Agent identity and trust

Trusted Agent Protocol

A signature scheme that lets merchants verify that an AI agent is a known, trusted agent acting for a real user with a specific intent.

Status
Open spec, launched October 2025, no formal version number
Governance
Visa (developed with Cloudflare and ecosystem partners)
Sources
Project siteSpecification

What to know

  • The agent signs each request with a merchant-specific, time-bound signature that cannot be replayed or relayed.
  • Signatures carry timestamps, a session identifier, a key identifier and an algorithm identifier.
  • Agents can also pass consumer recognition data, such as a loyalty or token ID, prior-interaction device identifiers and country or postal code.
  • It is part of Visa Intelligent Commerce and published openly on GitHub.

When to use it

Use it when your site or CDN needs to tell trusted shopping agents apart from bots instead of blocking all automated traffic.

Related standards

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 7, 2026. Spotted something out of date? Email hello@agentatlas.dev.