
Approve once. Prove every step.
Your customer approves the limits once. Every step after that, from the approval to the payment, is checked against them and signed into one record.
Bounded authority · Independently verifiable · PSP-agnostic
Modules
One control plane for every agent payment.
The same mandate, the same decision, the same evidence. Only the execution mode and the rail change.
The agent requests one specific purchase. Attesso answers ALLOW or DENY against the approved bounds.
A RECURRING mandate carries a per-period budget and stays active until its term runs out.
Future-dated authority waits in SCHEDULED until its valid_from time arrives, then goes ACTIVE.
The integrator moves the money on its own rail. Attesso reserves the amount against the mandate first.
Full and partial refunds are appended to the signed record as labelled external reports.
Every state change lands in one Evidence Bundle: a flattened JWS anyone can verify.
The paradigm shift
Agents can reason. Now they need authority to act.
Agents shouldn't hold unlimited wallets. And humans shouldn't have to approve every checkout. Attesso gives agents bounded economic authority, with proof of every action.
From agent intent to signed proof in nine lines.
The customer defines the permission. Attesso verifies the agent's request and produces signed evidence that proves it.
# 1. Create a bounded mandate curl -X POST $ATTESSO_API/v1/mandates \ -H "Authorization: Bearer ***" \ -d '{"subject_reference":"user_123","policy":{...}}' # 2. Customer approves with a passkey (hosted page) # 3. Authorize the agent's request curl -X POST $ATTESSO_API/v1/mandates/$MANDATE_ID/authorizations \ -H "Authorization: Bearer ***" \ -d '{"proposed_action":{...}}' # 4. Execute on your existing payment provider # 5. Confirm the payment curl -X PUT $ATTESSO_API/v1/authorizations/$AUTH_ID/commit \ -H "Authorization: Bearer ***" \ -d '{"external_action_reference":"booking_123","provider_transaction_reference":"pi_..."}'
From approval to a signed yes or no.
The customer approves a mandate that defines what the agent may purchase and under which conditions. When the agent requests payment, it submits a purchase that must comply with that approved mandate. Attesso verifies the request, produces signed evidence, and connects it to your existing payment flow.
Customer controlled
The customer sets the limit. The agent stays inside it.
Independently verifiable
Signed evidence records what was approved and what the agent requested.
Keep your payment provider
Add agent authorization without replacing your existing payment rail.
Built for agents that act while you're away.
Let a shopping agent buy for your users without ever holding their card.
A user signs a customer mandate like “purchase these running shoes from an approved merchant for no more than €150 before Friday.” The agent submits a payment request, Attesso returns verifiable evidence, and the payment runs through your existing provider.
Put nine lines between your agent and its next payment.
Every step, from the customer's approval to that payment, comes back signed.