Recognize the agent
Separate supported shopping agents from undifferentiated bot traffic.
Fraud and BSA/AML infrastructure for the agentic economy
A valid agent can still make an unauthorized payment. FLINT decides before settlement, and leaves evidence for the fraud team and the regulator.
Skyline’s invoice agent requests $1,450 USDC on Circle.
Payment intercepted before settlement.
pending decisionAgentic-commerce spend projected by 2030
Juniper Research
Machine identities for every human identity
Palo Alto Networks, 2026
Rise in malicious bot-initiated transactions in six months
Visa
Dark-web posts mentioning “AI Agent” across underground channels in a six-month comparison
Visa
Built for the agentic commerce stack
You gave it tools, a wallet, or a seat on the network. Credentials will still look fine after someone, or something, else is steering. FLINT checks the action before it happens and leaves a record if you have to explain it to yourself, to a bank, or to a regulator.
Click any threat vector to inspect live decision telemetry.
FLINT evaluates observable identity, authority, provenance, behavior, and transaction context at the decision boundary.
Same agent. Authorized spend.
Choose your responsibility. FLINT assembles the shortest path from exposed agent action to accountable, verifiable control.
Recognize legitimate agent buyers, verify available authority, and decide before settlement without treating every automated checkout as hostile.
Separate supported shopping agents from undifferentiated bot traffic.
Confirm the identity, mandate, amount, merchant, and transaction context available for this spend.
Return ALLOW, STEP-UP, REVIEW, or BLOCK while the payment can still be controlled.
Preserve a signed record of what FLINT checked, observed, and decided.
A BLOCK decision returned before settlement. The evidence is signed to the transaction record.
Receipt hash: locked to recordDeploying for Accept agent payments: Activates Sentry + Passport + Verify
FLINT is fraud and financial-authority infrastructure for the agentic economy. When an AI agent attempts a consequential action or payment, FLINT checks the available identity, principal, mandate, runtime, wallet, and reputation evidence, returns a verdict, and signs a record of the decision.
Agentic fraud is abuse in which an AI agent, its credentials, tools, delegation chain, or transaction context is manipulated to take an action its principal did not authorize. The agent can remain valid while its behavior, payee, amount, or purpose changes, which is why authentication alone is not enough.
Know Your Agent is the practice of establishing which agent is acting, which person or organization is accountable for it, what authority it holds, and whether the current action fits that authority. KYA complements human KYC; it does not replace customer identification or legal compliance obligations.
A signature can prove which agent sent a request, but not that its principal approved this payee, amount, tool, or moment. A hijacked, misconfigured, or over-delegated agent may keep valid credentials. FLINT checks the action against the mandate at execution time.
Six layers: Principal Identity, Agent Identity, Wallet Provenance, Authorization Scope, Environment Identity, and Cross-Merchant Reputation. Evidence may be verified, observed, unavailable, or conflicting; FLINT preserves those distinctions instead of treating missing data as fraud.
Keep the bot controls. Agent protocols and signatures can identify recognized automation; FLINT adds financial authority and transaction context so a merchant can distinguish an agent with permission to buy from a valid agent making an unauthorized purchase. FLINT Sentry provides advisory agent-commerce intelligence for Shopify merchants.
ALLOW means the evidence supports the action; STEP-UP asks for more proof; REVIEW identifies signals needing human or policy review; BLOCK means strong evidence says the action should not proceed. FLINT Verify returns the decision to the integrating system, which chooses enforcement. FLINT Sentry never stops or modifies Shopify orders.
No. FLINT can evaluate an agent without one. A Passport provides durable agent identity, binds it to an accountable principal and declared mandate, and gives trust evidence a stable place to accumulate across sessions, deployments, and counterparties.
A signed verification record is a tamper-evident receipt of what FLINT checked, what was observed or unavailable, which rules ran, and which verdict was returned for a specific action. FLINT uses hybrid signing (ES256 plus ML-DSA-65) so the record can be independently verified through the post-quantum transition. It is evidence, not a guarantee of a chargeback, insurance, or regulatory outcome.
No. FLINT sits between agent identity and financial action. It is rail-agnostic, holds no funds, and is designed to work alongside card and stablecoin rails, x402, API and MCP flows, device intelligence, blockchain analytics, IAM, sanctions screening, and transaction monitoring. FLINT adds agent authority, execution-time context, and signed evidence; regulated institutions remain responsible for their risk-based programs and filing decisions.
Founding design partner program
Bring the workflow: an agent that spends, a business accepting agents, a fintech opening a new rail, or a company governing an agent fleet. Together, we'll turn it into a safer launch, a clearer operating model, and a system your team can explain when the stakes are real.
Get early access across Passport, Verify, Sentry, and Command. Use only what your workflow needs.
Work directly with FLINT on architecture, controls, integrations, and the shortest path to a live pilot.
Exercise identity, mandate, runtime, wallet, and transaction-abuse scenarios against your real use case.
Build signed evidence, review paths, and governance practices in from the beginning, not after an incident.