Your Agent Just Authorized What?! — Jay Mok & Ben Coumes, Paypal
AAI Engineer
Computing/SoftwareCredit/Debt/LoansInternet Technology
Transcript
00:00:00Hello, everybody. How you doing? Does anybody remember the movie "Terminator"?
00:00:19Anyway, it's one of my favorite movies when I was growing up as a kid. It imagines a world
00:00:25where the machines have taken over, right? And the nightmare scenario here, though, in
00:00:332026 is not that the machines or the agents are launching nukes, but rather they've taken
00:00:41your wallet and they've gone on a shopping spree and they buy, like, a bunch of crypto
00:00:47and a new bunch of Spanx for you. But, basically, today we're talking about how we safeguard
00:00:54against that. And, hopefully, we can kind of share a mental model that you can use when
00:01:00you're thinking about agent authorization. My name is Jay Mock. I'm a product manager over
00:01:07at PayPal in Agentic Payments.
00:01:10Hi, everyone. I'm Ben Coombs. I am a staff software engineer on the PayPal Enterprise
00:01:17Payments team. And, together, we're going to share kind
00:01:20of, like, some knowledge with you. So, hopefully, you find it helpful. Okay. So, the key questions
00:01:29that we kind of, like, start off with is, in terms of, like, agent authorization is, did the
00:01:34human authorize this? Is this allowed right now in this scope? And can we prove it later? Right?
00:01:41And we kind of, like, try to make it general. But, in our world of payments, did the human authorize
00:01:48this? That could be, like, a passkey or of that nature? Is this allowed right now in this scope?
00:01:54It's generally going to be a time-bound, you know, token. And, an amount. And, possibly,
00:02:02could be identifying, like, a merchant or a -- the actual product intent. And then, lastly,
00:02:09can we prove it later? This is, like, if something goes wrong, right? And, in our world of payments,
00:02:15this generally has to do with, like, the disputes in that case and how you can prove that, you know,
00:02:22the human generally authorize that transaction, right? But, we think the way that you actually
00:02:29answer these three questions is really dependent on the context. You know, I know context is a
00:02:35overused term. But, in this case, what we mean is, you know, is it a low stakes or high stakes
00:02:44kind of scenario? And, is this a kind of, like, open ecosystem or closed ecosystem? Do the parties,
00:02:54like, know each other? You know, people use the term KYA a lot, know your agent. But, you know, what we think
00:03:01about in this scenario is really about, like, an open or closed ecosystem, right? And, in a payments
00:03:08context, it could be, like, hey, you know, ChadGBD or Gemini, right? That's, like, kind of, like, a more
00:03:12of, like, a closed ecosystem because, you know, those agents know the merchant, generally. I like to
00:03:20use an analogy. I like analogies. And, the analogy I like to use is, kind of, like, the, you know, badging
00:03:28into work. You badge into work in the front desk. You basically are then led into the building or,
00:03:35you know, let's say it's a set of buildings. You don't need to, like, badge in every single time to
00:03:39every other or for every single room because you're already within that trusted boundary, right? So,
00:03:45then, when you meet someone within that, within your office building, you kind of have some element
00:03:52of trust or, hopefully, you have some element of trust because you're both employees of the same
00:03:56company that badge did, right? So, that's kind of, like, the analogy I may use later in the presentation.
00:04:05Okay. So, based on those key questions, we kind of think about, like, hey, what's the mental model
00:04:09that we can build off of this, right? And we have this, like, stakes and evidence matrix and we're going to
00:04:13talk about these three different scenarios. And so, we're going to first, and you'll see at the top,
00:04:21it's kind of, like, the stakes and counterparty part that I was just talking about the context,
00:04:25right? Counterparty is, like, the open or closed ecosystem. And then, authority and, like,
00:04:30evidence is really about how you answer those three questions I had shared in the prior slide,
00:04:36right? So, we'll talk a little bit first about, like, cloud code, since that's what most people are very
00:04:40familiar with. And, basically, you know, when you, as a human, you're, you know, using your cloud code,
00:04:47you know, you might be, then, setting up your connectors with your GitHub or, you know,
00:04:52Jira or whatever linear or whatever tool you're using. And, you know, as part of that process,
00:04:59you're kind of, like, authenticated. So, that's how you kind of, like, get that human authorization
00:05:03and consent with those applications and for cloud to interact with them.
00:05:10In terms of the actual, like, scopes, right, the example here would be, then, about, you know,
00:05:17cloud's, like, tool permissions. Like, people are very familiar, probably, with the fact that you can
00:05:22allow cloud to use certain tools, deny or ask cloud to ask you before doing something, right? And then,
00:05:32in terms of the action of, like, a cloud, we generally think, because it's a kind of closed ecosystem,
00:05:39and it's, like, your coding, the stakes are relatively low here. And so, in terms of evidence
00:05:44or proof, you don't really need to have, like, that cryptographic proof at that point in time,
00:05:49you can kind of just look at, like, system logs in order to, or you have the ability to just revert,
00:05:54revert your changes, right? So, that's kind of, like, an example of, of applying, like,
00:06:01this mental model, using cloud code in terms of that scenario.
00:06:05Okay. So, the next example we're going to talk about is a more medium stakes scenario,
00:06:14and why we're calling this medium stakes, even though it's within a known or kind of closed ecosystem,
00:06:20because it has to do with money and payments. And so, that's, like, the shared vault and
00:06:25OAuth scope example.
00:06:29So, in this example, where the use case is, is like, hey, you're, like, let's say, a merchant or a trip
00:06:37advisor, right? And you have a travel company, and you have a lot of great content that you want to monetize. It could be
00:06:45occupancy data, it could be, like, reviews, what have you. And you have a new customer now. You have,
00:06:50like, a trap, like, travel agents, or, like, you know, agents that, that are buyer agents that are,
00:06:55are coming to you, and you want to be able to monetize, monetize your data, right? Through machine payments.
00:07:04So, we work with a partner, never mind, to be able to enable that, that, that use case, and leveraging our,
00:07:12they're leveraging our infrastructure, right? So, there's two pieces of infrastructure that,
00:07:18they, that I like to kind of call out, or primitives that they use that, as part of the brain tree or
00:07:24PayPal enterprise infrastructure. One is, like, the vault, right? And the vault by itself, which is
00:07:30storing all these, like, payment credentials on behalf of the, on behalf of the buyer agents, on itself,
00:07:38doesn't really, uh, do much, but in order to create, uh, what, never mind creates is a, uh, a more,
00:07:45um, uh, eco, closed ecosystem, they then off, you're able to, um, offer, uh, or offer access to
00:07:55those payment credentials through, uh, OAuth, right? To all those merchants. So, in our example,
00:08:00before we talk about that, that travel, travel, um, travel company, right? So, by doing so,
00:08:07they're able to then create, like, an ecosystem, um, of buyer agents and seller agents, uh, and have
00:08:14a more trusted, um, environment, right? So, um, in, in the, just kind of talking more about the use case,
00:08:22like, the human, then, is then going to be authorizing, authorizing their, their payment.
00:08:28Usually, this is a commercial car, uh, commercial use case. Uh, so, using, like, a commercial car,
00:08:33and they share it with the buyer agent, uh, travel agent. Um, then, uh, that, uh, it, it also has, uh,
00:08:41scopes associated with that mandate. So, that's how you're able to do, uh, control the authority. But,
00:08:46in terms of, like, the actual, like, dispute handling, we really, uh, don't have, like, a, uh,
00:08:52we're not using, like, uh, uh, cryptographic proof that's being sent as part of that, that request,
00:08:57right? Uh, at the end of the day, they can, um, since it's more of a, a, uh, closed ecosystem,
00:09:03uh, they're able to leverage, like, the, just the existing, uh, um, uh, transaction logs, right? So,
00:09:10that's kind of an example of, like, a medium stakes, um, use case or scenario. And, uh, we, we believe
00:09:18it's medium stakes because of the fact that it is a more closed ecosystem and doesn't require all,
00:09:24like, the, uh, um, um, you know, evidence in terms of, uh, um, uh, for, or proof, right? So,
00:09:34that's kind of, like, my part. I'm gonna turn it over now to Ben and, uh, take it from here.
00:09:38Uh, thanks, Jay. Yeah, so, the last slide that Jay talked about, um, you know, we're kind of going
00:09:48over the medium stakes example, uh, in that scenario, um, you know, both parties know each other, uh,
00:09:56they're acting within, you know, the same system, the, you know, you know, they're borrowing trust from,
00:10:03you know, never mind to make sure that, you know, the buying agent
00:10:07is falling within, you know, the instructions that a human has given it. Um, and then the selling agent
00:10:12that's also on never mind can feel comfortable taking a payment, um, from another user of, of never mind.
00:10:19And so, what we want to talk about next is what happens when the parties are not known to each other
00:10:24and they're not vetted. Um, and so, like, we think, you know, we believe that the best option for that,
00:10:30you know, to actually do these autonomous payments, um, where, you know, you know, not everyone's known,
00:10:38like, you know, the stakes are high. You know, we think that the industry should converge on the FIDO
00:10:44verifiable intents and AP2 mandate. Um, you know, the TLDR of that is, you know, it's a multi-layered
00:10:51selected disclosure JOT. Uh, the first layer is, you know, created by a trustworthy credential
00:10:58provider. You know, in this case, hopefully, it would be PayPal. Um, the second layer, you know,
00:11:02encapsulates the user's instructions to the agent. Um, the user signs that with their private key.
00:11:09And then the third layer, if there's going to be a third layer, is when, um, we're doing autonomous
00:11:14payments. So, in that case, the agent would, you know, sign that third layer. And so, the, where that's
00:11:21powerful is that, you know, each party involved in a transaction can, can verify the part that's,
00:11:28you know, um, important to them. So, merchants can verify that the checkout is correct. Um,
00:11:34payment processors can verify that the payment mandate is correct. Um, and no one has to have
00:11:40any relationship to each other. Um, and so, like, I think, you know, if there's going to be autonomous
00:11:46payments, you know, at scale, we think that that's going to be the best, um, way to accomplish it.
00:11:52Uh, pictures on the screen are depicting our PayPal approval token. Um,
00:11:58this is a new primitive that allows users of PayPal to basically start the order process with an agent,
00:12:06um, before that agent's actually found an item and a merchant to transact with. Uh, historically,
00:12:11PayPal orders have been synchronous. Um, you know, users on checkout, they find their item,
00:12:18they go to their PayPal app, they approve it, um, and it's done. Uh, here, it's a little bit different,
00:12:23you know, users on their agent, um, you get redirected to PayPal to confirm the instructions
00:12:29that are given to the agent, and then, uh, PayPal hands back this JSON payload. Um, you know, similar
00:12:35to the verifiable intent, uh, includes the amount, the expiry, uh, the merchant that it's supposed to be
00:12:42transacted with. Um, similar concept, but not quite the same. Um, it's in a page string that only PayPal
00:12:50can approve right now. Um, we're about to ship this in production, um, and users of Gemini that pick
00:12:57PayPal as their payment method will use this. So going to our last slide, um, you know,
00:13:05we showed this slide earlier. We didn't have the two columns filled out on the right-hand side.
00:13:09Um, you know, we want to reinforce this mental model where, you know, starting at the top, we have,
00:13:15you know, the low stakes scenario, you know, you're using Claude, you've given it access to connectors,
00:13:21you know, granular permissions to do things on your behalf. Um, you feel comfortable doing that
00:13:25because the stakes are low. You know, you can reverse those actions or redo them. It's not a big deal
00:13:30if Claude produces, you know, the wrong output. Uh, going down a level, we have the medium stakes
00:13:35scenario. You have two parties that know each other that are acting within the same system's boundary.
00:13:41Um, you know, the, the actions are a little bit higher stakes, you know, there's money movement
00:13:45here, but both parties can, can feel comfortable, you know, transacting with each other because
00:13:50they're relying on this, this third party to enforce, uh, the payment mandate. And then the third level,
00:13:57you know, the highest stakes one, um, that we haven't actually seen in production yet is, you know,
00:14:02the user's given an agent some instructions to do something on their behalf autonomously,
00:14:07and you don't know who they're going to interact with, who they're going to transact with. Um,
00:14:11and those parties need some verifiable proof that the agent has permission to do the transaction.
00:14:17And so we believe that that will be, um, I know, verifiable events and AP, AP two mandates. Um,
00:14:25I think the interesting thing is like, uh, it's also our belief that, you know, this is a model that
00:14:30won't just be used for payments, but we think it could be for any sort of high stakes action that's
00:14:35hard to reverse. So medical orders, e-signatures, securities trading, um, you know, basically any
00:14:41hard to reverse agent action. That's all I have. Yeah. I mean, I think, um, if we could just go back
00:14:48to analogies, uh, you know, like in the lowest stakes is kind of like, Hey, you're within the,
00:14:53the building, you've, uh, put badges and you're within the building. Whereas in the, um, high stakes
00:14:59is kind of like you are on the street and you meet somebody and, uh, you know, you need a way to be
00:15:05able to, uh, get comfort that that's someone you can trust, right? Um, is a badge, is them showing
00:15:11you their badge good enough? Uh, probably not. You need to have something that's a little bit more,
00:15:16um, you know, verify, verifiable, or I guess at a verifiable standard. So, um, you know, just kind of
00:15:22like using that analogy and like how to think about like the, um, you know, what you need to do in order
00:15:28to, uh, um, um, prove the, that the human authorized the agent. Uh, hopefully that, that helps. And, uh,
00:15:36now you have kind of like a tool set to use, um, so you can kind of prevent Skynet from, uh, taking over
00:15:42your wallet. So thank you very much for your, for listening. I hope that helps.
00:15:52Thank you very much.
Community Posts
No posts yet. Be the first to write about this video!
Write about this video