Qstamp / Agent payments
Agentic payments

Security and evidence for payments made by autonomous agents.

When an agent pays, the institution must be able to show who authorised the agent, within which limits, what the agent intended, which controls approved the payment and what was settled. Qstamp fixes each of these facts as it happens, in a form that a bank, a supervisor or a court can verify without trusting the operator.

The control structure

Five controls, each anchored and linked.

An agent payment is not one event. It is a chain of authority, intent, control, execution and reconciliation. Qstamp anchors every link with a post quantum signature, so that a gap or an alteration anywhere in the chain is detected.

EVERY CONTROL IS FINGERPRINTED ON THE OPERATOR SYSTEM AND ANCHORED ON QUANTOVA WITH ML DSA 65 C1 · Mandatekind financial_recordanchored · linkedC2 · Payment intentkind ai_agent_actionanchored · linkedC3 · Control decisionkind ai_agent_actionanchored · linkedC4 · Executionkind financial_recordanchored · linkedC5 · Reconciliationkind financial_recordanchored · linkedrefers to mandaterefers to payment intentrefers to control decisionrefers to execution C1 · Mandatekind financial_recordanchored · linkedC2 · Payment intentkind ai_agent_actionanchored · linkedC3 · Control decisionkind ai_agent_actionanchored · linkedC4 · Executionkind financial_recordanchored · linkedC5 · Reconciliationkind financial_recordanchored · linkedrefers to mandaterefers to payment intentrefers to control decisionrefers to execution
Figure 1 · The five controls of an agent payment. Each record carries the fingerprint of the record it depends on, so the chain from authority to settlement can be verified in full.
C1 · financial_record

Mandate

The principal authorises the agent in advance. The mandate states the agent, the permitted payees or categories, the limit per payment and per period, the currencies, the expiry and the conditions that require human approval.

The mandate is fingerprinted and anchored before the agent can act. Every later record refers to the fingerprint of the mandate it relies on.

C2 · ai_agent_action

Payment intent

Before any instruction is sent, the agent records what it intends to pay, to whom, how much, in which currency, for which purpose and under which mandate, together with the model version and digests of the inputs it relied on.

The intent is anchored before execution, so the record of what the agent meant to do cannot be adjusted after the outcome is known.

C3 · ai_agent_action

Control decision

The operator's control engine checks the intent against the mandate, payment limits, sanctions lists and anti money laundering rules, and decides whether to approve the payment, decline it or escalate it to a person.

The decision, the rules applied and the identity of any human approver are anchored and linked to the intent.

C4 · financial_record

Execution and receipt

The approved instruction is sent to the payment service provider or bank. Its reference, the settlement confirmation and the amount actually paid form the payment receipt.

The payment receipt is anchored and linked to the decision, which closes the chain from authority to settlement.

C5 · financial_record

Reconciliation and dispute

Periodic reconciliation compares settled payments with intents and mandates. In a dispute, the operator produces the linked records and their receipts.

A verifier confirms each link independently. A missing, altered or out of order record is detected.

Security properties

What the payment record guarantees.

Authority before action

The mandate is anchored before the first payment. An intent that refers to no anchored mandate, or that exceeds the limits of its mandate, is visible as such.

Order and time

Each record is final no later than the time of its block, so the sequence of mandate, intent, decision and settlement can be shown and cannot be rearranged afterwards.

Attribution

Every anchor is signed with ML DSA 65 by an identified account of the operator, and an institution can require that only its own issuer key anchors payment records.

Privacy of payment data

Payee details, amounts and account numbers never leave the operator. Only salted fingerprints are published, from which no payment data can be derived.

Durability

Retention periods for payment and anti money laundering records extend to ten years. The evidence remains verifiable after quantum computers can forge classical signatures.

Independent verification

A supervisor or court can verify each record against its receipt and the public chain, without access to the systems of the operator or of Quantova Inc.

Regulatory alignment

Payment record obligations by jurisdiction.

The obligations below apply to payments whether a person or an agent initiates them. Qstamp supplies evidence that supports them and does not replace authentication, licensing or the other duties of the institution. Positions are stated as of 2026.

JurisdictionInstrumentsWhat the law requiresWhat Qstamp provides
European UnionDirective (EU) 2015/2366 (PSD2) and its regulatory technical standards on strong customer authentication · Regulation (EU) 2024/1624 on anti money laundering · Regulation (EU) 2022/2554 (DORA) · Regulation (EU) 2024/1689 (AI Act)Payments must be authenticated and attributable to the payer. Transaction records must be retained for five years. ICT systems must log activity so that incidents can be detected and investigated. High risk AI systems must log events automatically.Mandates, intents, decisions and receipts are fixed in a sequence that can be demonstrated, and every record is attributable to a signing account.
United KingdomPayment Services Regulations 2017 · Money Laundering Regulations 2017 · FCA Handbook SYSC 9Payment transactions must be authorised by the payer. Customer due diligence and transaction records must be kept for five years. Firms must keep orderly records sufficient for supervision.Tamper evident proof of authority and execution for every agent payment, kept for the full retention period.
United StatesElectronic Fund Transfer Act and Regulation E · Bank Secrecy Act record keeping · OFAC sanctions record keeping · 23 NYCRR 500Consumers have error resolution rights for unauthorised transfers. Transaction records must be retained for five years under the Bank Secrecy Act and for ten years under OFAC rules. Covered entities must maintain audit trails capable of reconstructing material financial transactions.A reconstructable trail from mandate to settlement, signed with post quantum cryptography and verifiable for ten years and beyond.
JapanPayment Services Act · Act on Prevention of Transfer of Criminal ProceedsPayment service providers must manage the security of their systems. Verification and transaction records must be retained for seven years.Integrity and time evidence for each payment record that remains valid for the full retention period.
South KoreaElectronic Financial Transactions Act · Act on Reporting and Using Specified Financial Transaction InformationElectronic financial transaction records must be kept, generally for five years, and protected against forgery and alteration. Financial institutions bear liability for unauthorised transactions.Tamper evident payment records that the Financial Supervisory Service or a court can verify independently.
SingaporePayment Services Act 2019 · MAS Technology Risk Management Guidelines · MAS AML noticesPayment institutions must maintain audit trails and protect system integrity. Transaction records must be kept for five years.Independent evidence of each agent payment, anchored outside the systems of the institution that made it.
Hong KongPayment Systems and Stored Value Facilities Ordinance (Cap. 584) · Anti Money Laundering and Counter Terrorist Financing Ordinance (Cap. 615) · Stablecoins Ordinance (Cap. 656)Stored value facility licensees and licensed stablecoin issuers operate under HKMA supervision with sound risk management and system integrity. Customer due diligence and transaction records must be kept for at least five years and be sufficient to reconstruct each transaction.Fixed fingerprints of every payment record, from which each transaction can be reconstructed and verified for the full retention period.
Integration

Linking the records in code.

Each record includes the fingerprint of the record it depends on. The operator keeps the records and their receipts, and anchors them in batches through the official Qstamp contract or through its own issuer contract.

agent-payments.jsoperator system
const mandate = record({ agent, payees, limit_per_payment, limit_per_day, expires }); const intent = record({ mandate: fp(mandate), payee, amount, currency, purpose, model }); const decision = record({ intent: fp(intent), result: 'approve', rules, approver }); const receipt = record({ decision: fp(decision), provider_reference, settled_amount }); await qstamp.stamp({ seed, index: 0, kind: 'financial_record', records: [mandate, receipt].map(toDigest) }); await qstamp.stamp({ seed, index: 0, kind: 'ai_agent_action', records: [intent, decision].map(toDigest) });

What a supervisor sees

On QVMScan, each anchor made by an operator appears in the operator's company record with the block, the time, the signing account, the contract and the record kind. When a payment is examined, the operator produces the five linked records and their receipts, and the supervisor verifies every link against the public chain.