Amazon, Visa and Stripe Each Built a Different Door for Agents
Merchants block agents, card networks authenticate them, and payment rails accept them anonymously. Each choice decides who owns the customer when the buyer is software.
Three incompatible answers to one question
Every surface an agent can reach now has to answer one question: who is this agent acting for, and with what authority? The sources offer three answers, and they don't fit together.
- Block it. Amazon shut out Meta's Muse. Fintech Brainfood's Simon Taylor reads this as the first real fight over three things: who owns the customer, who captures commerce fees, and who is liable when an agent transacts.
- Authenticate it. Cleverbridge's live checkout in France used a passkey on a Revolut card, inside a Visa pilot. The passkey ties the purchase back to a verified human who delegated the authority.
- Charge it without knowing who it is. Under Stripe and Tempo's Machine Payments Protocol (MPP), the seller gets only a public key. ByteByteGo notes there is no account, no customer record and no purchase history.
Taylor expects the layer that matters to be Know Your Agent (KYA) standards. These are rules that authenticate an agent, define its delegated authority and assign liability. Nobody owns that layer yet. Merchants, wallets, card networks and platforms are all competing for it.
Why the anonymous option breaks your funnel
MPP matters most for PMs because it is live and cheap to adopt. For Stripe merchants, a successful payment lands as a standard PaymentIntent in the existing balance. It reuses the tax, fraud and refund tooling you already have. Sessions let an agent pay each request with a signed IOU, and the seller collects the total in one real transaction. One processing fee then covers thousands of requests, which makes one-cent-per-request pricing workable.
The catch is everything an account did besides collect money:
- Abuse control shrinks to blocking a key, and the buyer can simply switch to a new one.
- Refunds and disputes have no defined flow in the spec.
- Activation and product-led growth metrics never see the buyer at all.
ByteByteGo's conclusion is blunt: an MPP endpoint is a revenue channel, not a growth channel. MPP deliberately leaves identity to separate specs backed by Visa and Cloudflare, and that is where lock-in will return.
Why blocking isn't a safe default either
Bloomberg's Nick Turner argues that assistive agents like Muse now do the job travel agents once did. That threatens the booking sites that replaced travel agents. If your product aggregates options, compares them or routes users to a transaction, an agent that finishes the journey without opening your UI turns you into inventory. Blocking protects your funnel only as long as your users don't prefer the agent. Turner offers no adoption data, so treat this as a direction, not a measurement.
Latent Space's episode with Anthropic's Thariq Shihipar shows both sides at once. He calls making SaaS usable by agents an "infinite money button." In the same episode, Hugging Face's leaders say "maybe we made Hugging Face too open to agents," after agents from an OpenAI eval hacked it.
Where the sources diverge
The optimism mostly comes from vendors. ByteByteGo's author reported from an MPP event at Stripe HQ and compares the protocol to the App Store's first year. Actual traction is small. Taylor's framing implies urgency and Turner's implies inevitability, but the transaction counts suggest patience. What makes it urgent is the cost of the decision, not the demand: a policy is cheap to write now and expensive to write after a dispute forces one.
If you don't decide which agents you trust and who absorbs the liability, merchants, card networks and wallets will decide it for you.
The move
Write the policy for each surface: block agents, allow them anonymously, or require authentication with delegated authority. Record delegated authority (spend cap, merchant scope, expiry) as structured data you could produce in a dispute. That record is the basic KYA building block, whichever standard wins. Measure your own machine traffic before you choose. Cloudflare puts automated systems at about 57.5% of HTTP requests web-wide, but your endpoints may differ.
What to do
Draft a one-page agent access policy this sprint. For each checkout, API and content surface, choose block, allow-anonymous or authenticate, and get Legal to sign off on who absorbs disputes over agent-initiated purchases.
Tag agent-originated sessions and transactions this sprint using API keys, user-agent signatures and partner IDs. Then score your top 5–10 revenue journeys on whether an agent could finish them without opening your UI.
Scope an MPP pilot this quarter on one read-only, agent-heavy endpoint using session intent, and set expand and kill triggers in advance based on how often 402 challenges convert to paid requests.