Nevermined Pay
For AI Agents
Your agent can pay with your card. Set the rules once, and your agent transacts autonomously, with real cards, on real rails.
Humans in the loop
Your agent's workflow breaks every time it needs to pay for something.
Agents that transact
Users delegate once. Your agent handles payments autonomously.
The journey
From enrollment to autonomous purchase. A single, unbroken flow.
Users add their card once
A PCI-compliant capture form (VGS) tokenizes the card instantly. Nevermined never sees the number, only a secure network token is stored. Verified via 3DS or FIDO2 passkey.
ISO 27001 · SOC 2 Type II · PCI SAQ-D certified infrastructure.
They define the guardrails
Spending caps, time windows, and merchant categories. Think of it as a power-of-attorney for payments, scoped and revocable.
"Up to $200/week on research APIs, revoke any time."
Hand the key to the agent
The agent receives a scoped API key: payment capability, not card credentials. One key can work across sessions, tools, and frameworks.
OpenAI, Anthropic, LangChain, CrewAI, MCP, and any agent.
The agent pays via x402
When the agent hits a paywall, it includes a payment header in the HTTP request. The purchase completes in milliseconds. No checkout. No redirect.
As natural as a browser loading a page.
Full trail. Full control.
Every transaction is logged with agent ID, amount, merchant, and timestamp. Exportable for SOC 2, ISO 27001, and regulatory audits. Users revoke delegation with one click.
Compliant, auditable, instantly revocable.
Two ways to get started
Whether you're an individual or a platform builder, there's a path.
Enroll & Delegate
Users enroll their card once, set spending rules, and hand a scoped key to any agent. The agent gets purchasing power, never the card number.
Embedded Capture
Ship AI products that can buy things. Drop in a PCI-compliant iframe, users enter their card inline, and agents transact. Card data never touches your servers.
What agents can buy
If it accepts a card, your agent can pay for it.
Supported payment providers
One delegation API, multiple payment rails. Same agent code regardless of provider.
Enroll a card, create a delegation, and let your agent transact.
Why developers trust Nevermined Pay
Enterprise-grade security
Every layer is designed so card data never touches Nevermined, and every action is auditable.
PCI SAQ-D Compliant
Card data is captured by VGS and tokenized before it enters our system. Nevermined never sees or stores raw card numbers (PANs).
SOC 2 Type II
Independently audited for security, availability, and confidentiality. Report available under NDA for enterprise customers.
ISO 27001 Certified
Information security management system certified to the international standard. Covers data handling, access controls, and incident response.
FIDO2 / Passkey Auth
Strong Customer Authentication at enrollment via 3DS or FIDO2 passkeys. Phishing-resistant, hardware-bound verification.
Full Audit Trail
Every transaction logged with agent ID, amount, merchant, and timestamp. Exportable logs for compliance reporting and dispute resolution.
GDPR Compliant
Data encrypted at rest (AES-256) and in transit (TLS 1.3). Data deletion requests honoured. No raw PAN storage anywhere in the system.
SOC 2 Type II report, ISO 27001 certificate, and PCI attestation of compliance available under NDA. Contact us for details.
Under the hood
Real card rails. Open protocol. No crypto, no wallets.
Frequently asked questions
Everything you need to know about Nevermined Pay.
It's neither. Nevermined Pay uses your real credit or debit card. At enrollment, the card number is tokenized by a PCI-compliant vault. Nevermined never sees or stores the raw PAN. What the agent receives is a scoped virtual card credential that encodes identity, spending limits, and merchant restrictions. The actual charge still runs on existing card rails, so it appears on your normal statement.

