Visa Trusted Agent Protocol, from the merchant’s side.
Visa Trusted Agent Protocol (TAP) lets an AI agent in Visa’s program sign its requests to a merchant’s site, so the merchant can tell it apart from other bots. Visa announced TAP on 14 October 2025, developed with Cloudflare. It builds on HTTP Message Signatures (RFC 9421) and is part of Visa Intelligent Commerce.
What happens on the wire.
- 01
The agent signs the request
Each request carries an HTTP message signature over the host and path, with created and expires times, a key ID, a nonce, and a tag: agent-browser-auth while browsing, agent-payer-auth when paying.
- 02
The merchant looks up Visa’s key
Visa publishes agent public keys as a JWKS at mcp.visa.com/.well-known/jwks. The merchant, or a site-protection provider acting for it, fetches the key named by the key ID.
- 03
The merchant checks time and replay
The created and expires times should be no more than 8 minutes apart, and a nonce already seen in the last 8 minutes should be blocked as a replay.
- 04
Optional consumer and payment data
The request body can carry a consumer-recognition object, including a Visa-signed ID token with obfuscated email and phone, and a payment container. Both are signed with the same nonce as the request.
What a valid result shows, and what it does not.
Shows
- The request was signed with a key Visa publishes for an agent in its program.
- If the verifier enforces the time window and keeps a nonce cache, the request passed those checks. A valid signature alone does not prove that the request was not replayed.
- When present, the consumer and payment objects were signed with the same nonce as the request.
Does not show
- That the cardholder approved this cart or this price. That is a mandate or consent record, such as AP2 or Verifiable Intent.
- Which of your customer accounts the agent acts for. Visa’s spec says the merchant must keep its own mapping table for that.
- Anything that happened after the request, such as payment, delivery, or a return.
What it leaves on the record.
Visa’s TAP repository says the protocol is meant to “minimize chargebacks from unauthorized transactions,” but the specification defines no dispute process. A verified TAP signature is evidence that a Visa-registered agent key made the request, nothing more.
Liability follows Visa’s card rules. Under the current rules, an agentic payment provider is treated as the cardholder, and the cardholder is responsible for its actions as if they had initiated the transaction. Keep the verification result, key ID, nonce, and timestamps with the order. TAP does not keep them for you.
What to do now.
- 01
Ask your CDN or bot-management provider whether it verifies TAP today. Visa built TAP with Cloudflare, and Visa announced TAP support across Akamai in December 2025.
- 02
If you verify it yourself, follow Visa’s order: required fields and tag, time window, nonce, then the signature against Visa’s published key.
- 03
Pass the result to checkout and store it with the order, not only in edge logs.
- 04
Treat a valid TAP signature as agent identity. Check what the cardholder allowed separately.
What KYA does with Visa TAP today.
Merchant-scoped TAP registry, public key lookup, and Shopify verification flow are live. A generic public TAP verifier is not exposed yet.
Short answers.
Is Visa TAP open source?
The code is public on GitHub, but its licence points to the Visa Developer Center terms of use and the TAP product terms. It is not an open-source licence.
How is Visa TAP different from Web Bot Auth?
Both use RFC 9421 HTTP Message Signatures, and Visa calls TAP aligned with Web Bot Auth. TAP uses its own tags (agent-browser-auth and agent-payer-auth), keys that Visa publishes, and an 8-minute nonce window. Web Bot Auth uses the web-bot-auth tag and a key directory named in a Signature-Agent header.
Does Visa TAP prevent chargebacks?
The specification defines no dispute process. TAP identifies the agent’s key; who is liable for a disputed transaction follows Visa’s card rules.
Keep what each agent order leaves behind.
We’ll map what Visa TAP and the other specs reaching your checkout produce to one record per order, with the gaps marked.