A proof of presence your policy can call
Wherever your decision layer calls for a human, your app asks for a tap. The result returns to your service so you can make the decision. There is nothing new to issue, download or remember.
Agentic commerce
Your platform decides when an agent needs a person. Koard delivers the proof.
The cardholder taps the physical card on their own phone. Your platform receives a verified result bound to that action. The tap is non financial.
Agentic commerce is built on Tap for Everything.
The problem
Agentic commerce is more than just the final transaction. Each step must trace back to a human. That includes giving the agent a card, setting its spending limit and approving purchases.
Biometric verification proves control of a device. A passcode proves control of a phone number. A tap proves the cardholder has the physical card in hand.
The card’s chip produces a cryptogram the network validates. Stolen card details cannot produce one.
Wherever your decision layer calls for a human, your app asks for a tap. The result returns to your service so you can make the decision. There is nothing new to issue, download or remember.
Every approval is bound to one action, one amount, one counterparty and one moment. It cannot be replayed, applied to a different action or reused after it expires. Your platform receives the outcome and the proof, and it never receives a card number.
The same tap method applies to every scenario and is optimized for a frictionless user experience.
Who asks for the tap
The party with the cardholder’s attention runs the verification. It can pass the result to the party carrying the risk.
The tap is non financial, so it does not need to sit inside a payment authorization.
Your app prompts the cardholder to tap when your policy requires a human. Your platform holds the result and proof and makes the decision.
The tap is independent of the merchant of record. It replaces the one time passcode, knowledge based question and manual review.
When an agent spends on a card the bank issued, the banking app asks the cardholder to tap. It is the same tap and the same proof, on the bank’s side of the purchase.
It replaces the one time passcode and the call from the fraud desk.
The merchant holds an unusually large agent order until the cardholder presents the card. It learns only that the card was present and keeps the record for disputes.
The tap replaces the review queue and the chargeback that follows a typed card number.
The use cases
Each use case applies a Tap for Everything product to agentic commerce. All use the same SDK and the same non financial tap.
01
A person lets an agent shop within a budget
The cardholder taps once to open the session. The proof is bound to the agent, the budget and the time window. The agent works within those limits without asking again.
Cardholder Device · Your platform · Android
Tap to Authenticate
02
An agent asks for permission to act without asking every time
A standing permission is a high risk action. The cardholder sets the limit with a tap, and the proof is bound to the agent, the amount, the category and the expiration date.
Cardholder Device · Your platform · Android
Tap to Authenticate
03
An agent needs a credential before it can buy anything
The cardholder taps the physical card against their own phone. The agent receives a credential of its own, provisioned from that tap. The number printed on the physical card never becomes the agent’s credential, and neither does a stolen number typed into a form.
Cardholder Device · Your platform · Android
Tap to Add Card
04
Your policy engine flags one purchase for verification
The cardholder approves the purchase with the card they have on them. The proof is bound to the item, the amount, the merchant and the moment. Any second use of the proof is rejected.
Cardholder Device · Your platform · Android
Tap to Confirm
05
An agent has lined up three payments for one trip
One tap approves the whole set. The proof is bound to the total. If a price changes before the payments are finalized, the agent comes back for another tap.
Cardholder Device · Your platform · Android
Tap to Confirm
06
An agent is buying and the issuer wants the cardholder in the loop
The banking app sends a notification. The cardholder taps the card on their own phone and the purchase goes through, with no passcode, no phone call and no security questions.
Cardholder Device · Issuer · Android
Tap to Verify
07
An unusually large order arrives from an agent
The merchant asks for a tap before releasing the order. Once the card has been presented, the order ships, and the merchant learns nothing else. No card number is returned.
Cardholder Device · Merchant · Android
Tap to Confirm
08
The credentials an agent runs on are changing
Changing, invalidating or deleting a key is a high risk account action. Instead of sending a passcode, ask the owner to tap the card on file. Bind the proof to that change.
Cardholder Device · Your platform · Android
Tap to Authenticate
In the age of AI, proof of physical possession will be a requirement.
Koard is the human trust layer for agentic payments. Whether the platform, the merchant or the bank asks, the person answers with the physical card in their hand.
The demo
Walk through what happens before the agent acts and when it does, screen by screen. Tap the phone to advance.
Tap the phone to advance. Arrow keys work too. Red markers are failure states.
Screen
1 / 4
Tap to Authenticate · Cardholder Device · Your platform · Android
The agent asks to open a shopping session. Your policy requires a tap before it can begin.
How it plugs in
These taps are not payments. No money moves. There is no interchange or certification queue.
Integrate the SDK. Call it wherever your policy needs a human. Turn it on or off for each flow.
1
SDK to integrate
0
Dollars moved by the tap
0
Card numbers returned
1
Tap method for any moment your policy names
Your policy decides
The decision to allow, verify, hold or deny stays with your engine. When the answer calls for a human, you ask for a tap.
Your app asks
The SDK prompts the cardholder to hold the physical card against their own phone. The chip produces a cryptogram. The network validates it. Nothing about the card is typed, photographed or stored on the phone.
You hold the result
You receive an outcome and a proof, bound to the action, the amount and the moment. Keep it as evidence. No card number is returned.
Who this is for
Authorization and policy layers
Your engine returns allow, verify, hold or deny before an agent acts.
When it returns verify, request a tap for proof of possession. Bind the result to the decision you record.
Agent wallets and spend controls
You enforce budgets, cumulative caps and covenants governing what an agent may spend and whom it may pay.
The person taps to set the rules or step in when a purchase needs approval. This provides step up authentication for a non human spender.
Checkout and commerce orchestration
Agents buy from your catalog, a broadcast, a thread or a chat.
For amounts you mark as high value, a tap protects the purchase and gives the merchant of record evidence that the card was in hand. You get fewer disputes and a record for those that still occur.
Delegated authorization and agent identity
You carry proof of who authorized an agent, the scope granted and when it expires. A tap binds that grant to the person holding the physical card.
The proof of presence is independent of the underlying protocol. There is nothing new to issue.
Questions
In agentic commerce, an AI agent searches, compares, books or orders on a person’s behalf. The person remains accountable. Key decisions still need a human.
Koard provides the human trust layer for delegating to the agent, setting its scope, approving its actions and paying.
Proving human intent means attributing an agent’s action to a real person who intended it.
A tap of the physical card on their own phone proves possession at that moment. The proof is bound to the action shown. The requesting platform holds the result.
A biometric proves the person who unlocked the phone is present. It does not prove card ownership. Stolen card details enrolled into a wallet pass the biometric every time.
A tap proves possession of the physical card. Use it alongside existing controls for actions your policy marks as high risk or high value.
The agent platform can request a tap in its app. The bank can request one in its banking app. The merchant can request one before releasing a large agent order.
The party with the cardholder’s attention runs the tap and can pass the result to the party carrying the risk.
Tap to Verify, Tap to Authenticate, Tap to Add Card and Tap to Confirm are non financial. No money moves. There is no interchange. There is nothing to certify. The tap can sit anywhere in your flow, including outside a payment authorization.
Every approval is bound to one action, one amount, one counterparty and one moment. It cannot be replayed, applied to a different action or reused after it expires. Any second use of the same proof is rejected.
Neither the agent nor the platform sees the card number. The platform receives an outcome and a proof. When a card is added by tap, the platform holds a token reference, the last four digits for display and the provenance recorded on the token. It never holds the primary account number.
You receive an outcome and proof. The proof records card presence and the tap on the cardholder’s own device. It also records the action, amount and moment to which it is bound.
Keep it. If a cardholder later says the agent’s purchase was not theirs, the merchant holds evidence of card presence at approval.
There is one SDK. The tap happens on the cardholder’s own phone. These Cardholder Device flows run on Android. The same SDK also supports Terminal flows on both iOS and Android. In those flows, the merchant’s phone is the terminal.
It is priced per tap. There is no integration fee, no setup fee and no monthly minimum. The party that asks for the tap pays for it and can pass the cost or a margin on it down the chain.
Sign up with your company and a work email. We review every signup, and approved partners receive the Tap for Everything document, the Android demo app and a sandbox to build against.
Private beta
Sign up for the private beta with your company and work email. We review every signup.
Get startedWhat you receive
Approved partners receive the Tap for Everything document, the Android demo app and a sandbox invite.
A thirty minute call establishes where you are today and what the shortest route looks like.
Sesie Bonsi, Chief Innovation Officer
sesie@koard.com