Now self-serveAccess PayOS data to make better payment decisions, no sales call needed.Start building →
Agent Data / Agentic Tokens

Tokens an agent can pay with, safely.

Agentic Tokens are network-issued, PayOS-provisioned payment credentials for AI-driven commerce. They let your agent complete purchases on a consumer's behalf, under passkey-authenticated consent and clearly defined scope.

“Book the 7am flight to Austin. Keep it under $300.”
Your AI agent · instruction captured
↓
Passkey approved
Face ID · the consumer consents
↓
5221 74•• •••• 8812
AGENTIC TOKEN · ONE-TIME CRYPTOGRAM
NETWORK-ISSUED
↓
skyfare.com · checkout
$287.00 · the agent completed the purchase
✓

Pay anywhere.

Transform your customer experience with AI-powered payments, an agent that can check out, book, subscribe and settle bills, everywhere your users transact.

$129.99
Easy Checkout
1 / 9

Online Shopping

AI agents place e-commerce orders at any merchant checkout and pay securely with PayOS, no card details ever handed over.

Card number
MM/YY
CVV

Agent-centric, multi-merchant, consent-anchored.

Not card-on-file at one merchant, and not a device-only wallet. Agentic Tokens are built for agents that act across the web.

Network alignment

Works with Visa and Mastercard agentic and token programs.

Security by design

Passkeys for consumer consent; tokens replace the raw PAN.

Scope controls

Merchant / MCC, spend, time windows and usage limits enforced by the networks.

Traceability

Consumer instruction, credential issuance and authorization are all linked for audit and disputes.

Processor-agnostic

Baseline guest-checkout coverage across merchants, no lock-in.

Multi-merchant

One agent-centric credential works across websites, not just card-on-file at one store.

Three pillars of agentic tokenization.

Included 01

Tokenization for agents

Agents are onboarded through PayOS. When your agent requests payment credentials, the card networks return a PCI-exempt credential usable for checkout at any website.

What this means for you
One request returns a credential your agent can spend at any merchant, no raw card number involved.
Credential
type PCI-exempt
usable at Any website
raw PAN Never exposed
onboarding Via PayOS
Included 02

Cardholder verification with passkeys

A payment passkey verifies the cardholder when a consumer adds a new card, and when they give purchase instructions before the agent transacts, binding consent directly to the token.

What this means for you
PayOS handles the Visa and Mastercard passkey integration; you just present the confirmation step in your agent’s flow.
Verification
method Payment passkey
on add card Required
on instruction Required
phishing-resistant Yes
Included 03

Payment instructions & signals

Credential requests must match the cardholder-approved instruction, and authorizations are checked against it (amount, merchant / MCC, scope). Signals are generated for each authorized transaction.

What this means for you
Every token ties back to a passkey-authenticated instruction; out-of-scope requests are rejected, and signals are exposed to help you trace and support disputes.
Signals
instruction match Enforced
out of scope Rejected
per authorization Signal emitted
dispute support End-to-end

A different kind of credential.

✓

What Agentic Tokens are

✓Agent-centric credentials that act on behalf of a consumer.
✓Multi-merchant, usable for checkout across websites.
✓Consent-anchored to a passkey-authenticated instruction.
×

What they are not

×Traditional card-on-file at a single merchant.
×Device-only wallets tied to one device.
Passkeys are a network requirement
Visa and Mastercard both require passkey authentication to issue agentic payment credentials. Consent is built into the rails, not bolted on.

Two ways in.

How you use Agentic Tokens and the PayOS Wallet depends on who you are.

For consumers
PayOS Wallet

A standalone, consumer-facing wallet. Use it directly in the browser or through MCPs, no integration required.

wallet.payos.ai
For organizations
Build it into your product

Embed the wallet and token flow inside your own app.

PaymentSheet Pre-built React drop-in, the fastest path (~1 hour).
Mobile SDKs Native iOS and Android passkey SDKs.
PaymentSheet covers the whole flow; walletOnboard and skipOtp props run either step alone.

Core building blocks.

The primitives behind every flow in the integration.

Wallet user

An identity created or resolved by phone or email. One identity, many cards.

Card

Stored PCI-compliant and network-token provisioned in the wallet.

Payment Intent

Amounts, currency, merchants and user. Multiple payments per intent.

Session token

Short-lived, single-use, backend-generated token that initializes any SDK or checkout.

Authentication

Passkey step-up that binds consumer consent directly to the intent.

Credentials

Generate, then retrieve, the agentic network token the agent pays with.

One drawer. The entire flow.

One React drawer overlays your app and handles everything, end to end. No purchase happens inside it: PayOS generates the credential, and your agent pays.

1
Phone verification
An OTP creates or resolves the wallet user.
2
Card creation
A secure iframe captures the card; it never touches your servers. Stored and network-token provisioned.
3
Card selection
Returning users see their saved cards immediately.
4
Credential generation
Runs the passkey step-up and generates the agentic token payment credentials.
5
Retrieve the credential
Retrieve the credential for your AI agent to use. No purchase happens here.
Returning consumer on a trusted device? The OTP is skipped. Trust lasts 90 days per device via walletUserId.

Bring your own UI, or go native.

Headless by design for full control, plus native passkey SDKs for iOS and Android.

Headless Own every pixel with the JS SDK Card Element and Passkey JS SDK, but full control means full orchestration: mint short-lived session tokens, sequence register() and authenticate(), and handle WebAuthn support. Reach for it only when PaymentSheet truly can't fit the design.

iOS

Native passkey SDK for passkey enrollment and payment authentication in your app.

Android

Native passkey SDK for passkey enrollment and payment authentication in your app.

Mobile web

Use PaymentSheet or the Passkey JS SDK in the default browser. Passkeys do not work in in-app browsers like Instagram or Facebook.

Issue your first agentic token.

Passkey consent, scoped credentials and linked signals, all through one API.