<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.hawkins-scitt-attested-agent-payment" target="https://datatracker.ietf.org/doc/html/draft-hawkins-scitt-attested-agent-payment-01">
   <front>
      <title>Attested Payment Authorization for Autonomous Agents</title>
      <author initials="W." surname="Hawkins" fullname="Walter Hawkins">
         <organization>Independent</organization>
      </author>
      <date month="August" day="14" year="2026" />
      <abstract>
	 <t>   Autonomous software agents increasingly initiate payments on behalf
   of principals.  Existing agent-payment mechanisms authenticate the
   human principal, the operator, or possession of a key; none of them
   establishes that the software authorized to spend is the software
   that was reviewed.  A key held by a compromised or silently modified
   agent authenticates exactly as well as one held by an honest agent.

   This document defines a payment authorization scope bound to a key
   whose protection properties are attested by hardware, and registers
   the resulting authorization as a Signed Statement on an SCITT
   Transparency Service.  The binding reuses the EAT confirmation and
   key-attributes claims without modification; the contribution is the
   authorization scope, the verification procedure a payment executor
   performs before settlement, the transparency record that makes the
   authorization artifact and its registration auditable independently
   of the agent and of the executor, and an execution-record mechanism
   that makes the executor&#x27;s aggregate accounting auditable on
   challenge.  What is registered evidences the authorization; it does
   not evidence that the verification procedure was performed for any
   given settlement.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-hawkins-scitt-attested-agent-payment-01" />
   
</reference>
