Your Agent Just Authorized What?!
Jay Mok
- When
- Thursday, July 22:50 PM – 3:10 PM · 20 min
- Where
- Track 2San Francisco, CA · imported from ai.engineer's public schedule feed
About this session
The nightmare scenario writes itself: your agent just ran off with your credit card and maxed it out on concert tickets, crypto, and a questionable NFT collection. Relax — we're building the guardrails. When an agent acts on your behalf, three questions must always be answerable: Did the human authorize this? Did they authorize this, now, in this scope? And can we prove it later? This talk maps three permissioning layers onto a stakes ladder: OAuth scopes at the bottom (broad capability, weak per-action proof, fine when reversible), Claude Code's tool-scoped allow/ask/deny model in the middle (brilliant for developer tooling, but no cryptographic evidence), and signed payment mandates at the top — where FIDO's Agentic Payments Working Group is building toward cryptographically-bound, constraint-carrying credentials. We'll share artifacts from Agent to Agent payments using our Shared Vault and Oauth to our constraint carrying Approval token leveraging our pillars of Identity and Buyer and Seller protection. You leave with a stakes × evidence matrix and a mental model that applies beyond payments: medical orders, e-signatures, securities trading, activities where you want you want to be more careful with your agent.
Speaker
PayPal
More in Agentic Commerce
- Inside the AI economy: What Stripe’s data revealsTuesday, June 30 · 10:45 AM – 11:05 AM · Leadership 1
- Designing Multimodal Collaborative Agents for Next-Gen CommerceThursday, July 2 · 10:45 AM – 11:05 AM · Track 2
- Building safe payment infrastructure for machine-to-machine commerceThursday, July 2 · 10:45 AM – 11:05 AM · Leadership 1
- Why Your AI Agent Needs a Wallet: Agentic commerce on Arc with USDC and NanopaymentsThursday, July 2 · 11:10 AM – 11:30 AM · Track 2
- When AI Agents Pay and Sellers Monetize: Building x402 Apps for Agentic Commerce on AWSThursday, July 2 · 11:40 AM – 12:00 PM · Track 2
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.