How Attesso works
Four steps to authorize agent-led actions without handing payment execution to Attesso.
Create a mandate
Your platform sends Attesso a structured policy derived from the customer's request.
Attesso creates a unique hosted approval link. Your platform remains responsible for identifying the customer who receives it.
Customer approves once
Attesso shows the exact mandate on its hosted approval page. The customer approves it with a passkey.
Biometric data and private keys remain on the customer's device. Attesso stores only the credential data and evidence needed to verify the approval.
Evaluate the proposed action
When an agent finds a matching result, your platform submits the proposed action or payment data to Attesso.
Attesso checks it against the active mandate. The customer does not need to be online again while that mandate remains valid.
Receive a decision and evidence
Attesso returns ALLOW or DENY and appends the decision to the audit record.
Only your platform decides whether to continue to its payment processor or action system. Attesso never executes the transaction.
Ready to discuss an integration?
Attesso is preparing its production API. Talk to us about the smallest safe integration for your platform.
Frequently asked questions
Common questions about mandates, authorization, and integrating Attesso.
What is a spending mandate?
A mandate is a time-limited policy supplied by a platform and approved by its customer with a passkey. It defines which agent-led actions or payments may be authorized.
Does Attesso handle cards or money?
No. Attesso does not issue cards, handle card details, move funds, or settle payments. Your platform and payment processor remain responsible for execution.
How fast is authorization?
Attesso is designed to evaluate both synchronous and asynchronous requests against an active mandate and return an ALLOW or DENY decision without requiring the customer to return.
Does Attesso replace payment authentication requirements?
No. Attesso records the customer-approved mandate and authorization evidence. Your platform and payment provider remain responsible for determining which payment and regulatory requirements apply.
What happens if an AI agent tries to exceed an approved limit?
Attesso returns DENY and records the decision. Your platform must only continue when it receives ALLOW for the proposed action.
Do I need to replace my existing payment processor?
No. Attesso sits before your existing payment or action flow as a neutral authorization layer. Your processor still handles payment execution and settlement.
Questions about integrating Attesso?
Our team will walk you through the setup for your specific platform.