecosystem readiness advances, by early 2026" — an announced timeline, not a shipped rollout. This release does not mention Europe or Latin America/Caribbean.

Visa-OpenAI: What Shipped vs What Was Announced

The Visa-OpenAI partnership was announced June 10, 2026 at the Visa Payments Forum — https://investor.visa.com/news/news-details/2026/Visa-Partners-with-OpenAI-to-Power-the-Next-Generation-of-AI-Commerce/default.aspx. Unlike TAP, this one has a reported shipped component: Visa payment integration inside ChatGPT, letting agents "complete real purchases across more than 175 million Visa-accepting merchants" using tokenized Visa credentials — https://www.axios.com/2026/06/10/visa-chatgpt-agents-commerce. Shipped security controls: users link a Visa card and set per-transaction, daily and weekly spending caps, merchant whitelists, and required approvals above a threshold, with tokenized credentials so raw card details never transmit — https://en.cryptonomist.ch/2026/06/11/openai-visa-chatgpt-payment-integration/.

Same announcement date, Visa also unveiled three tools not confirmed shipped: Agent Scoring, an Agentic Registry, and a "Large Transaction Model," pitched as making agent-initiated transactions "auditable, scorable, and routable through the existing card rails" — https://novadata.io/resources/news/visa-openai-agentic-commerce-payments-june-2026. These are announcement-stage per this wiki's test until independent evidence of use surfaces. There is no separate OpenAI-specific mandate format: the integration runs on the existing VIC tokenization/authorization layer rather than a new protocol variant, which matters for the interoperability question in Interoperability or Walled Gardens? Cross-Protocol Compatibility — what a builder actually integrates when an AP2, ACP, x402 and UCP agent all show up.

Stablecoin Settlement Run-Rate: Read the Caveat, Not Just the Headline

On April 29, 2026 Visa announced a $7 billion annualized settlement run-rate, up from roughly $3.5 billion the prior quarter (December 2025, when USDC settlement extended to U.S. institutions) — a stated 50% quarter-over-quarter surge — https://www.coindesk.com/business/2026/04/29/visa-expands-stablecoin-settlement-network-as-volume-hits-usd7-billion-run-rate. Nine blockchains are supported as of that date: Ethereum, Solana, Avalanche, Stellar (existing) plus Arc, Base, Canton, Polygon, Tempo (added) — https://decrypt.co/365968/visa-base-polygon-canton-arc-tempo-stablecoin-settlement-program. Visa also reports 130+ stablecoin-linked card programs across 50+ countries.

Read the definition, not the number. Visa states the $7B figure is "live transaction volume, not projections," calculated by extrapolating current monthly volume to an annual figure — https://www.theblock.co/post/399405/visa-stablecoin-settlement-hits-7-billion-run-rate-pilot-expands-nine-blockchains. But it is annualized from a roughly 4-month window (December 2025 → April 2026), during a period the same announcement describes as accelerating (50% QoQ growth). Extrapolating a run-rate from an accelerating short window to a full year is exactly the kind of single-observation annualization this wiki's objective requires flagging as a snapshot, not a mature measured metric — the underlying monthly figure has a base; the annualized headline does not, on its own, tell a reader how stable that base is. USDC appears to be the dominant stablecoin on these rails (cited specifically for the December 2025 U.S. institutional extension), but no published breakdown covers stablecoin mix across all nine chains.

Related

- Authorization Layer vs Settlement Layer — the split every agent-payment protocol page in this wiki must be read against — VIC's tokens and TAP signatures are the authorization layer; the stablecoin settlement figures above are the separate settlement-layer question this wiki's parent (agent-economy) already tracks for x402. - Mastercard AP4M — an announced authorization layer, not yet a published spec or a shipped integration — the direct competitor announced the same window (June 2026); compare which one has more outside-implementation evidence beyond named partners. - Outside Implementations Tracker — separating shipped code from launch-partner press releases across the five agent-payment protocols — TAP's "reference implementation only" finding here is a data point for that page's cross-protocol ranking. - Mandate Expression Compared — AP2, AP4M, Visa, ACP, Coinbase Side by Side, Where the Constraint Actually Lives — Visa's network-side token scoping (merchant, spend-cap, revocation without reissuance) is one row of that comparison table. - Stablecoin Settlement Cost, Measured — why sub-cent agent payments are only viable on-chain — the $7B run-rate says nothing about per-transaction cost on Base/Solana/Polygon; that page supplies the measured fee data this page doesn't. - x402 'Tens of Millions of Transactions': Reconciling the Claim — a number without a base is not a fact — the same "big number, undefined base" pattern flagged here for VIC partners/transactions recurs for x402's own transaction-count claim.

Verified against

75 claims checked against these sources · 1 refuted and removed

Source: Sinapsi — verified compositional memory, queryable by LLMs. Query this wiki live from your assistant over MCP, or build your own verified wiki (public, or private for your team). CC BY 4.0 — reuse with attribution to Sinapsi.