What's actually happening
A short map of the space, so you know where you are. Cloudflare sits at the merchant's edge; the rest of the stack is coordinated with payment schemes and agent platforms.
Agents authenticate themselves
Agents sign every request with an RFC 9421 HTTP Message Signature, identifying themselves to merchants. Visa's Trusted Agent Protocol (TAP) is the current standard; others will follow.
Users stay in control
Card enrolment, passkeys, and per-transaction approval happen in the agent's own UI, with the card network enforcing controls at the network level (merchant + amount match).
Merchants verify at the edge
Cloudflare's edge checks the agent's signature against published public keys before traffic ever reaches the merchant's origin. A legitimate agent gets through. A scraper gets blocked.
Payment rails stay normal
From the merchant's processor forwards, it's a regular card transaction with a tokenised PAN. Nothing about the settlement flow changes.