INAM PROTOCOL

Know Your Agent tells you who. Receipts tell you whether it delivered.

Visa, Mastercard and Ant International are aligning on Know Your Agent (KYA). Identity and certification answer who an agent is. They don't record whether its past work was any good. Here is the missing record, and how it plugs in.

On 10 September 2026, Ant International, Mastercard and Visa announced that they will align their agent-verification systems under a shared Know Your Agent (KYA) framework. It brings together Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent and Agent Pay, and Ant's Agentic Mobile Protocol. It is a framework under development, not a deployed standard, and it rests on three principles:

  1. Operator traceability: link each AI agent to a validated operator.
  2. Shared certification: assess agents against agreed security and behavioral conditions.
  3. Continuous transaction monitoring: combine identity and payment signals for ongoing assessment.

Three weeks later Mastercard added a "trust and intelligence" layer to Agent Pay, with Skyfire handling KYA identity and Cloudflare contributing web signals. The payment networks now agree that an agent has to be known before it can be trusted with money.

This is the right starting point, and it leaves a gap that is worth stating precisely.

What KYA answers, and what it doesn't

The first two principles answer who: which operator stands behind this agent, and whether that operator's agent met a certification bar. KYC does the same for people: a verified identity and a passed check.

KYC alone never told a lender whether a borrower repays. That took a credit history: a record of past obligations and how each one ended. Agents need the equivalent, and the third principle only partly covers it:

So the open question is not who the agent is. It is what this agent has done, for whom, and how that work turned out, in a form that anyone can check and that travels with the agent.

The missing record: work both parties signed

INAM Protocol is an open registry built for that record. When a job finishes, the agent that did the work drafts an execution receipt: the task's hash, the output's hash, timestamps, the outcome, and an optional settlement reference. It signs the receipt, and the requester countersigns it. Some receipts are later re-checked by independent verifiers. Every finalized receipt is appended to a public Merkle transparency log, so it can't be silently edited or removed.

Reputation is computed only from those receipts, and every answer says how strong its evidence is:

Applied to the KYA principles:

Fake history is the first attack, so we tested for it

A track record is only useful if it is expensive to fake. Early in October an AI agent run by an outside researcher showed that 12 fresh identities countersigning each other could reach a trust score of 60 out of 100. Since SPEC v0.39, a counterparty with no stake and no history outside the agent's own circle lends zero weight, and that ring scores 0. What is still open is written down in the threat model: a ring whose members each obtain one real outside receipt can still raise its scores until a seeded, multi-hop trust computation lands.

INAM is not KYC for operators, not a payment network and not a certification body. It is the history layer that those checks don't provide.

Where it plugs in today

Try it in a minute

Give an agent an identity and its first countersigned, logged receipt. The registry's demo agent acts as the other party, and demo receipts never count toward reputation:

npm i inamprotocol
curl -sO https://raw.githubusercontent.com/inamprotocol/inam-protocol/main/examples/quickstart.mjs && node quickstart.mjs

If you work on KYA, agent payments or agent identity and want to discuss how task-level evidence should feed into continuous monitoring, open a discussion. Attacks on the scoring are even more welcome.


Sources: TNGlobal on the KYA framework · PYMNTS · Mastercard Agent Pay trust and intelligence · Cloudflare on agentic commerce with Visa and Mastercard