Before money moves

Agentic payments are not fully here yet.

An agent can already choose a product, fill a basket and call a payment API. That is not the same as a payment a merchant, a finance team or a buyer can stand behind. What is still missing is a permission and execution boundary that runs before money moves. That is where BoundProof sits. AffixIO does not replace the payment provider.

The short answer

The model is ahead of the decision.

Agentic software is a real change from a chatbot. It can pursue a goal, pick a next step and adapt when the page or the price changes. Payments do not become agentic just because that software can reach a checkout. A payment is agentic, in any sense an organisation can operate, only when someone other than the agent has already decided that this spend is allowed.

Open protocols that let agents call tools, talk to each other or hand a payment instruction to a rail are necessary plumbing. They are also young, and they are not a policy. A vendor orchestrator that wants to coordinate everyone else's agents is a product strategy, not a neutral check. Neither one answers the question the merchant actually has: may this agent spend this amount, with this counterparty, under this mandate, right now?

  1. Askthe agent proposes a spend
  2. Boundmandate, amount, merchant, expiry
  3. Decideallow, deny or review
  4. Then payon the merchant's own provider

What is still missing

Three gaps sit in front of the charge.

01

A rule specific enough to enforce

Who may spend, with whom, up to what amount, in which category, and until when. A chat transcript, a prompt, or a standing "the agent can buy things" instruction is not that rule. If two systems describe the same supplier or the same limit differently, both can be internally consistent and the payment can still be wrong.

02

A check the spender does not grade

If the same system proposes the purchase and approves it, there is no boundary. The organisation still has to own the definitions, the mandate and the person accountable when the numbers do not reconcile. No model supplies that. BoundProof evaluates the rule the merchant configured. It does not invent the meaning of "allowed".

03

A receipt that outlives the session

Later, risk, finance and support need to see what was authorised without parking a second copy of the customer's payment data. BoundProof receipts are signed with ML-DSA-65. The integration lineage is the open-source AffixIO SDK. The signed result records the decision that was made. It does not make a later, unchecked action safe, and it does not take the payment.

Where AffixIO sits

BoundProof is the boundary, not the till.

BoundProof is a permission and execution boundary for AI agents and agentic shopping, placed before money moves. The agent asks. The boundary checks the mandate and the limit. A signed outcome comes back. Only then does the merchant's payment provider see a charge the business has already allowed. Card, wallet and account rails stay where the merchant already runs them.

That is a narrower job than "the agentic platform". It is also the job that has to exist before agentic payments are an operating model rather than a demonstration. Teams can switch an agent on faster than they can agree what allowed means. The boundary does not close that organisational gap. It makes the gap visible, because a spend that has no configured rule does not proceed.

Trying it

Two free allocations. Not one number.

Agents

150 free SDK proofs

AI agents receive 150 free AffixIO SDK proofs, with no card, when a BoundProof Agent is provisioned. That allocation is for the agent. It is not the human trial.

People

100 free proofs

Eligible new Hub accounts, for a person, can claim 100 free proofs with no card. One allocation per account holder. It is a separate offer from the agent allocation. Do not collapse the two into a single figure.

Direct answers

What is here, what is not, and what AffixIO will not take over.

Are agentic payments fully here?

Agents can already attempt to buy. What is not settled for most organisations is a permission boundary that runs before money moves, with a receipt of the decision. Until that exists, agentic payments are demonstrated more often than they are operated.

Does BoundProof take the payment?

No. BoundProof is a permission and execution boundary for AI agents and agentic shopping. The payment provider stays the merchant's.

What is on the receipt?

BoundProof receipts are signed with ML-DSA-65. The integration lineage is the open-source AffixIO SDK. A signed receipt records the decision that was made. It does not replace the merchant's payment provider, and it does not make a later unchecked action safe. ML-DSA-65 is the signature on the receipt, not a claim that every part of the stack is post-quantum secure.

How do the free proofs split?

AI agents receive 150 free SDK proofs with no card. Eligible new Hub accounts for people receive 100 free proofs with no card. These are separate allocations.

Free proof allocations

Agents get 150 free proofs. Humans get 100. No card required.

AI agents receive 150 free AffixIO SDK proofs on BoundProof Agent provision. Eligible new Hub account holders (humans) can claim one allocation of 100 free SDK proofs to test AffixIO verification, agentic payment checks, transaction intent proof and signed yes, no or review outcomes.

Terms: one allocation per account holder, per person or business owner. No card is required. Proofs expire after 30 days. Duplicate, shared, automated or abusive signups may be refused or removed. Agents: /boundproof/agent/. Humans: Hub onboarding with offer params.

See free proofs split