Every action checked against the exact mandate your customer signed.
A mandate is the customer-approved boundary for a later action. Attesso authorizes each proposed action against that exact mandate and returns a decision with signed evidence. You keep your own payment provider and bind each authorization to it. Attesso never holds or moves money.
Built in stages, described plainly.
A mandate enters Attesso as a native passkey mandate (available in sandbox) or a verified AP2 mandate (in development). Attesso normalizes it, evaluates each proposed action against the exact mandate, controls single use, and preserves evidence.
Attesso returns the decision, lifecycle state, and signed evidence. You then execute on your own qualified provider, whose external rail returns ordered acceptance or invalidation proof.
You keep your rail. Attesso controls the spend.
A platform creates a bounded mandate and sends the customer to hosted passkey approval. When an agent proposes an action, Attesso evaluates it against the exact mandate and returns a decision. You then execute on your own booking, checkout, or payment provider.
- Authorize a proposed action against the exact mandate a user signed.
- Evaluate every supported constraint deterministically and fail closed on unknowns.
- Maintain single-use authorization state across retries, concurrency, expiry, and revocation.
- Produce signed evidence anyone can verify, without trusting Attesso.
The execution rail stays outside Attesso.
The platform retains its booking, checkout, payment, and fulfillment systems. Attesso supplies bounded authority; it does not act as Merchant, payment-method provider, wallet, or settlement system.
You bind each authorization to your own payment provider and execute. Attesso never holds or moves money, so it needs no payment license and holds no float.
The action matches every known constraint and one provider-fenced authority chain is provisioned.
A known policy or lifecycle condition prevents the proposed action.
Attesso cannot establish eligibility, so execution must not continue.
Each result is accompanied by signed evidence anyone can verify.
Have an asynchronous action and an execution rail?
We will map the mandate, your execution rail, and the evidence you need with your engineering team.