Engineering brief
Your AI Agent Just Authorized What? A Framework for Agent Payments
At a glance
- Relevance
- Practical value
- Warnings
- None
PayPal's Jay Mok and Ben Coumes propose a stakes-and-counterparty matrix for agent authorization: low-stakes code edits need only logs, high-stakes open payments need cryptographic proofs. The framework is worth adopting—before your next agent approves a transaction you can't…
Agent authorization is the next governance bottleneck—this framework makes it concrete.
Summary
PayPal presents a framework for agent authorization built on two axes: transaction stakes (low vs. high) and ecosystem openness (closed vs. open).
The model translates into three tiers: low-stakes actions in closed ecosystems (like Claude code editing) rely on simple logs and reversibility. Medium-stakes payments within a trusted network (e.g., Nevermind) use OAuth scopes and shared vaults, but still depend on centralized transaction logs rather than cryptographic proof.
For high-stakes, open-ecosystem payments where parties don't know each other, the authors argue for FIDO verifiable intents and AP2 mandates—multi-layered, selectively disclosable JWT-style proofs signed by the user and optionally the agent. PayPal's new 'approval token' is a concrete step in this direction, shipping soon for select wallet users.
The tradeoff is clear: stronger cryptographic guarantees increase complexity and user friction, but are mandatory for irreversible actions in untrusted environments. The model generalizes beyond payments to medical orders, e-signatures, and securities trading.
Watch the video
This video is blocked due to your privacy settings. To watch this video, please accept YouTube marketing cookies.
Related breakdowns
Context compaction is a trap when caching is cheap
Caching flips the economics of context management. Full history outperforms compaction on cost and accuracy. Teams that compact by default may be wasting money.
AI memory has converged on profiles—context silos remain the real gap
After three years, ChatGPT and Claude converged on running profiles for memory—but made opposite compute tradeoffs. The real problem is context access, not…
AI Loop Hype Misses the Real Problem: Defining What “Good” Means
A Langfuse experiment shows self‑improvement loops gain most on first iteration with clear yes/no criteria—ditch fuzzy LLM‑judge scores for binary evaluators.
Get TL;DW
Too Long; Didn't Watch.
A concise breakdowns of the AI and devtools videos that actually matter for engineering leaders.
Free. Weekly. No hype.
Video and thumbnails remain the property of their respective creators. tldw.news provides editorial analysis, commentary, and discovery links to original content.