A product discussed on AI Engineer.

Your Agent Just Authorized What?! — Jay Mok & Ben Coumes, Paypal
Sep 1, 2026 · 16:07
PayPal's Jay Mok and Ben Coumes tie agent authorization to three questions — did the human authorize it, is it allowed in scope, can you prove it later — answered by stakes and familiarity. Low stakes is the coding agent: allow/ask/deny permissions plus system logs, since actions revert. Medium stakes is money in a closed ecosystem — Evermind's shared vault plus OAuth scopes, with the amount-bound mandate and transaction logs settling disputes. High stakes: autonomous payments between strangers need a layered selective disclosure JWT per FIDO/AP2 — merchants verify checkout, processors verify the mandate. The approval token inverts the flow: users approve before an agent finds an item; PayPal returns a payload with amount, expiry and merchant, starting with Gemini.

The Agentic Commerce Stack — Ahnaf Prio, Best Buy
Aug 27, 2026 · 20:38
Ahnaf Prio, Senior Engineering Manager at Best Buy, argues agentic shopping now runs on standardized commerce primitives rather than browser automation, with 45% of agent sessions on ChatGPT and Gemini already touching shopping. He explains why screenshot/DOM agents failed and maps MCP, A2A, OpenAI's ACP, Google's UCP, and AP2 payment mandates. Merchants push product feeds because M merchants times N products does not scale; payments today use shared tokens or Google Pay. His live demo has his cat Jenny as a bakery agent on Cerebras at 3,000 tokens per second, showing checkout state transitions and an AP2 token with spend ceiling and revocation URL. He closes with evals for behavior, protocol compliance and latency, citing Chipotle's agent answering programming questions as a whack-a-mole caution.
Powered by PodHood