AI Engineer Europe 2026
Building safe Payment Infrastructure for the autonomous economy
About this talk
Stripe principal software engineer Steve Kaliski explains how autonomous agents can transact safely while separating nondeterministic discovery from deterministic credentials, checkout, and payments. He examines domain-verification and credential risks, demonstrates spending controls and shared payment tokens integrated with Stripe PaymentIntents, and introduces the Stripe-and-Tempo Machine Payments Protocol for paid HTTP requests using HTTP 402. A demonstration includes the Tempo blockchain and pathUSD, followed by audience questions about recurring agent budgets and transaction volumes.
Chapters
- 0:00Why autonomous agents need deterministic payment infrastructure
- 2:49Credential risks, domain verification, and spending guardrails
- 6:03Stripe PaymentIntents and shared payment tokens
- 8:57Machine Payments Protocol and HTTP 402
- 9:45Paid-endpoint demonstration, Tempo, and agent-friendly commerce
- 16:32Audience questions: recurring budgets and payment volumes
Talk transcript
- 0:00
[on-hold music] Just wanted to thank everyone for being here.
- 0:17
Um, I'm from Stripe, and today I'm gonna talk about building safe payment infrastructure for the autonomous economy or, uh, how we can let robots spend money and how businesses can receive money from robots.
- 0:28
So just about me, I'm a principal software engineer at Stripe. Spent my first four years leading our issuing team, so that's a product that lets developers create physical and virtual credit cards, uh, that historically would be for humans, um, increasingly for bo-robots.
- 0:41
In the last two years, um, I've been exploring how to l-let robots spend money and how Stripe businesses can adapt to that new kind of buyer. And if I have just one takeaway, if you stop listening for the rest of, uh, the presentation, um, discovery and exploration benefit from non-determinism, right?
- 0:57
So the amazing thing about LMs is huge corpus of information, the world's information can, uh, predict and, and recommend code or products or, or businesses for you. Um, but credentials, payments, and checkout require determinism, so not just benefit from it, but require it.
- 1:12
So, um, that sort of isolation of how do I find things or h- or what should I do from how am I gonna transact, um, is sort of the critical separation.
- 1:22
So what we're gonna talk about, uh, agents as economic actors, all the bad things that can happen, um, the solutions that, that Stripe and our partners have worked together on to fix those, and then a little bit of what's next.
- 1:34
So, uh, again, maybe another takeaway. Uh, agents are already economic actors, right? They have their own currency and tokens. So as you are in Claude Code or Codex or any other kind of application, um, you are in effect spending money, right?
- 1:47
It might be proxied through the subscription you have or converted from the tokens that are being inputted or outputted, turning into dollars. But in effect, we're already letting them spend, right?
- 1:57
Just not with any business but the LM, uh, provider that they're working with. So how do we enable other currencies and other spend patterns and other payment methods and other business interactions is our, is our main question.
- 2:09
So, um, we probably, like, we're gonna zoom through this 'cause all we've talked about today is agents, I imagine. So, uh, agents produce text. Sometimes they need to read or write data or interact with third parties.
- 2:19
They do so using tools, and sometimes those tools require money. So how do we safely enable this? Um, again, we all know this, but, uh, crudely, an agent is just calling LM and calling tools.
- 2:31
There's spend in both of them, um, and the tools in particular we're gonna talk about are search, credential management, and payment.
- 2:41
It's the magic, but it's also the risk. So, uh, what are the main problems? Um, I can buy from the wrong place. I can buy the wrong thing. I can spend the wrong amount.
- 2:49
I can use the wrong credential. So the base approach, uh, sort of the OpenClaw style, let's just let the robot operate a human. Uh, operate... Well, hopefully not operate a human, but, uh [laughs] [laughing]
- 3:01
Concerning slip, uh, hopefully doesn't come true. Let the robot just operate the browser like a human. Um,
- 3:08
so wrong place. Well, first, how does an agent certify it's in the right place or domain? Um, how do I know that, you know, maybe the, the website looks a lot like, you know, amazon.com, but is, you know, Amazon dot whatever and, and is a fake one?
- 3:21
Um, the wrong thing. Uh, you could stumble through a site looking for a purple T-shirt, and you could maybe less concerningly buy an orange T-shirt, but you could also, you know, uh, buy something that's ten times more expensive.
- 3:33
The wrong amount. Um, you know, as we know, at least for me, I've seen totally different prices here than back at home. Prices can drift. There's miscalculations, different currencies, taxes, and so on.
- 3:43
Like, the number you- your robot may extract from the page may not actually be the amount of money that you want to spend. And of course, wrong credential. Um, you could paste a credit card.
- 3:52
It could go to the wrong place. Um, but, you know, as, as here, there are other diff- payment methods that are hard or, if not impossible, for an agent to relay.
- 4:01
So we want to be able to solve all four of those things. And again, the base approach of taking a card number, bad. Browsing a site can be finicky.
- 4:08
Filling forms, clicking pay, it's all slow. Um, hard to observe outcomes.
- 4:13
And, you know, this isn't unique to payments, right? It's the same as operating any web app, uh, or anything that has a monetary risk, and that's why MCPs and, uh, APIs exist.
- 4:22
So, you know, in Stripe parlance, the, the left-hand side dashboard is for a human, and the right-hand side, robots prefer code. So the ideal approach is something where we can bind to a merchant.
- 4:33
We can enforce spend policies. It can be API-driven and thus programmatic, and you can have verifiable identities.
- 4:40
So I'm gonna talk about three different things that Stripe and our partners have built together around credentials, payment flows, and checkout to illustrate how we're trying to solve all of those problems.
- 4:50
So first I wanna talk about shared payment tokens. And the idea here is that, um, you know, first, not all payment methods are, you know, universal like credit cards.
- 5:01
Um, some are expressed in different ways. Um, but there's also no way to enforce spend limits or controls when you just hand a card number to someone else, right?
- 5:09
You're gonna trust them that they charge the amount that you parsed out of the page or whatnot. And what we built with shared payment tokens is this idea that an agent can collect a payment credential, and it can share it with the seller, you know, across hundreds of different payment method types, and it can encode sort of
- 5:25
like a mandate or smart contract the limitations of that credential to be used by a particular seller. So, you know, uh, we'll do a demo in a second, but I can apply usage limits to specific currencies, to amounts for time, and a particular seller.
- 5:39
So, uh, even if I've been, you know, uh, duped by a domain or, um, ha- you know, haven't parsed the amount correctly, I can still apply what I think is right in terms of the amount and the particular seller that I'm targeting.
- 5:52
So again, scope to seller, en- it's enforced by Stripe, works across payment methods, and it's auditable. So we're gonna jump into a quick demo just to show you how that works.
- 6:03
So- Let's look at, um, kind of a common Stripe integration. So I have my seller Stripe account, and I wanna charge, uh, $50. So like, normally I would create a PaymentIntent, and on line 39 I'd collect that payment method myself, and it would run, and that's all great.
- 6:21
Um, but now instead of collecting the payment method on my website, an agent is collecting a payment method that it may have already received from its human operator or through the subscription that backs the harness or whatever it may be.
- 6:33
So we're gonna introduce a second Stripe account, and this is the agent Stripe account. And it's gonna provision a shared payment token, let's say it collect-- had collected a Visa card.
- 6:44
And it's gonna say that this Visa card, which has a much higher credit limit, is only gonna work for $25, and it's only gonna work for the next thirty days, and it's scoped to this particular seller, illustratively my internal test account.
- 6:57
So we're gonna go ahead and we're gonna create that credential.
- 7:02
And instead of the seller using a payment method that they've collected, they're gonna receive a token that's been granted to them and try to run the payment.
- 7:13
So let's... Cool. So the first thing we see is that we created that new shared payment token, which applies to that Visa card. It's active. It has that twenty-five dollar limit, and it's gonna expire in thirty days.
- 7:30
Now, what's important as part of this also is we don't want the seller to be fully hidden from what's happening. So in the same way that they would have otherwise collected a card and knew the brand and knew the last four and so on, um, we still send that information over.
- 7:43
So the, the brand and the last four, the credit type, they can use all these inputs in their existing risk analysis. So an important part here too is that we're not trying to do something secret from the seller.
- 7:55
We w-- still wanna provide the relevant infor-information to the seller so that they can still apply their exec-- uh, their previous, uh, risk systems, um, so that, you know, they, they can accept payment.
- 8:07
Um, but what we'll see is we actually had a failure here. So the requested amount, which was fifty dollars, is greater than the amount that was, uh, mandated. So again, we, like, collected a credential.
- 8:18
We shared it. We applied a limit. We trusted the seller. The seller tried to do more, and now Stripe enforced its own limitations. So, uh, again, like, this would work across any payment method type and, you know, now that we, you know, can lower the cost, we'll see that, uh, this actually goes through.
- 8:37
Yep, and that payment went through. So now we're able to securely send credentials, apply limits, make sure there's a minimized blast radius, um, and still allow the seller to process payments as they normally would.
- 8:48
Now, um, that covers credential sharing, but there's two more parts to this is how do we actually associate payment to a product, and then how do we do checkout?
- 8:57
So, uh, the second thing we built, uh, we worked with our friends at Tempo, was what we call the Machine Payments Protocol. So back to that original point around tool calls, um, well, tool calls are just sort of HTTP requests that agents can make.
- 9:10
Um, and H-HTTP requests, um, should be able to be paid for, right? So one way is you pass in an API key, but sometimes those interactions with tools can be ephemeral.
- 9:19
So we wanna be able to communicate the need to pay, um, in those HTTP requests by returning a 402 status code and then supply that credential that we showed earlier, um, so that we can actually get a good back.
- 9:32
So, um, we've covered, uh, how do we get credentials, how do we know to pay for them and associate with the actual product we're buying, so again, um, closing that window of, uh, uh, of improved determinism.
- 9:45
Um, so maximizing determinism. Let's do a demo.
- 9:50
So now if we jump over here, I'm gonna start a server.
- 9:59
This server's a regular sort of, uh, web server. It has pro-protected endpoints that now require payment. So let's say my robot is calling one of these endpoints to try to execute a tool and make a cURL request to it.
- 10:13
It fails, tells us that we need to pay. It gives us some, uh, uh,
- 10:19
encoded payload that explains what we're buying and who we're paying for and the, uh, what we're paying for and the, the mechanism to pay for it. Um, and I can go ahead and,
- 10:33
uh, pay for it now. So now we get some extra information back because we're speaking that protocol. We can see that it's gonna cost a penny, um, this, to this particular recipient.
- 10:45
Um, it'll be pathUSD on the Tempo blockchain, and I can go ahead and
- 10:51
approve it. So now that goes through, we get our success, and then we can see a transaction landed on the blockchain. So, uh, we're, you know, able to create credentials that have limited use.
- 11:06
Now we can be, uh, told by a seller how they want money and have it be associated with the actual re-resource I'm requesting, and now I can send them funds.
- 11:15
Um, but the last part is, um, let's just jump back in, is like we're not always buying API calls, right? And sometimes the, uh, details, uh, of the purchase matter quite a bit, right?
- 11:28
The tax amount, maybe there's that. There's, uh, restrictions about the amount of things I could buy. All the things that a typical e-commerce site is trying to convey. And to that earlier point around, you know, the, the robot, you know, stumbling around a checkout page, there are a lot of details that we want to be able to
- 11:44
relay back to the agent and ultimately back to the human buyer, um, to make sure that the thing we're buying is the, is the thing we think we're buying, right?
- 11:52
Um, we wanna mi-minimize disputes and chargebacks and so on. And if we have this proxy layer of the agent in between, we run the risk of, uh, incorrectly relaying those details.
- 12:01
So what we built, uh, with OpenAI being the Agentic Commerce Protocol is a standard set of APIs and objects that can explain how checkouts work, uh, across the web.
- 12:13
So, um, similar to the last thing we showed where the seller kind of conveys the need to pay, um, we establish a back and forth between agent, a seller, and their PSP,
- 12:24
um, where every single time the agent wants to create a checkout or update the quantity or pick a shipping amount, um, the seller can relay, sort of like a tool call, relay back the latest state, respond to that request, um, and ultimately result, uh, in payment.
- 12:39
So we can sort of illustrate how this works with a, a real business. Let's open up a server here.
- 12:52
So, um, Stripe operates something called Stripe Press. It's our store of books. Um, and this is obviously a very cool, uh, human-friendly way to look at it. Um, but our equivalency, um, is the robot-friendly way of looking at it.
- 13:04
So, um, the ACP protocol or the ACP covers a few things. Uh, how do we express a product catalog, right? So, um, instead of the robot stumbling around and having to click on links and figure out what to buy, we can express our products just in JSON with images and descriptions and pricing, and then the robot can
- 13:22
pick one of those and initiate a checkout. So, uh, we can pull up a familiar UI, maybe I'm asking for recommendations about AI books, and on the right-hand side, we'll see the requests that the agent makes.
- 13:35
So it tells a little bit about the buyer, the line items and quantity it wants, and then the seller can relay back basically the state of the cart. So instead of the robot trying to, you know, pull information, you know, out of a UI like this, it has structured data that it can refer to.
- 13:50
So, uh, the, the line items, the base price of each, applicable tax, the different fulfillment options, and so on. So nothing surprising here, but, you know, our goal is to sort of establish that determinism, right?
- 14:03
Where like we've segued from discovery, where maybe we were doing some web crawling, now we've transitioned to just purely programmatic back and forths. So, you know, as I change payment methods or I change shipping and ultimately pay,
- 14:17
those back and forths happen. Payment goes through using something like a shared payment token or otherwise to relay those credentials.
- 14:28
Back in. Yep. So, you know, at the end, we, we have API-driven commerce flows that are flexible to different payment methods, whether they're crypto or cards or any of the other hundreds of payment methods that exist.
- 14:41
And critically, the seller remains in control. They continue to have the relationship that they expected to have with the customer, but also receive the signals, um, a-and risk data that they need to safely interact with agents.
- 14:54
And sort of the, you know, goes without saying, most of us have already done this with, with our products, but, you know, we want to make our products agent-friendly.
- 15:01
Um, and if we only expose u-- web UIs or, or, or applications like that, um, we increase the l-likelihood of non, you know, the nondeterminism interacting with our businesses.
- 15:12
Instead, we should make them age friend- agent-friendly, um, to maximize the deterministic flows that agents have with our businesses. So leveraging things like shared payment tokens or wallets or other technologies to then manage those credentials safely, um, is then important for agents so that they're able to, uh, you know, not accidentally spend a gajillion dollars on a
- 15:30
card. Um, so TLDR, discovery we should keep with nondeterminism, that's perfect. Payments and checkout and credentials, we want to shift towards exclusively deterministic. Um, so nondeterministic planner and constraints with verifiable parties and structured negotiation results in a small radius of risk and hopefully safe, uh, payments between agents and businesses.
- 15:54
So that's all I got. Thank you. [audience applauding] I have two minutes and nine seconds if people have questions.
- 16:07
You mentioned blockchain. Yeah. What-- Is this hosted by Tempo or Stripe, or do our own separate? Yeah. So, um, you know, Stripe supports a number of different, uh, protocols and, and, uh, a variety of networks, including Base and Tempo.
- 16:21
So the transaction data, uh, innately lives on those chains, and then Stripe replicates the sort of product view of that data in our own system. Yeah.
- 16:32
The microphone. This guy.
- 16:35
Um, the shared payment token's really cool. Uh, in terms of, say, like recurring budgets and payments, like I'm thinking of, you know, I wanna give OpenClaw twenty-five dollars a week to use with like a particular model.
- 16:49
How, how does that, uh, kind of factor in?
- 16:52
Yeah. So you touched on two points, the sort of the subscription thing and then sort of more enduring policies. Um, on the subscription side, um, in the same way you give a credit card to a business and you permit it to spend twenty-five dollars or, or whatever on a, on a periodic basis, but it still uses the
- 17:07
same credential. Uh, we have a similar idea there as well, sort of similar to in OAuth access and refresh flow, where you could sort of like request, uh, subsequent usage.
- 17:16
Um, and then on the, on the other part about like, uh, uh, sort of more balanced budgets, the, the sort of equivalency can work here where you just pick a higher number.
- 17:26
Um, we still scope it to individual sellers, um, but you could just create infinite of them.
- 17:32
Yeah.
- 17:35
Um, so I'm wondering, is Stripe Projects just effectively a wrapper of these primitives that you've discussed during the session?
- 17:41
Uh, yes. Th-thank you for that plug. I did not have time to include that, but yes, Stripe Projects is built on shared payment tokens and then, uh, the mannerism in which a seller or, uh, SaaS business can express their products is the idea.
- 17:53
And then the point you touched on, the recurring part is how the, uh, monthly part would work.
- 17:58
Thank you.
- 17:58
Thank you.
- 18:00
You mentioned that you have, uh, started this, uh, two years ago. I'm wondering about the, the number of, uh, such payments done and the v-volume money moves.
- 18:10
Yeah, we-
- 18:10
Can you share something-
- 18:11
We don't have public stats on any of that. Um, but I think in general we're very encouraged by it, and we're really excited about, um, trying to support more businesses and accepting that type of, uh, payment.
- 18:20
Okay.
- 18:20
Yeah. [gavel pounding] Well, I'm at zero now, so thank you everyone. Appreciate it. [audience applauding] [upbeat music]