Basis Theory for agents

Give agents the ability to act, not access to your credentials.

Agents need to pay, sign in, call APIs, and handle sensitive data. Basis Theory turns credentials you already own into scoped, revocable access without handing over the card number, password, or key.

What you control

Cards and payment methods

Connected accounts

Processor and wallet credentials

API keys

Logins

Sensitive data

What your agent can do

Pay at checkout

Use a connected account

Call a privileged API

Complete a browser task

Reason over sensitive data

Use the right payment rail

What you control

Cards and payment methods

Connected accounts

Processor and wallet credentials

API keys

Logins

Sensitive data

What your agent can do

Pay at checkout

Use a connected account

Call a privileged API

Complete a browser task

Reason over sensitive data

Use the right payment rail

Companies that trust

Companies that trust

Basis Theory’s agentic infrastructure

Basis Theory’s agentic infrastructure

Use Cases

Build agents that can finish the job.

Buying, selling, signing in, calling a protected service, or working with real records: each one needs the agent to handle the information securely.

Build an agent that buys

Let it purchase on a customer’s behalf at merchants you approve, or spend from a wallet you offer your users.

Let it purchase on a customer’s behalf at merchants you approve, or spend from a wallet you offer your users.

// Agentic Credential minted for amount, merchant, and time window.

// Agentic Credential minted for amount, merchant, and time window.

Used for

Travel booking split across airlines, hotels, and local providers

Subscription recovery after a card reissue

Build an agent that works in the browser

Let it navigate a site, build a cart, and reach checkout on a customer’s behalf.

Let it navigate a site, build a cart, and reach checkout on a customer’s behalf.

// Data is filled inside the boundary, never in the agent’s context.

// Data is filled inside the boundary, never in the agent’s context.

Used for

In-page insurance purchase with no redirect

Ad-to-checkout inside a streaming experience

Build an agent that operates real systems

Let it use an approved account or a privileged API to get work done.

Let it use an approved account or a privileged API to get work done.

// It never receives the login or the key. We attach the real credential in flight.

// It never receives the login or the key. We attach the real credential in flight.

Used for

A connected account used without handing over the session

Build an agent that works with real records

Let it reason over real customer and payment data instead of redacted stubs.

Let it reason over real customer and payment data instead of redacted stubs.

// Agent operates inside a PCI Level 1 boundary. Only the approved result comes back out.

// Agent operates inside a PCI Level 1 boundary. Only the approved result comes back out.

Used for

An agent reasoning over card data inside PCI scope

Don’t hand agents credentials. Route the capability they need.

The original credential stays with you. Basis Theory issues a scoped, single-use, revocable credential for one job, in the format the destination accepts. Your agent can act. It never holds the secret.

BT/AI Platform

Sources

Vaulted Card

LIVE

Connected Account

LIVE

Processor Wallet

LIVE

Stablecoin Wallet

Soon

Authentication Credentials

Soon

Rails/Providers

Visa Intelligent Commerce

LIVE

Mastercard Agent Pay

LIVE

Stripe Shared Payment Tokens

LIVE

Stripe Link Virtual Cards

LIVE

Stablecoins

Soon

Browserbase

Alpha

Browser Use

Soon

Delivery

Agentic Payments API

LIVE

Browser Aperture

Alpha

PCI Agent Runtimes

LIVE

Agent Credential Proxy

Alpha

PCI Router

Soon

Managed Auth

Soon

BT/AI Platform

Sources

Vaulted Card

LIVE

Connected Account

LIVE

Processor Wallet

LIVE

Stablecoin Wallet

Soon

Authentication Credentials

Soon

Rails/Providers

Visa Intelligent Commerce

LIVE

Mastercard Agent Pay

LIVE

Stripe Shared Payment Tokens

LIVE

Stripe Link Virtual Cards

LIVE

Stablecoins

Soon

Browserbase

Alpha

Browser Use

Soon

Delivery

Agentic Payments API

LIVE

Browser Aperture

Alpha

PCI Agent Runtimes

LIVE

Agent Credential Proxy

Alpha

PCI Router

Soon

Managed Auth

Soon

BT/AI Platform

Sources

Vaulted Card

LIVE

Connected Account

LIVE

Processor Wallet

LIVE

Stablecoin Wallet

Soon

Authentication Credentials

Soon

Rails/Providers

Visa Intelligent Commerce

LIVE

Mastercard Agent Pay

LIVE

Stripe Shared Payment Tokens

LIVE

Stripe Link Virtual Cards

LIVE

Stablecoins

Soon

Browserbase

Alpha

Browser Use

Soon

Delivery

Agentic Payments API

LIVE

Browser Aperture

Alpha

PCI Agent Runtimes

LIVE

Agent Credential Proxy

Alpha

PCI Router

Soon

Managed Auth

Soon

Agentic Payments

LIVE

Let an agent spend.

Visa Intelligent Commerce

Mastercard Agent Pay

Stripe SPTs

Stripe Link

Stablecoins

+ More coming soon

Your agent gets the exact credential the merchant accepts.

Give an agent an allowance, a merchant and a time window. At checkout, Basis Theory mints the credential the merchant accepts, and the agent never sees the card.

Allowance · alw_8f2c41ab

Active

Source

Visa ··4242 · vaulted card

Merchant

cartograph.example.com

Amount

$500.00

Window

until Sep 17, 2026 · 14:00 UTC

Credential

Single-use · minted at checkout

allowance_remaining

$320.00

/ $500.00

1 credential minted · $180.00 burned on mint

Revoke allowance

View credentials →

Allowance · alw_8f2c41ab

Active

Source

Visa ··4242 · vaulted card

Merchant

cartograph.example.com

Amount

$500.00

Window

until Sep 17, 2026 · 14:00 UTC

Credential

Single-use · minted at checkout

allowance_remaining

$320.00

/ $500.00

1 credential minted · $180.00 burned on mint

Revoke allowance

View credentials →

A payment policy for any agentic payment protocol.

The protocol shouldn’t decide whether your agent can pay safely. Basis Theory converts one approved source into the card, network token, shared payment token, or stablecoin payment the checkout requires.

ACP/AP2

Agentic Commerce Protocol · Agent Payments Protocol

spt / network token

UCP

Universal Commerce Protocol

card / network token

MPP

Machine Payments Protocol

card / network token / spt

x402

HTTP-Native Payments

stablecoin payment

Browser Use

Browser agent rail

card / network token

ACP/AP2

Agentic Commerce Protocol · Agent Payments Protocol

spt / network token

UCP

Universal Commerce Protocol

card / network token

MPP

Machine Payments Protocol

card / network token / spt

x402

HTTP-Native Payments

stablecoin payment

Browser Use

Browser agent rail

card / network token

ACP/AP2

Agentic Commerce Protocol · Agent Payments Protocol

spt / network token

UCP

Universal Commerce Protocol

card / network token

MPP

Machine Payments Protocol

card / network token / spt

x402

HTTP-Native Payments

stablecoin payment

Browser Use

Browser agent rail

card / network token

PCI Agent Runtimes

LIVE

Run the agent where sensitive data can be used safely.

Many teams face this decision: keep sensitive data away from their agents, or pull the agent into PCI scope. Instead, run the agent logic, SDKs, and models you already use inside a PCI Level 1 environment.

Vercel AI SDK

OpenAI SDK

LlamaIndex

Claude Agent SDK

Llama Stack

+ Any other model

sandbox.js

node 24 · PCI Level 1

//runs inside Basis Theory’s PCI Level 1 environment

module.exports = async function (event) {

const { generateText } = await import(‘ai’)

// the caller sent {{ 0d0f56a5-6374-… }}, not a card number

// it resolves inside the boundary, never in your app

const card = event.req.card

const { text } = await generateText({

model: openai(event.configuration.MODEL),

// bring your own model

system: ‘You are a PCI-scoped agent. Answer only the question.’,

// the model sees only what you allow

prompt: event.req.prompt + ‘ · ‘ + card.brand + ‘ ‘ + card.last4,

})

// only the sanitized answer leaves the boundary

return { res: { statusCode: 200, body: { ok: true, text } } }

}

sandbox.js

node 24 · PCI Level 1

//runs inside Basis Theory’s PCI Level 1 environment

module.exports = async function (event) {

const { generateText } = await import(‘ai’)

// the caller sent {{ 0d0f56a5-6374-… }}, not a card number

// it resolves inside the boundary, never in your app

const card = event.req.card

const { text } = await generateText({

model: openai(event.configuration.MODEL),

// bring your own model

system: ‘You are a PCI-scoped agent. Answer only the question.’,

// the model sees only what you allow

prompt: event.req.prompt + ‘ · ‘ + card.brand + ‘ ‘ + card.last4,

})

// only the sanitized answer leaves the boundary

return { res: { statusCode: 200, body: { ok: true, text } } }

}

Your agent code. Your model choice. A boundary you do not have to build.

Your app sends a token reference, not a card number. It resolves inside the boundary, the agent reasons over only what you allow, and only the approved result comes back out.

Your app sends a token reference, not a card number. It resolves inside the boundary, the agent reasons over only what you allow, and only the approved result comes back out.

Browser Aperture

Alpha

Give the browser a job, not open-ended access.

Browser Aperture holds an agent to the sites, actions, data, and spend limits you approve. It works inside that envelope, and sensitive actions come to us. Every move is recorded.

// 01

The agent drives

Ten moves: observe, navigate, click, type, select, scroll, wait, ask for a human, prepare, commit. No selectors, scripts, or DevTools.

// 02

The agent can’t

Read a sensitive value. Leave approved sites. Exceed its per-purchase, total, or count limits.

shop.example.com/checkout

Aperture · apt_3f9c

Checkout

Order total:

$48.20

Email

casey@agentmail.dev

Ship to

410 Mission St, San Francisco

Payment · held by Basis Theory

Agent: read-only

Card number

4111 20•• •••• 0021

Expiry

•• / ••

CVC

•••

Inject

Basis Theory types the real value into the shielded field

Intercept

An alias goes in · the real credential is substituted at egress

Place order · $48.20

Commit requires approval · Single-use credential

// 03

We take the wheel

At the card step, we take over. We fill the real value into a shielded field, or swap in the real credential after the request leaves the browser. A compromised agent can’t leak a secret it never held.

// 04

You stay in control

Approval is on by default. The agent can ask for a person, a person can take over at any point, and every move is on the record.

// 01

The agent drives

Ten moves: observe, navigate, click, type, select, scroll, wait, ask for a human, prepare, commit. No selectors, scripts, or DevTools.

// 02

The agent can’t

Read a sensitive value. Leave approved sites. Exceed its per-purchase, total, or count limits.

shop.example.com/checkout

Checkout

Order total:

$48.20

Email

casey@agentmail.dev

Ship to

410 Mission St, San Francisco

Payment · held by Basis Theory

Card number

4111 20•• •••• 0021

Expiry

•• / ••

CVC

•••

Inject

Basis Theory types the real value into the shielded field

Intercept

An alias goes in · the real credential is substituted at egress

Place order · $48.20

Commit requires approval · Single-use credential

// 03

We take the wheel

At the card step, we take over. We fill the real value into a shielded field, or swap in the real credential after the request leaves the browser. A compromised agent can’t leak a secret it never held.

// 04

You stay in control

Approval is on by default. The agent can ask for a person, a person can take over at any point, and every move is on the record.

// 01

The agent drives

Ten moves: observe, navigate, click, type, select, scroll, wait, ask for a human, prepare, commit. No selectors, scripts, or DevTools.

// 02

The agent can’t

Read a sensitive value. Leave approved sites. Exceed its per-purchase, total, or count limits.

shop.example.com/checkout

Aperture · apt_3f9c

Checkout

Order total:

$48.20

Email

casey@agentmail.dev

Ship to

410 Mission St, San Francisco

Payment · held by Basis Theory

Agent: read-only

Card number

4111 20•• •••• 0021

Expiry

•• / ••

CVC

•••

Inject

Basis Theory types the real value into the shielded field

Intercept

An alias goes in · the real credential is substituted at egress

Place order · $48.20

Commit requires approval · Single-use credential

// 03

We take the wheel

At the card step, we take over. We fill the real value into a shielded field, or swap in the real credential after the request leaves the browser. A compromised agent can’t leak a secret it never held.

// 04

You stay in control

Approval is on by default. The agent can ask for a person, a person can take over at any point, and every move is on the record.

Observe

Checkout · 14 refs

Click

Continue as guest

Type

Email · public field

Type

Card · SENSITIVE_FIELD_REJECTED

Hand-off

Shielded field · filled by Basis Theory

Commit

$48.20 · single-use · approved

Observe

Checkout · 14 refs

Click

Continue as guest

Type

Email · public field

Type

Card · SENSITIVE_FIELD_REJECTED

Hand-off

Shielded field · filled by Basis Theory

Commit

$48.20 · single-use · approved

Agent Credential Proxy

Alpha

Give an agent access to an API. Not the API key.

An agent can call Stripe, GitHub, a bank, or any authenticated service without ever holding the credential. Basis Theory checks each request against your policy, attaches the real credential in flight, strips sensitive values from the response, and logs it per agent.

Agent Runtime

The agent holds a permissioned stand-in. Basis Theory holds the secret.

No API keys

No cards

No passwords

1 · Request

4 · Redacted

Secret stripped

Agent Credential Proxy

Validates the request against your policy

Injects the real credential in flight

Strips sensitive values from the response

Logs every call, per agent

2 · Injected

Secret attached

3 · Response

Upstream API

Stripe, GitHub, a bank: anything with an endpoint. It receives a normal, fully authenticated request.

Sees real credential

Never sees the agent

Rate limits per agent

Spend and amount ceilings

Anomaly detection

Sensitive-path denial

Alerts

Agent Runtime

The agent holds a permissioned stand-in. Basis Theory holds the secret.

No API keys

No cards

No passwords

Agent Credential Proxy

Validates the request against your policy

Injects the real credential in flight

Strips sensitive values from the response

Logs every call, per agent

Upstream API

Stripe, GitHub, a bank: anything with an endpoint. It receives a normal, fully authenticated request.

Sees real credential

Never sees the agent

1 · Request

4 · Redacted

Secret stripped

2 · Injected

Secret attached

3 · Response

Rate limits per agent

Spend and amount ceilings

Anomaly detection

Sensitive-path denial

Alerts

Agent Runtime

The agent holds a permissioned stand-in. Basis Theory holds the secret.

No API keys

No cards

No passwords

Agent Credential Proxy

Validates the request against your policy

Injects the real credential in flight

Strips sensitive values from the response

Logs every call, per agent

Upstream API

Stripe, GitHub, a bank: anything with an endpoint. It receives a normal, fully authenticated request.

Sees real credential

Never sees the agent

1 · Request

4 · Redacted

Secret stripped

2 · Injected

Secret attached

3 · Response

Rate limits per agent

Spend and amount ceilings

Anomaly detection

Sensitive-path denial

Alerts

As agents grow in use, so do the security risks.

Unique secrets found sitting in MCP config files

+%

+%

+%

year-on-year growth in AI-service secrets leaked on public GitHub

%

%

%

Of enterprises running agents report at least one agent-related security incident

A key in a .env file vs. a key behind the proxy.

Key in a .env file

Key behind the Agent Credential Proxy

Every action is attributable

No record.

See which agent used which credential, where, and why.

Bad requests stop before the secret moves

Goes through.

Enforce destination, method, spend, rate, and sensitive-path rules.

Revoke one agent without rotating every system

Rotate the key everywhere it’s used.

Kill its permissioned reference. The underlying key stays put.

A leaked placeholder is not a leaked secret

Full power, from anywhere.

Outside the proxy and its policy, it is useless.

Every action is attributable

KEY IN A .ENV FILE

No record.

AGENT CREDENTIAL PROXY

See which agent used which credential, where, and why.

Bad requests stop before the secret moves

KEY IN A .ENV FILE

Goes through.

AGENT CREDENTIAL PROXY

Enforce destination, method, spend, rate, and sensitive-path rules.

Revoke one agent without rotating every system

KEY IN A .ENV FILE

Rotate the key everywhere it’s used.

AGENT CREDENTIAL PROXY

Kill its permissioned reference. The underlying key stays put.

A leaked placeholder is not a leaked secret

KEY IN A .ENV FILE

Full power, from anywhere.

AGENT CREDENTIAL PROXY

Outside the proxy and its policy, it is useless.

COMING SOON

Soon

More ways to give agents access.

Soon

Managed Auth

Let agents sign in without ever learning your password.

Store logins the same way Basis Theory stores payment credentials. An agent can use an approved account in an approved browser flow without the username, password, or session becoming part of its prompt or tool configuration.

Vaulted like a card

Never in the prompt

Pairs with Browser Aperture

Spend and amount ceilings

Soon

PCI LLM Router

Use the models your agent needs without moving sensitive data outside the boundary.

One OpenAI-compatible endpoint for sending sensitive prompts to supported models inside Basis Theory’s PCI Level 1 environment. Cardholder data stays in the boundary, and you still pick the right model.

One API for supported models

Sensitive prompts stay inside the PCI boundary

Works with PCI Agent Runtimes

Model choice without rewriting your agent architecture

Agentic commerce will not run on one checkout flow or one credential format.

Payment networks, merchant platforms, browsers, cloud runtimes, and AI agents are all defining how autonomous commerce works. Basis Theory is the credential and policy layer that lets them interoperate without exposing what’s underneath.

Agentic Commerce Consortium

Founded by Basis Theory in 2025 to bring researchers, solution providers and payment networks into one working group on agentic commerce infrastructure. Its white paper set out the first shared standards for agent-led commerce.

The Consortium →

Agentic Payments Alliance

A founding member alongside Rain, Mastercard, and others defining how agent-driven payments get authorized, secured, and rewarded. Launched August 18, 2026.

The announcement →

In The News

Agents will need credentials. They should not need the secrets behind them.

Build agents that can pay, sign in, use APIs, and work with sensitive data while you keep control of where, when, and how they act.