Skip to main content

Hackathon Complete 🏁

Share your feedback

Feedback
Nevermined Pay

Nevermined Pay For AI Agents

Your agent can pay with your card. Set the rules once, and your agent transacts autonomously, with real cards, on real rails.

Today

Humans in the loop

Your agent's workflow breaks every time it needs to pay for something.

1
Your agent hits a paid API. Workflow halts
2
User gets a notification. Opens laptop. Finds card
3
Manually enters card number, expiry, CVV. Approves
Repeat for every purchase. Users churn.
With Nevermined Pay

Agents that transact

Users delegate once. Your agent handles payments autonomously.

1
Your agent hits a paid API. Checks spending mandate
2
$12 is within the $100 limit - approved ✓
3
Pays via x402 header. Zero user interaction
User gets a receipt. Your agent keeps working.

The journey

From enrollment to autonomous purchase. A single, unbroken flow.

Enroll

Users add their card once

A PCI-compliant capture form (VGS) tokenizes the card instantly. Nevermined never sees the number, only a secure network token is stored. Verified via 3DS or FIDO2 passkey.

ISO 27001 · SOC 2 Type II · PCI SAQ-D certified infrastructure.

Mandate

They define the guardrails

Spending caps, time windows, and merchant categories. Think of it as a power-of-attorney for payments, scoped and revocable.

"Up to $200/week on research APIs, revoke any time."

Delegate

Hand the key to the agent

The agent receives a scoped API key: payment capability, not card credentials. One key can work across sessions, tools, and frameworks.

OpenAI, Anthropic, LangChain, CrewAI, MCP, and any agent.

Transact

The agent pays via x402

When the agent hits a paywall, it includes a payment header in the HTTP request. The purchase completes in milliseconds. No checkout. No redirect.

As natural as a browser loading a page.

Audit

Full trail. Full control.

Every transaction is logged with agent ID, amount, merchant, and timestamp. Exportable for SOC 2, ISO 27001, and regulatory audits. Users revoke delegation with one click.

Compliant, auditable, instantly revocable.

Two ways to get started

Whether you're an individual or a platform builder, there's a path.

1
For Users

Enroll & Delegate

Users enroll their card once, set spending rules, and hand a scoped key to any agent. The agent gets purchasing power, never the card number.

💳Card tokenized via PCI-compliant vault (VGS)
🔐Verified via 3DS or FIDO2 passkey
🔑One key → many agents, many sessions
📊SOC 2 / ISO 27001 audit trail + instant revoke
2
For Builders

Embedded Capture

Ship AI products that can buy things. Drop in a PCI-compliant iframe, users enter their card inline, and agents transact. Card data never touches your servers.

🧩Drop-in iframe, zero PCI scope
🚫No redirects, no external portals
Works behind any x402 paywall
🏷️White-label ready for your brand

What agents can buy

If it accepts a card, your agent can pay for it.

API callsSaaS subscriptionsResearch papersCompute creditsData feedsCloud storageSoftware licensesMarket reportsProfessional servicesDomain renewalsAd spendBooking feesMulti-agent budgetsTool accessContent paywalls

Supported payment providers

One delegation API, multiple payment rails. Same agent code regardless of provider.

StripeLive
Visa VICComing Soon
PayPal BraintreeComing Soon
Try NVM Pay

Enroll a card, create a delegation, and let your agent transact.

Why developers trust Nevermined Pay

Zero
raw card numbers stored
1
API call to revoke
mandate granularity
100%
auditable trail
ISO 27001SOC 2 Type IIPCI SAQ-D

Enterprise-grade security

Every layer is designed so card data never touches Nevermined, and every action is auditable.

PCI SAQ-D Compliant

Card data is captured by VGS and tokenized before it enters our system. Nevermined never sees or stores raw card numbers (PANs).

SOC 2 Type II

Independently audited for security, availability, and confidentiality. Report available under NDA for enterprise customers.

ISO 27001 Certified

Information security management system certified to the international standard. Covers data handling, access controls, and incident response.

FIDO2 / Passkey Auth

Strong Customer Authentication at enrollment via 3DS or FIDO2 passkeys. Phishing-resistant, hardware-bound verification.

Full Audit Trail

Every transaction logged with agent ID, amount, merchant, and timestamp. Exportable logs for compliance reporting and dispute resolution.

GDPR Compliant

Data encrypted at rest (AES-256) and in transit (TLS 1.3). Data deletion requests honoured. No raw PAN storage anywhere in the system.

Enterprise customers:

SOC 2 Type II report, ISO 27001 certificate, and PCI attestation of compliance available under NDA. Contact us for details.

Under the hood

Real card rails. Open protocol. No crypto, no wallets.

x402 protocol
1
# Agent requests a paid resource
2
GET /paid-resource
3
← 402 Payment Required
4
# Agent attaches payment token
5
GET /paid-resource
6
X-Payment: tok_abc…
7
← 200 OK ✓ content delivered
OpenAIAnthropicLangChainCrewAIStrandsMCPCustom agents
🎯
Scoped
Per-agent, per-task limits
⏱️
Time-limited
Mandates expire on your terms
🔄
Portable
Any card, any agent, any framework

Frequently asked questions

Everything you need to know about Nevermined Pay.

It's neither. Nevermined Pay uses your real credit or debit card. At enrollment, the card number is tokenized by a PCI-compliant vault. Nevermined never sees or stores the raw PAN. What the agent receives is a scoped virtual card credential that encodes identity, spending limits, and merchant restrictions. The actual charge still runs on existing card rails, so it appears on your normal statement.

Get started

Give your agents purchasing power

Ready to let your agents transact? Let's talk.