Your Agent Just Authorized What?! — Jay Mok & Ben Coumes, Paypal

AAI Engineer
Computing/SoftwareCredit/Debt/LoansInternet Technology

Transcript

00:00:00Hello, everybody. How you doing? Does anybody remember the movie "Terminator"?
00:00:19Anyway, it's one of my favorite movies when I was growing up as a kid. It imagines a world
00:00:25where the machines have taken over, right? And the nightmare scenario here, though, in
00:00:332026 is not that the machines or the agents are launching nukes, but rather they've taken
00:00:41your wallet and they've gone on a shopping spree and they buy, like, a bunch of crypto
00:00:47and a new bunch of Spanx for you. But, basically, today we're talking about how we safeguard
00:00:54against that. And, hopefully, we can kind of share a mental model that you can use when
00:01:00you're thinking about agent authorization. My name is Jay Mock. I'm a product manager over
00:01:07at PayPal in Agentic Payments.
00:01:10Hi, everyone. I'm Ben Coombs. I am a staff software engineer on the PayPal Enterprise
00:01:17Payments team. And, together, we're going to share kind
00:01:20of, like, some knowledge with you. So, hopefully, you find it helpful. Okay. So, the key questions
00:01:29that we kind of, like, start off with is, in terms of, like, agent authorization is, did the
00:01:34human authorize this? Is this allowed right now in this scope? And can we prove it later? Right?
00:01:41And we kind of, like, try to make it general. But, in our world of payments, did the human authorize
00:01:48this? That could be, like, a passkey or of that nature? Is this allowed right now in this scope?
00:01:54It's generally going to be a time-bound, you know, token. And, an amount. And, possibly,
00:02:02could be identifying, like, a merchant or a -- the actual product intent. And then, lastly,
00:02:09can we prove it later? This is, like, if something goes wrong, right? And, in our world of payments,
00:02:15this generally has to do with, like, the disputes in that case and how you can prove that, you know,
00:02:22the human generally authorize that transaction, right? But, we think the way that you actually
00:02:29answer these three questions is really dependent on the context. You know, I know context is a
00:02:35overused term. But, in this case, what we mean is, you know, is it a low stakes or high stakes
00:02:44kind of scenario? And, is this a kind of, like, open ecosystem or closed ecosystem? Do the parties,
00:02:54like, know each other? You know, people use the term KYA a lot, know your agent. But, you know, what we think
00:03:01about in this scenario is really about, like, an open or closed ecosystem, right? And, in a payments
00:03:08context, it could be, like, hey, you know, ChadGBD or Gemini, right? That's, like, kind of, like, a more
00:03:12of, like, a closed ecosystem because, you know, those agents know the merchant, generally. I like to
00:03:20use an analogy. I like analogies. And, the analogy I like to use is, kind of, like, the, you know, badging
00:03:28into work. You badge into work in the front desk. You basically are then led into the building or,
00:03:35you know, let's say it's a set of buildings. You don't need to, like, badge in every single time to
00:03:39every other or for every single room because you're already within that trusted boundary, right? So,
00:03:45then, when you meet someone within that, within your office building, you kind of have some element
00:03:52of trust or, hopefully, you have some element of trust because you're both employees of the same
00:03:56company that badge did, right? So, that's kind of, like, the analogy I may use later in the presentation.
00:04:05Okay. So, based on those key questions, we kind of think about, like, hey, what's the mental model
00:04:09that we can build off of this, right? And we have this, like, stakes and evidence matrix and we're going to
00:04:13talk about these three different scenarios. And so, we're going to first, and you'll see at the top,
00:04:21it's kind of, like, the stakes and counterparty part that I was just talking about the context,
00:04:25right? Counterparty is, like, the open or closed ecosystem. And then, authority and, like,
00:04:30evidence is really about how you answer those three questions I had shared in the prior slide,
00:04:36right? So, we'll talk a little bit first about, like, cloud code, since that's what most people are very
00:04:40familiar with. And, basically, you know, when you, as a human, you're, you know, using your cloud code,
00:04:47you know, you might be, then, setting up your connectors with your GitHub or, you know,
00:04:52Jira or whatever linear or whatever tool you're using. And, you know, as part of that process,
00:04:59you're kind of, like, authenticated. So, that's how you kind of, like, get that human authorization
00:05:03and consent with those applications and for cloud to interact with them.
00:05:10In terms of the actual, like, scopes, right, the example here would be, then, about, you know,
00:05:17cloud's, like, tool permissions. Like, people are very familiar, probably, with the fact that you can
00:05:22allow cloud to use certain tools, deny or ask cloud to ask you before doing something, right? And then,
00:05:32in terms of the action of, like, a cloud, we generally think, because it's a kind of closed ecosystem,
00:05:39and it's, like, your coding, the stakes are relatively low here. And so, in terms of evidence
00:05:44or proof, you don't really need to have, like, that cryptographic proof at that point in time,
00:05:49you can kind of just look at, like, system logs in order to, or you have the ability to just revert,
00:05:54revert your changes, right? So, that's kind of, like, an example of, of applying, like,
00:06:01this mental model, using cloud code in terms of that scenario.
00:06:05Okay. So, the next example we're going to talk about is a more medium stakes scenario,
00:06:14and why we're calling this medium stakes, even though it's within a known or kind of closed ecosystem,
00:06:20because it has to do with money and payments. And so, that's, like, the shared vault and
00:06:25OAuth scope example.
00:06:29So, in this example, where the use case is, is like, hey, you're, like, let's say, a merchant or a trip
00:06:37advisor, right? And you have a travel company, and you have a lot of great content that you want to monetize. It could be
00:06:45occupancy data, it could be, like, reviews, what have you. And you have a new customer now. You have,
00:06:50like, a trap, like, travel agents, or, like, you know, agents that, that are buyer agents that are,
00:06:55are coming to you, and you want to be able to monetize, monetize your data, right? Through machine payments.
00:07:04So, we work with a partner, never mind, to be able to enable that, that, that use case, and leveraging our,
00:07:12they're leveraging our infrastructure, right? So, there's two pieces of infrastructure that,
00:07:18they, that I like to kind of call out, or primitives that they use that, as part of the brain tree or
00:07:24PayPal enterprise infrastructure. One is, like, the vault, right? And the vault by itself, which is
00:07:30storing all these, like, payment credentials on behalf of the, on behalf of the buyer agents, on itself,
00:07:38doesn't really, uh, do much, but in order to create, uh, what, never mind creates is a, uh, a more,
00:07:45um, uh, eco, closed ecosystem, they then off, you're able to, um, offer, uh, or offer access to
00:07:55those payment credentials through, uh, OAuth, right? To all those merchants. So, in our example,
00:08:00before we talk about that, that travel, travel, um, travel company, right? So, by doing so,
00:08:07they're able to then create, like, an ecosystem, um, of buyer agents and seller agents, uh, and have
00:08:14a more trusted, um, environment, right? So, um, in, in the, just kind of talking more about the use case,
00:08:22like, the human, then, is then going to be authorizing, authorizing their, their payment.
00:08:28Usually, this is a commercial car, uh, commercial use case. Uh, so, using, like, a commercial car,
00:08:33and they share it with the buyer agent, uh, travel agent. Um, then, uh, that, uh, it, it also has, uh,
00:08:41scopes associated with that mandate. So, that's how you're able to do, uh, control the authority. But,
00:08:46in terms of, like, the actual, like, dispute handling, we really, uh, don't have, like, a, uh,
00:08:52we're not using, like, uh, uh, cryptographic proof that's being sent as part of that, that request,
00:08:57right? Uh, at the end of the day, they can, um, since it's more of a, a, uh, closed ecosystem,
00:09:03uh, they're able to leverage, like, the, just the existing, uh, um, uh, transaction logs, right? So,
00:09:10that's kind of an example of, like, a medium stakes, um, use case or scenario. And, uh, we, we believe
00:09:18it's medium stakes because of the fact that it is a more closed ecosystem and doesn't require all,
00:09:24like, the, uh, um, um, you know, evidence in terms of, uh, um, uh, for, or proof, right? So,
00:09:34that's kind of, like, my part. I'm gonna turn it over now to Ben and, uh, take it from here.
00:09:38Uh, thanks, Jay. Yeah, so, the last slide that Jay talked about, um, you know, we're kind of going
00:09:48over the medium stakes example, uh, in that scenario, um, you know, both parties know each other, uh,
00:09:56they're acting within, you know, the same system, the, you know, you know, they're borrowing trust from,
00:10:03you know, never mind to make sure that, you know, the buying agent
00:10:07is falling within, you know, the instructions that a human has given it. Um, and then the selling agent
00:10:12that's also on never mind can feel comfortable taking a payment, um, from another user of, of never mind.
00:10:19And so, what we want to talk about next is what happens when the parties are not known to each other
00:10:24and they're not vetted. Um, and so, like, we think, you know, we believe that the best option for that,
00:10:30you know, to actually do these autonomous payments, um, where, you know, you know, not everyone's known,
00:10:38like, you know, the stakes are high. You know, we think that the industry should converge on the FIDO
00:10:44verifiable intents and AP2 mandate. Um, you know, the TLDR of that is, you know, it's a multi-layered
00:10:51selected disclosure JOT. Uh, the first layer is, you know, created by a trustworthy credential
00:10:58provider. You know, in this case, hopefully, it would be PayPal. Um, the second layer, you know,
00:11:02encapsulates the user's instructions to the agent. Um, the user signs that with their private key.
00:11:09And then the third layer, if there's going to be a third layer, is when, um, we're doing autonomous
00:11:14payments. So, in that case, the agent would, you know, sign that third layer. And so, the, where that's
00:11:21powerful is that, you know, each party involved in a transaction can, can verify the part that's,
00:11:28you know, um, important to them. So, merchants can verify that the checkout is correct. Um,
00:11:34payment processors can verify that the payment mandate is correct. Um, and no one has to have
00:11:40any relationship to each other. Um, and so, like, I think, you know, if there's going to be autonomous
00:11:46payments, you know, at scale, we think that that's going to be the best, um, way to accomplish it.
00:11:52Uh, pictures on the screen are depicting our PayPal approval token. Um,
00:11:58this is a new primitive that allows users of PayPal to basically start the order process with an agent,
00:12:06um, before that agent's actually found an item and a merchant to transact with. Uh, historically,
00:12:11PayPal orders have been synchronous. Um, you know, users on checkout, they find their item,
00:12:18they go to their PayPal app, they approve it, um, and it's done. Uh, here, it's a little bit different,
00:12:23you know, users on their agent, um, you get redirected to PayPal to confirm the instructions
00:12:29that are given to the agent, and then, uh, PayPal hands back this JSON payload. Um, you know, similar
00:12:35to the verifiable intent, uh, includes the amount, the expiry, uh, the merchant that it's supposed to be
00:12:42transacted with. Um, similar concept, but not quite the same. Um, it's in a page string that only PayPal
00:12:50can approve right now. Um, we're about to ship this in production, um, and users of Gemini that pick
00:12:57PayPal as their payment method will use this. So going to our last slide, um, you know,
00:13:05we showed this slide earlier. We didn't have the two columns filled out on the right-hand side.
00:13:09Um, you know, we want to reinforce this mental model where, you know, starting at the top, we have,
00:13:15you know, the low stakes scenario, you know, you're using Claude, you've given it access to connectors,
00:13:21you know, granular permissions to do things on your behalf. Um, you feel comfortable doing that
00:13:25because the stakes are low. You know, you can reverse those actions or redo them. It's not a big deal
00:13:30if Claude produces, you know, the wrong output. Uh, going down a level, we have the medium stakes
00:13:35scenario. You have two parties that know each other that are acting within the same system's boundary.
00:13:41Um, you know, the, the actions are a little bit higher stakes, you know, there's money movement
00:13:45here, but both parties can, can feel comfortable, you know, transacting with each other because
00:13:50they're relying on this, this third party to enforce, uh, the payment mandate. And then the third level,
00:13:57you know, the highest stakes one, um, that we haven't actually seen in production yet is, you know,
00:14:02the user's given an agent some instructions to do something on their behalf autonomously,
00:14:07and you don't know who they're going to interact with, who they're going to transact with. Um,
00:14:11and those parties need some verifiable proof that the agent has permission to do the transaction.
00:14:17And so we believe that that will be, um, I know, verifiable events and AP, AP two mandates. Um,
00:14:25I think the interesting thing is like, uh, it's also our belief that, you know, this is a model that
00:14:30won't just be used for payments, but we think it could be for any sort of high stakes action that's
00:14:35hard to reverse. So medical orders, e-signatures, securities trading, um, you know, basically any
00:14:41hard to reverse agent action. That's all I have. Yeah. I mean, I think, um, if we could just go back
00:14:48to analogies, uh, you know, like in the lowest stakes is kind of like, Hey, you're within the,
00:14:53the building, you've, uh, put badges and you're within the building. Whereas in the, um, high stakes
00:14:59is kind of like you are on the street and you meet somebody and, uh, you know, you need a way to be
00:15:05able to, uh, get comfort that that's someone you can trust, right? Um, is a badge, is them showing
00:15:11you their badge good enough? Uh, probably not. You need to have something that's a little bit more,
00:15:16um, you know, verify, verifiable, or I guess at a verifiable standard. So, um, you know, just kind of
00:15:22like using that analogy and like how to think about like the, um, you know, what you need to do in order
00:15:28to, uh, um, um, prove the, that the human authorized the agent. Uh, hopefully that, that helps. And, uh,
00:15:36now you have kind of like a tool set to use, um, so you can kind of prevent Skynet from, uh, taking over
00:15:42your wallet. So thank you very much for your, for listening. I hope that helps.
00:15:52Thank you very much.

Key Takeaway

Agent authorization requires a contextual mental model spanning low-stakes system logs, medium-stakes OAuth shared vaults, and high-stakes verifiable intent tokens to prevent unauthorized autonomous spending.

Highlights

  • PayPal builds an approval token primitive for agentic payments that lets users start the order process before an item or merchant is found.

  • Gemini users choosing PayPal as their payment method will use the new PayPal approval token primitive in production.

  • Fido verifiable intents and AP2 mandates use a multi-layered selected disclosure JSON Web Token signed by the user's private key.

  • Payment processors verify payment mandates while merchants verify checkout correctness without requiring prior relationships.

  • Agent authorization frameworks divide scenarios into low stakes cloud coding, medium stakes shared vault operations, and high stakes autonomous multi-party transactions.

Timeline

Core Agent Authorization Questions

  • Agent authorization relies on determining human approval, scope validity, and proof for future disputes.
  • Payment context requires answers dependent on stakes and ecosystem openness.
  • Workplace badge analogies describe operating within trusted trust boundaries.

Human authorization uses methods like passkeys while scopes use time-bound tokens with amounts and merchant intent. Ecosystem openness dictates whether parties know each other beforehand. Working within a trusted office building serves as an analogy for closed ecosystem trust.

Low and Medium Stakes Authorization Scenarios

  • Cloud code integration represents a low stakes closed ecosystem relying on system logs or manual reversions.
  • Shared vaults and OAuth scopes handle medium stakes commercial travel card payments within trusted partners.
  • Transaction logs suffice for dispute handling in closed medium stakes environments without cryptographic proof.

Users set up GitHub and Jira connectors using human authentication while configuring tool permissions. Travel companies monetize occupancy data and reviews through buyer agents using enterprise infrastructure primitives. Vaults store payment credentials on behalf of buyer agents and provide access via OAuth.

High Stakes Autonomous Payments and Approval Tokens

  • Fido verifiable intents and AP2 mandates govern high stakes transactions with unknown counterparties.
  • PayPal approval tokens allow users to start order processes before agents find a specific item or merchant.
  • Verifiable security models extend beyond payments to hard to reverse actions like medical orders and e-signatures.

Multi-layered selected disclosure tokens contain layers from trusted credential providers, user instructions signed with private keys, and autonomous agent signatures. PayPal approval tokens return JSON payloads with amount, expiry, and merchant details. Street interactions without prior familiarity serve as analogies for high stakes trust requirements.

Community Posts

No posts yet. Be the first to write about this video!

Write about this video