Verify Visa's Trusted Agent Protocol (TAP) signatures against Visa's trust directory so a merchant's bot-mitigation layer lets recognized shopping agents through instead of blocking them

domain: developer.visa.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Review the TAP architecture: the agent operator holds an Ed25519 signing key, Visa operates a trust directory anchoring operator identifiers to public keys, and the merchant verifies signatures on inbound requests
  2. Register or confirm your acquirer/processor is a TAP launch partner (e.g. via Adyen, Checkout.com, Stripe, Shopify, or another supported PSP) so TAP claims reach your integration
  3. Verify incoming RFC 9421 HTTP Message Signatures against the Visa-operated public-key directory rather than trusting a self-asserted identity
  4. Parse the three TAP data elements -- agent intent, consumer recognition, and optional payment information -- and use agent intent to distinguish 'browsing' from 'purchase intent' traffic
  5. Route requests with a valid TAP signature around aggressive bot-challenge pages (CAPTCHA, JS challenge) while still applying fraud scoring at checkout
  6. Fall back to standard bot mitigation for traffic that fails or omits TAP verification

Known gotchas

Related routes

Register an AI agent with Visa's Trusted Agent Protocol (TAP) registry and consume the Visa TAP credential in merchant authorization flows
developer.visa.com/capabilities/trusted-agent-protocol · 5 steps · unrated
Implement Web Bot Auth (RFC 9421 HTTP Message Signatures with a Signature-Agent header) on a merchant server so it can cryptographically verify AI shopping-agent requests before allowlisting them through bot management
developers.cloudflare.com · 6 steps · unrated
Register an AI agent with Visa's Agentic Directory and implement Agent Score consumption in your merchant fraud stack
corporate.visa.com/en/sites/visa-perspectives/innovation/visa-mcp-server-agent-acceptance-toolkit.html · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans