Human-Present Transactions
Human-Present Transactions are payment flows in which a person remains directly involved when an AI shopping agent prepares and completes a purchase. The person reviews the final checkout details, authenticates through a trusted interface, and explicitly approves the payment.
This model matters because agentic commerce changes how a transaction is assembled. The agent may search, compare and prepare the cart, but the person still confirms what will be purchased and how it will be paid for. Entersekt connects this shift to a wider move toward authentication that validates intent as well as identity.
What are Human-Present Transactions?
A Human-Present Transaction is an agent-assisted payment in which the user directly approves the specific checkout and payment details before execution. The user remains in the loop at the point where the transaction becomes final.
The term is used in the Agent Payments Protocol (AP2), which distinguishes a direct Human Present flow from a Human Not Present flow. In the direct flow, the user approves closed mandates that describe the particular checkout and payment. In the autonomous flow, the user approves constraints in advance and an agent acts later within those limits.
How does a Human-Present Transaction work?
A Human-Present Transaction usually follows a two-stage process: the agent assembles a checkout, then a trusted surface displays the final details for user approval.

- Shopping: The user starts a request with a shopping agent. The agent communicates with the merchant and assembles a cart.
- Checkout: The merchant creates a signed checkout containing the transaction details. The agent selects an available payment instrument through the credential provider.
- Review: The agent sends the checkout and payment details to a trusted surface, such as an approved banking or payment interface.
- Authentication and consent: The trusted surface displays the relevant details and obtains user verification and consent. This may include a biometric action.
- Cryptographic binding: The trusted surface creates signed checkout and payment mandates. A cryptographic link binds the payment to the approved checkout.
- Verification: The credential provider, merchant and payment processor verify the mandates before payment proceeds.
- Receipt: The relevant parties receive signed receipts that record the outcome and support later review.
This sequence gives each participant a defined verification role. It also creates evidence that connects the person’s approval to the particular merchant, amount, payment instrument and checkout details.
What are the main components?
| Component | Role in the transaction |
|---|---|
| Shopping agent | Finds products, assembles the cart and coordinates the purchase. |
| Merchant | Creates the checkout and confirms that the cart matches the approved details. |
| Credential provider | Verifies the payment mandate and issues an appropriately scoped payment credential. |
| Trusted surface | Displays the transaction details and collects user authentication and consent. |
| Merchant payment processor | Checks that the payment credential is authorized for the approved checkout. |
| Mandates and receipts | Bind intent, payment and outcome into verifiable records. |
Why is user presence important in agentic payments?
User presence matters because identity alone does not establish that a person intended to approve a particular purchase. A trusted user could still be shown the wrong merchant, amount or item if the transaction details are altered before approval.
Human-Present Transactions address this risk by making the person review the closed transaction before signing it. This is closely related to transaction confirmation, where the approval is tied to the specific action rather than only to an authenticated session. The FIDO transaction confirmation paper describes this principle as a way to link consent to transaction details and support auditability.
For financial institutions, that distinction supports clearer decisions about authentication, authorization, disputes and accountability. It also creates a more direct control point when an agent is involved in a payment journey.
Human-Present versus Human-Not-Present Transactions
| Characteristic | Human Present | Human Not Present |
|---|---|---|
| User involvement | Direct approval at checkout | Approval before autonomous execution |
| Transaction scope | Specific closed checkout | Predefined constraints |
| Signing authority | User credential or trusted agent provider | Agent key operating under user-approved authority |
| Primary control | User reviews the final details | Verifiers assess whether the transaction fits the approved limits |
| Typical use | Assisted shopping and checkout | Recurring or delegated purchases |
These models can work together. An autonomous flow may return the user to a Human-Present flow when a merchant or credential provider cannot confirm that the purchase fits the approved constraints.
How do Human-Present Transactions relate to authentication?
Human-Present Transactions extend authentication from a question of identity to a question of intent. Identity authentication asks who is acting. Transaction approval asks whether that person agrees to the exact action shown.
Modern financial authentication can add context such as device trust, location, behavior and transaction characteristics. Entersekt’s digital banking fraud prevention approach connects authentication and risk analysis across account access and high-risk actions.
In a Human-Present flow, these signals can help determine how approval should happen. A familiar device and expected purchase may support a quick user experience. An unusual merchant, amount or device may call for stronger verification or additional review.
What risks should financial institutions consider?
Agentic payments introduce risks that sit across the full transaction lifecycle. The agent, merchant, credential provider and payment processor each need a reliable way to verify what was requested, what was approved and what was executed.
- Intent manipulation: An agent may assemble a cart that differs from the person’s request.
- Display integrity: The approval surface must show the same relevant details that the institution verifies.
- Scope errors: A delegated authority model may allow a purchase outside the user’s intended limits.
- Credential misuse: Payment credentials must be scoped to the approved transaction or permitted constraints.
- Evidence gaps: Institutions may need verifiable records for disputes, investigations and regulatory review.
- Social engineering: A person may approve a payment after being manipulated, even when their identity is valid.
These risks make context important. Entersekt’s authorized push payment protection explains why authenticating a customer does not by itself establish that a payment is safe or intended. The same principle applies to agent-assisted commerce.
What should institutions assess before supporting agentic payments?
Institutions should assess both the technical controls and the customer journey before accepting agent-initiated payments. The objective is to preserve clear user approval while making each verification decision proportionate to the risk.
- Approval surface: Confirm that users can review the merchant, amount, items and payment instrument through a trusted interface.
- Mandate integrity: Check that the approved checkout and payment records are cryptographically linked.
- Authority scope: Define which merchants, amounts, instruments and time periods an agent may use.
- Risk decisioning: Combine identity, device, behavior and transaction signals before approving payment.
- Exception handling: Return the user to direct approval when a transaction falls outside its permitted scope.
- Evidence and disputes: Retain the records needed to reconstruct what the user saw and approved.
- Interoperability: Align the implementation with relevant commerce, payment, identity and authentication standards.
Entersekt’s view of the changing payment landscape is outlined in four shifts in digital payment trust, including the move toward security decisions that connect identity, intent, risk and evidence.
Frequently asked questions about Human-Present Transactions
➡️ What does Human Present mean in agentic commerce?
Human Present means the person directly approves the specific checkout and payment before an agent completes the purchase. The person reviews the closed transaction through a trusted surface, authenticates and signs the relevant mandates.
➡️ Are Human-Present Transactions the same as traditional online checkout?
They can resemble traditional checkout because the person approves the final purchase. The difference is that a shopping agent may assemble the cart and coordinate the payment, while signed mandates connect the person’s approval to the transaction details.
➡️ What is the difference between a checkout mandate and a payment mandate?
A checkout mandate establishes that the agent is authorized to complete a particular checkout. A payment mandate establishes that the agent is authorized to pay for that checkout. Cryptographic binding connects the two records.
➡️ Can Human-Present Transactions help prevent payment scams?
They can make the approval decision more explicit, but user presence alone does not stop every scam. Entersekt combines authentication with transaction context and risk intelligence so institutions can assess intent as well as identity before payment.
➡️ How does Entersekt relate to Human-Present Transactions?
Entersekt helps financial institutions assess identity, device, behavior and transaction context across digital banking and payment journeys. This supports authentication decisions that can keep ordinary activity simple and apply additional verification when risk is elevated.
➡️ What standards are relevant to Human-Present Transactions?
Relevant work includes the Agent Payments Protocol, transaction confirmation concepts from the FIDO Alliance, payment authentication standards and applicable regulatory requirements. The correct implementation depends on the payment method, jurisdiction, institution and role each party performs.
Sources and related articles
- Agent Payments Protocol specification, including roles, mandates and verification responsibilities.
- AP2 flow examples, including the direct Human Present flow and autonomous Human Not Present flow.
- FIDO Transaction Confirmation, covering consent tied to specific transaction details.