Skip to content
FAQ

Frequently asked questions.

How approvals work, what is billable, how evidence verifies, and what Attesso deliberately leaves out.

01

What Attesso is, and what it is not.

What is Attesso?

Attesso is a B2B authorization and evidence service for agent-led actions. You create a bounded mandate, the end user approves it with a passkey, and Attesso decides whether each later proposed action fits those exact bounds. Your systems execute; Attesso records what was approved and decided.

Who is Attesso for?

Teams whose users pre-authorize something that happens later: travel and rebooking flows, procurement, marketplaces, and the payment or execution providers behind them. If inventory, price, or availability can change after the user leaves, that is the fit.

Does Attesso move money or hold payment credentials?

No. Attesso never holds or moves money, and never stores payment credentials, provider secrets, passkey private keys, or biometric data, so it needs no payment license. It supplies the decision and the evidence; execution stays with you.

How is this different from a payment provider?

A provider processes a payment. Attesso checks that the specific action matches what the user approved, and signs the result so anyone can verify it later. It is PSP-agnostic: you bind each authorization to your own provider.

Do we have to replace our payment stack?

No. You keep your provider, checkout, and fulfillment systems. Attesso returns a decision; you execute on your existing rail and report the outcome back.

Why passkeys?

Approving a mandate is a hosted WebAuthn ceremony. The user approves one exact mandate on their own device, with no password and no shared secret, and the session is short-lived, single-use, and bound to that mandate.

02

One approval, exact bounds, one execution.

What exactly is a mandate?

An immutable, user-approved statement of allowed actions within fixed policy and time bounds: which action, under which constraints, and for how long. The user approves the exact mandate, and nothing about it can change afterward.

What happens when the agent proposes an action?

Attesso evaluates it deterministically against the exact mandate and returns ALLOW, DENY, or INDETERMINATE. Unsupported or unmet conditions fail closed: if eligibility cannot be established, execution must not continue.

What does an ALLOW give us?

One reservation for that proposed action, valid until its execution deadline. It is not standing permission: execute within the window, or let the reservation release.

What does commit mean?

You report that your executor accepted the action. A single-use mandate is consumed permanently; a recurring mandate draws down its period budget and stays active.

What if the action does not happen?

You cancel on definite non-acceptance and the reservation is released. If a provider call times out or the result is ambiguous, reconcile against the executor first, then commit or cancel; retries and replays are safe by design.

Can an approved mandate be changed or stopped?

It cannot be changed; new terms require a new approval. A mandate that has not committed can be revoked, which ends it permanently.

Do you support recurring authority?

Yes. A recurring mandate carries a period schedule with a per-period budget and a term of up to 400 days. Every authorization must fit within its period.

What happens when a mandate expires?

An active mandate expires at the end of its validity if nothing committed first, and any open reservation is closed with it.

03

Raw HTTP, hosted approval, your rail.

How do we integrate?

Server to server, over raw HTTP: create the mandate, send the user through the hosted approval, authorize the proposed action, execute on your rail, and commit or cancel. The quickstart walks the whole loop with a free test key.

Is there an SDK or a CLI?

No. Attesso is deliberately SDK-free: the public integration surface is raw HTTP plus a runnable quickstart and guides, so there is no client library to track or keep in sync.

What does the end user see?

A short-lived hosted page that shows the exact mandate and asks for a passkey approval. There is nothing to install and nothing for you to build.

Where does execution happen?

On your systems. Attesso returns the decision and the evidence; you execute on your own provider, then bind the external references back with commit or cancel.

What about AP2 and other agent protocols?

Native Attesso is fully usable without AP2. We are exploring an AP2 v0.2 human-not-present adapter as a future compatibility option, with Attesso as the verifier, not the merchant or payment-method provider. No conformance is claimed. Read the AP2 position.

The boundary

Attesso authorizes and records. Your rail executes.

Attesso never holds or moves money, never stores payment credentials, and never calls your provider. It returns the decision and the evidence; execution stays where it belongs.

04

Free to prove it, billed only when live.

How do we try it?

Create an Organization, initialize Test, and make a free test API key. Test covers the full lifecycle, including real passkey approvals, and none of it is billed. The playground runs a complete flow in your browser without an account.

What is different about live?

Live is a separate deployment, database, and approval trust. Live keys require an active, server-verified Stripe entitlement; test keys keep working without billing.

Can test activity become live?

No. Test and live are separate configured deployments and databases by design. A live flow starts with live keys and its own trust configuration.

05

One price, one billable event.

What does it cost?

0.5% + $0.25 USD per authorized transaction: 0.5% of the amount the mandate authorizes plus $0.25, with a $0.30 minimum and a $25 maximum. No base fee, no monthly minimum, no tiers. Applicable taxes are additional. See pricing.

What counts as an authorized transaction?

The first verified approval of a live mandate, moving it to ACTIVE or SCHEDULED. Test approvals, failed attempts, rejected, revoked, or expired mandates, replays, and execution attempts are never billed.

When are we invoiced?

Stripe Billing invoices in arrears at the end of your monthly subscription period. A Stripe invoice below the processor's minimum charge may carry forward; there is no Attesso-side minimum or base fee.

How does cancellation work?

Stripe's Customer Portal owns payment methods, invoices, and cancellation, configured for the end of the current period. If entitlement lapses, live keys suspend rather than delete, and they resume when entitlement is restored. Test stays usable throughout.

06

Signed, verifiable, append-only.

What exactly gets signed?

Every lifecycle step: the mandate, the decision, state changes, and any external reports your executor supplies, each explicitly source-labelled. The signed evidence bundle is the durable record of what was authorized and what happened.

How do we verify evidence without your dashboard?

Signatures verify against Attesso's published keys, independently of our service. Reference implementations in Node.js, Go, and Python check a real bundle step by step. Read the verify guide.

What is the provable record?

An append-only, tamper-evident log over every mandate event, with signed checkpoints and independent RFC 3161 time anchors. Hold a checkpoint snapshot, and later anyone can prove that nothing before it was rewritten or removed, without trusting Attesso. Check the record.

What does Attesso never store?

Payment credentials, provider secrets, passkey private keys, and biometric data. API keys are hashed at rest, shown once at creation, and limited to two active slots per Organization and environment.

Can a record be edited or deleted?

The record is append-only by design. A correction or a late report appears as a new, timestamped entry; nothing already committed can be silently changed, reordered, or dropped.

Is Attesso a licensed payment service?

Attesso never holds or moves money, so it needs no payment license. It adds authorization and evidence alongside the regulated providers that do the paying.

07

Who we are, and how to start.

Who is behind Attesso?

Attesso B.V., a Dutch company registered under KVK 42040136, founded by Douwe Kramer and Sid van Kalken. Read more on the about page.

How do we start?

Create a free test key and put one mandate through its full lifecycle. Then talk to us about live and a pilot.

Still deciding?

Create a free test key and run one mandate end to end, or ask us directly.