Agent identity and trust
Trusted Agent Protocol
A signature scheme that lets merchants verify that an AI agent is a known, trusted agent acting for a real user with a specific intent.
- Status
- Open spec, launched October 2025, no formal version number
- Governance
- Visa (developed with Cloudflare and ecosystem partners)
- Sources
- Project siteSpecification
What to know
- The agent signs each request with a merchant-specific, time-bound signature that cannot be replayed or relayed.
- Signatures carry timestamps, a session identifier, a key identifier and an algorithm identifier.
- Agents can also pass consumer recognition data, such as a loyalty or token ID, prior-interaction device identifiers and country or postal code.
- It is part of Visa Intelligent Commerce and published openly on GitHub.
When to use it
Use it when your site or CDN needs to tell trusted shopping agents apart from bots instead of blocking all automated traffic.
Related standards
MCP · Model Context ProtocolA2A · Agent2Agent ProtocolSKILL.md · Agent SkillsAGENTS.md · AGENTS.mdACP · Agent Client ProtocolPAP · Personal Agent ProtocolAG-UI · Agent User Interaction Protocol (AG-UI)A2UI · A2UIMCP Apps · MCP AppsPACT · Personal Agent Consent & Trust Protocol (PACT)ANP · Agent Network ProtocolOASF · Open Agentic Schema FrameworkWebMCP · WebMCPllms.txt · llms.txtAgent Spec · Open Agent Specification
Get the weekly agent stack update
New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.
Reviewed Oct 7, 2026. Spotted something out of date? Email hello@agentatlas.dev.