The robots are ready to spend your money—with permission, of course.
Crossmint announced on April 16 it would let artificial intelligence agents charge purchases directly to Mastercard accounts, a development that inches the financial system closer to a future where software, not people, handles routine buying decisions. The integration, launching through an invite-only program, targets developers building on OpenClaw, an open-source agent framework.
It's a prosaic milestone wrapped in technical complexity. For all the talk of autonomous AI, agents still can't easily buy things. They lack credit cards. They can't pass fraud checks. And handing over raw payment credentials to software that operates independently feels, well, risky.
Crossmint's Lobster.cash payment layer attempts to thread that needle. Working with Mastercard's Agent Pay infrastructure, it routes purchases through traditional card networks while maintaining a cryptographic record proving each transaction fell within boundaries the cardholder set beforehand. Think of it as a permission slip, but one encoded in math rather than a parent's signature.
"Bringing this to lobster.cash means agent users don't need a new wallet or a new card," said Alfonso Gómez-Jordana Mañas, Crossmint's co-founder. "They can put the card they already have to work for their agent."
Whether consumers actually want that remains an open question.
The authorization choreography
The underlying mechanics involve several handoffs. Cardholders define constraints upfront: spending limits, approved merchants, time windows. The agent initiates a purchase, which travels through Mastercard's existing payment rails. But sensitive card details never reach agent infrastructure directly. Instead, a third-party vault operated by Basis Theory—which holds PCI Level 1 and SOC 2 compliance certifications—tokenizes and stores that data. The agent receives network tokens, not the actual account number.
Each transaction gets tagged with what Mastercard calls a "Verifiable Intent" record, a cryptographic proof that the purchase matched the user's pre-approved parameters. Issuers and merchants can independently verify that proof, creating an auditable chain of authorization.
Verifiable Intent itself is a specification Mastercard developed with Google and released on March 5, 2026. The draft protocol, hosted at verifiableintent.dev, uses SD-JWT-based delegation chains to encode permission structures. It's designed to interoperate with competing frameworks: Google's Agent Payments Protocol, the Universal Commerce Protocol, and the Agentic Commerce Protocol that OpenAI built with Stripe.
That cross-compatibility is deliberate. Mastercard appears to be positioning itself as infrastructure—authorization plumbing that works regardless of which checkout system or agent platform a developer chooses. Not the storefront, just the locks and keys.
A year in the making, sort of

Mastercard first announced Agent Pay on April 29, 2025. By early March, the company said it had processed live agent-initiated transactions across Latin America and the Caribbean, with several major banks testing the system. Those pilot programs involved institutions like Santander, Commonwealth Bank of Australia, DBS, and UOB.
The Lobster.cash integration is different—it's aimed at open agent ecosystems rather than closed banking trials. OpenClaw, according to Crossmint, has been used to deploy over one million agents across more than 20 messaging platforms, though that figure comes directly from the vendor and hasn't been independently verified. Crossmint says it plans to extend support to other frameworks, including Claude Code, Devin, Hermes, and Zo Computer, though timelines for that expansion weren't disclosed.
Pablo Fourez, Mastercard's Chief Digital Officer, described the partnership as extending the card network's existing trust model to agent platforms while preserving the security controls consumers expect. Perhaps more than Mastercard expected, the challenge has been retrofitting payment infrastructure designed for humans clicking buttons to accommodate software making autonomous decisions.
A crowded, fragmented field

Lobster.cash isn't operating in a vacuum. Visa unveiled its Trusted Agent Protocol last October. Google released the Agent Payments Protocol in mid-September, then followed up with the broader Universal Commerce Protocol in January. OpenAI and Stripe introduced their Agentic Commerce Protocol in late September, which now powers checkout features in ChatGPT.
Mastercard's gambit is that Verifiable Intent can serve as a common authorization layer beneath all of those competing systems. The protocol specification explicitly notes compatibility with Google's and OpenAI's approaches, suggesting Mastercard sees its role as certifying intent rather than dictating how checkout flows should work.
The timing isn't accidental. Academic researchers have published multiple analyses this year highlighting safety and abuse risks in widely deployed agent frameworks—systems that often have broad access to email, file storage, and third-party APIs. Verifiable Intent's constraint logic and audit trails directly address those concerns, at least in theory. Whether they hold up under real-world adversarial pressure is another matter.
What's still unclear
Crossmint raised $23.6 million last March in a round led by Ribbit Capital, with Franklin Templeton, Nyca Partners, First Round Capital, and Lightspeed Faction participating. The company describes itself as a wallet, stablecoin, and card-rails platform for agentic payments, claiming more than 40,000 clients—again, a figure provided by the company itself.
The early-access program launches first for OpenClaw developers. No public dates exist for broader availability. Details on which issuers support the system by region, how consumer-facing authentication (like 3D Secure or passkey prompts) gets handled, pricing, and how disputes work when an intent record is involved—all of that remains vague.
What's becoming clearer is the trajectory. Payment infrastructure built for humans is being quietly rebuilt for software agents that shop, book, and pay without checking in. The industry's bet is that programmable constraints and cryptographic receipts can scale trust fast enough to keep pace.
Whether consumers will embrace agents with spending authority, or whether they'll balk at the idea of delegating purchasing decisions to software still learning the ropes—that's the harder question. One a permission slip, however cryptographically sophisticated, can't answer on its own.
