Use Mastercard Agentic Tokens (MDES extension) to bind a tokenized card credential to a specific AI agent and merchant scope

domain: developer.mastercard.com/mastercard-checkout-solutions/documentation/use-cases/agent-pay · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Request an Agentic Token via the Mastercard Digital Enablement Service (MDES) Tokenization API, specifying the agent identity, permitted merchant scope (one or more merchant IDs or MCC categories), and consent policy including spend caps and expiry.
  2. The issuer returns a token that binds the underlying card PAN to the agent identity and scope; the raw card number is never exposed to the agent or LLM.
  3. Embed the Agentic Token in the agent's payment credential store; at checkout, the agent passes the token in the authorization request just as a standard MDES token, with additional fields carrying agent identity.
  4. Configure real-time authorization revocation: the consumer's issuer app can pull the agent's authorization at any time, immediately invalidating the Agentic Token at the network level.
  5. Test in the Mastercard sandbox via developer.mastercard.com; the agentic tokenization sandbox supports Level 1 (minimal changes) and higher level implementations per the Merchant Cloud Tutorials.

Known gotchas

Related routes

Provision a tokenized Visa card credential for an AI agent using the Crossmint Agentic Cards API with Basis Theory vaulting
docs.crossmint.com · 5 steps · unrated
Understand Mastercard Digital Enablement Service (MDES) tokenization concepts including provisioning flow and token cryptogram usage
Network-token provisioning · 6 steps · unrated
Enroll in the Mastercard Agent Pay for Machines (AP4M) protocol and issue Verifiable Intent credentials for your agent so it can transact across Mastercard's card and stablecoin rails
www.mastercard.com/us/en/business/artificial-intelligence/mastercard-agent-pay.html · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans