How virtual cards for AI agents work

The flow, as described in the announcement, starts with the user connecting their AI agent to their Mastercard account through Alchemy. That's where the real limits get set: spending caps, approved merchants, and allowed product categories. Within that range, the agent buys without the user stepping in for each individual transaction. On the developer side, Alchemy's CLI can configure an agent in under a minute, and full integration takes less than five.

Visa already had a prior partnership with Alchemy, so Mastercard arrives second to a move American Express is also tracking — the signal is that all three major payment networks are betting, in parallel, that autonomous agents are becoming a real purchasing channel, not an isolated experiment.

"Agentic tokens": the security piece behind every purchase

The system's security rests on what Mastercard calls "agentic tokens": tokens that carry the user's declared intent along with the transaction details, so the network can verify the agent is operating within the instructions it was given. Mastercard describes it as "a card with identity, purpose and trust built in." Jorn Lambert, Mastercard's Chief Product Officer, put the company's stance plainly: "We believe it's not a question of if, but of when and how fast."

Alchemy frames the shift even more directly: "The checkout button is dying. AI agents are going to discover, compare and buy products on behalf of their users." It's the same logic behind ChatGPT's scheduled tasks integrated with Gmail, Slack and GitHub, or work copilots that already operate with some autonomy — except here, the point of no return is the payment itself, not an administrative task.

"The first large-scale fraud incident with this mechanism will decide whether agent cards survive as they are — or get regulated into something unrecognizable."

What regulation still doesn't answer

The original report correctly flags the regulatory gap: current payment rules like PSD2, and the upcoming PSD3 in Europe, were designed for transactions a person initiates — not an autonomous system. Mastercard says its agentic tokens are compatible with PSD3, which allows third-party payments with explicit consent and revocation at any time, and that revoking an agent's access is as simple as connecting it. But the core question remains unresolved: if an agent makes an unauthorized purchase because of a prompt injection on a malicious site, a misread instruction, or a store's dark pattern — who's responsible? The user, Alchemy, Mastercard, or the agent's maker?

That ambiguity isn't a minor detail. The first large-scale fraud incident using this mechanism will likely decide whether agent cards survive as they are, or end up regulated into something unrecognizable.

What this means for businesses and consumers

For an e-commerce business or a local company, this technology isn't directly available yet, but it points to where global online retail is headed: agents buying straight from the store, with no human reviewing the cart before paying. If your business depends on a checkout flow, promotions or price comparisons built for a human shopper, it's worth asking how your store looks to an agent that compares and decides in milliseconds instead of a person browsing at their own pace.

For consumers, the practical takeaway is simpler: any integration like this, once it arrives, should be set up with the same limits the system itself describes — low spending caps, specific merchants, and easy revocation — until it's clear who's on the hook when something goes wrong.

Talk about your project →