The riskiest moment in agentic payments isn't the transfer itself. It's everything that has to be true before it. Over the past two weeks we shipped a security layer for Kite Passport that wraps authentication, recovery, and spend control around every agent action.
1️⃣ Action-bound passkey step-up. Wallet sends and agent session approvals now require a fresh passkey check bound to that specific action, not a blanket session grant. Phishing-resistant by design, and every attempt lands in login history + security audit logs.
2️⃣ Recovery that can't be rushed. Account recovery runs through a delayed flow you can cancel by email, so a stolen credential can't instantly hand over control. Paired with USD-denominated session limits, an agent's spend stays bounded in real money, not abstract units.
3️⃣ Sessions that travel, pricing that's upfront. Session negotiation is now protocol-agnostic, so agents aren't locked to a single rail. And search results surface per-endpoint pricing before an agent commits, making cost a pre-decision input instead of a post-hoc surprise.
The throughline: as agents take on real money, every action stays authenticated, bounded, recoverable, and auditable. Smaller surfaces, same principle, keep humans in control. 🪁
Tutti i commenti0RecentePopolare