title: "智能体授权了什么?PayPal 的高风险自主支付信任框架"
source_url: "https://www.youtube.com/watch?v=vGn6N4-bxBY"
author: "AI Engineer"
excerpt: "公共早报 PayPal 的 Jay Mok 与 Ben Coumes 提出一套智能体授权的风险与信任框架:当自主操作从可逆的工具调用走向开放且高风险的支付时,权限边界与可验证证据必须同步增强。"
Brief Description
Jay Mok and Ben Coumes of PayPal present a practical model for authorizing AI agents. They frame authorization around three questions---whether a human authorized the action, whether it is allowed in the present scope, and whether the authorization can be proven later---and show how the evidence required changes with the stakes of the action and the trust relationship between parties. Their examples move from low-risk coding agents to payment systems and eventually to open, high-stakes autonomous transactions.
Table of Contents
The three questions behind agent authorization
Context, trust boundaries, and low-stakes agents
Controlled payment authority in a closed ecosystem
Verifiable authorization for open, high-stakes payments
PayPal approval tokens and the broader model
The Three Questions Behind Agent Authorization
Jay Mok: The familiar science-fiction fear is that machines take over. In the nearer-term version, an agent gets access to a wallet, goes on a shopping spree, and makes unwanted purchases. The goal is to develop a mental model that helps prevent that outcome when designing agent authorization.
Jay Mok is a product manager in PayPal's agentic payments organization, and Ben Coumes is a staff software engineer on PayPal's enterprise payments team. They begin with three questions that apply broadly, and especially clearly to payments: Did the human authorize this? Is this action allowed right now and within this scope? Can the authorization be proven later?
Human authorization might be established through a passkey or a similar authentication mechanism. Current authority is usually bounded: a token may have an expiry, an amount limit, a specific merchant, or an identified product intent. The final question matters when something goes wrong. In payments, that often means a dispute and the need to demonstrate that the person actually authorized the transaction.
The answers depend on context. The important dimensions are whether the scenario is low or high stakes, and whether it is an open or closed ecosystem. Rather than treating "know your agent" as a slogan, the speakers ask whether the parties know and trust one another within a shared boundary.
Jay compares this to entering an office building. A person badges in at the front desk and is then inside a trusted boundary; they do not need to badge again for every room. Encountering another person inside the building carries some trust because both have passed the same entry point. That analogy helps explain why the level of evidence required changes as an interaction moves beyond a known boundary.
Context, Trust Boundaries, and Low-Stakes Agents
The speakers organize the model as a stakes-and-evidence matrix. Stakes and counterparty describe the context: how consequential the action is and whether the ecosystem is open or closed. Authority and evidence describe how the three authorization questions are answered.
Their low-stakes example is an agent such as Claude Code connected to tools like GitHub, Jira, or Linear. A person authenticates while setting up those connectors, which establishes human authorization and consent for the agent to interact with the applications. The scope is expressed through tool permissions: the user can allow specific tools, deny them, or require the agent to ask before acting.
Because this is a relatively closed environment and the actions are usually reversible, the evidence burden is lower. A developer can inspect system logs, revert a change, or redo an incorrect output. The speakers do not argue that authorization is unnecessary in this setting; rather, they argue that the available controls and reversible consequences make cryptographic proof unnecessary at the moment of each action.
Controlled Payment Authority in a Closed Ecosystem
Jay Mok: The medium-stakes example involves money, even though the parties are known and operate in a comparatively closed ecosystem. Jay describes a travel company with valuable data---such as occupancy information or reviews---that it wants to monetize. Buyer-side agents, including travel agents, can pay to access that data through machine payments.
PayPal and a partner called Nevermind support this type of arrangement using two infrastructure primitives. The first is a vault that stores payment credentials on behalf of buyer agents. By itself, a vault does not establish a complete trust arrangement. The second is OAuth, which lets the system offer controlled access to those credentials to participating merchants. Together, these components create an ecosystem of buyer and seller agents with a more trusted operating environment.
In this commercial-card use case, a human authorizes the payment credential for a buyer or travel agent. The resulting mandate has scopes that provide controlled authority. The parties do not send cryptographic proof with every payment request for dispute handling; because they are in a more closed system, they can rely on the existing transaction logs.
Ben Coumes: In this model, both sides know one another and act in the same system. They borrow trust from Nevermind: the buyer agent is expected to stay within the instructions a human gave it, and the selling agent can accept payment from another Nevermind user with confidence in the shared infrastructure. This is why the scenario is medium stakes rather than low stakes: money is moving, but the closed ecosystem reduces the amount of independent evidence needed.
Verifiable Authorization for Open, High-Stakes Payments
The final scenario starts when the parties are neither known to one another nor vetted by a common system. In that setting, the speakers argue that autonomous payments should converge on FIDO verifiable intents and AP2 mandates.
Ben describes the model as a multilayered, selectively disclosed credential. The first layer comes from a trustworthy credential provider, potentially PayPal. The second layer contains the user's instructions to the agent and is signed with the user's private key. A third layer may be added for an autonomous payment, signed by the agent itself.
This arrangement allows each party in a transaction to verify the part relevant to it. A merchant can verify that checkout information is correct, while a payment processor can verify that the payment mandate is correct. The parties do not need a pre-existing relationship with one another; the evidence travels in a form that can be independently verified.
For payments at scale, the speakers see this as the best way to support interactions where unknown parties must still trust that an agent is acting with valid authority. The evidence is not merely a record in a shared platform's logs. It is proof that can be checked across a boundary.
PayPal Approval Tokens and the Broader Model
Ben then describes PayPal's approval token, a new primitive for users who begin an order process with an agent after the agent finds an item at a merchant. Historically, a PayPal order has been synchronous: a user finds an item, goes to the PayPal app at checkout, approves it, and completes the purchase.
With an agent, the user is redirected to PayPal to confirm the instructions supplied to that agent. PayPal returns a JSON payload containing information such as the amount, expiry, and intended merchant. The speakers compare the concept to a verifiable intent, while noting that it is not identical: the token is currently an opaque string that only PayPal can approve. They say it is about to be shipped into production for users who select PayPal as a payment method.
The completed matrix reinforces the three levels. At low stakes, a user gives an agent access to connectors and granular permissions; the resulting actions are easy to reverse or correct. At medium stakes, two known parties operate inside the boundary of a shared system, and that third party enforces the payment mandate. At high stakes, an agent may act autonomously with an unknown counterparty, so the counterparty needs verifiable proof that the agent has permission to transact.
The speakers expect the high-stakes model to extend beyond payments. They cite medical orders, e-signatures, securities trading, and any agent action that is difficult to reverse. Returning to the office-badge analogy, Jay contrasts being inside a building with meeting someone on the street. A badge may be sufficient within the building's trusted boundary, but an open interaction needs a stronger, verifiable standard. The purpose of the framework is to help designers decide what proof is necessary to show that a human authorized an agent before it performs a consequential action.