WEBVTT

NOTE Sentence-level transcript of https://www.youtube.com/watch?v=vGn6N4-bxBY

NOTE One cue per sentence. Cue ids are the line anchors on /transcripts/vGn6N4-bxBY.html. A cue ends where the next begins, or 2 s after its last word.

s1
00:00:01.309 --> 00:00:03.309
[music]

s2
00:00:12.640 --> 00:00:13.480
Hello everybody.

s3
00:00:13.480 --> 00:00:15.200
How are you doing?

s4
00:00:15.200 --> 00:00:20.000
Um Does anybody remember the movie Terminator?

s5
00:00:20.000 --> 00:00:24.440
Uh anyways, it's one of my favorite uh movies when I was growing up as a kid.

s6
00:00:24.440 --> 00:00:29.080
And it imagines a world where the machines have taken over, right?

s7
00:00:29.080 --> 00:00:42.320
And uh uh the nightmare scenario here though in in 2026 is not that the machines are or the agents are launching nukes, but rather uh they've uh taken your wallet

s8
00:00:42.320 --> 00:00:44.600
and they've gone on a shopping spree.

s9
00:00:44.600 --> 00:00:50.120
And they buy like a bunch of crypto and new bunch of bunch of spanks for you.

s10
00:00:50.120 --> 00:01:04.080
Um but the basically today we're talking about how we safeguard against that and uh and uh hopefully we can kind of share a a mental model that you can use when you're thinking about agent authorization.

s11
00:01:04.080 --> 00:01:05.840
Uh my name is uh Jay Mock.

s12
00:01:05.840 --> 00:01:10.520
I'm a product manager over at PayPal in agentic payments.

s13
00:01:10.520 --> 00:01:11.520
And

s14
00:01:11.520 --> 00:01:12.040
Hi everyone.

s15
00:01:12.040 --> 00:01:12.720
I'm Ben Cooms.

s16
00:01:12.720 --> 00:01:18.800
I am a staff software engineer on the payment PayPal enterprise payments team.

s17
00:01:18.800 --> 00:01:21.960
And together we're going to share kind of like some knowledge with you.

s18
00:01:21.960 --> 00:01:25.000
Um so hopefully uh you find it helpful.

s19
00:01:25.000 --> 00:01:26.680
Okay.

s20
00:01:26.680 --> 00:01:36.760
So uh the the key questions that we kind of like uh start off with is uh in terms of like agent authorization is uh did the human authorize this?

s21
00:01:36.760 --> 00:01:42.160
Um is this allowed right now in this scope and can we prove it later, right?

s22
00:01:42.160 --> 00:01:48.720
And we we kind of like try to make it general, but in our world of payments, yeah, did the human authorize this?

s23
00:01:48.720 --> 00:01:52.080
Uh that could be like a passkey or of of that nature.

s24
00:01:52.080 --> 00:01:54.280
Uh is this allowed right now in this scope?

s25
00:01:54.280 --> 00:01:59.080
It's generally going to be a time bound um you know you know token.

s26
00:01:59.080 --> 00:02:08.800
Um and an amount and possibly could be identified like a merchant or a the actual product intent.

s27
00:02:08.800 --> 00:02:11.520
Lastly, can we prove it later?

s28
00:02:11.520 --> 00:02:14.120
This is like if something goes wrong, right?

s29
00:02:14.120 --> 00:02:25.240
And in our world of payments it's generally has to do with like the disputes and in that case and how do you can you prove that you know the the human generally authorized that transaction.

s30
00:02:25.240 --> 00:02:26.040
Right?

s31
00:02:26.040 --> 00:02:34.320
Um But we think the way that you actually answer these three questions is really dependent on the context.

s32
00:02:34.320 --> 00:02:45.840
You know, context is a overused term, but in this case what we what we mean is um you know, is it a low stakes or high stakes kind of

s33
00:02:45.840 --> 00:02:47.040
scenario?

s34
00:02:47.040 --> 00:02:54.160
Um and is this a kind of like open ecosystem or closed ecosystem?

s35
00:02:54.160 --> 00:02:55.920
Do the parties like know each other?

s36
00:02:55.920 --> 00:02:58.880
You know, people use the term KYA a lot.

s37
00:02:58.880 --> 00:03:06.800
Know your agent, but you know, what we think about in this scenario is is is really about is it like an open or closed ecosystem, right?

s38
00:03:06.800 --> 00:03:11.400
And in a payments context it could be like, "Hey, you know, ChatGPT or Gemini, right?"

s39
00:03:11.400 --> 00:03:18.760
That's like kind of like a more of like a closed ecosystem because you know, the those agents know the merchant generally.

s40
00:03:18.760 --> 00:03:23.519
Um I like to use a an analogy.

s41
00:03:23.519 --> 00:03:24.920
I like analogies.

s42
00:03:24.920 --> 00:03:29.360
And the analogy I I like to use is kind of like the you know, badging into work.

s43
00:03:29.360 --> 00:03:31.400
You badge into work in the front desk.

s44
00:03:31.400 --> 00:03:37.480
You basically are are then led into the building or you know, let's say it's a set of buildings.

s45
00:03:37.480 --> 00:03:45.160
You don't need to like badge in every single time to every other or for every single room because you're already within that trusted boundary, right?

s46
00:03:45.160 --> 00:03:54.480
So then when you meet someone in within that within your your office building, uh, you kind of have some element of trust, or hopefully you have some element of trust,

s47
00:03:54.480 --> 00:03:58.800
uh, because you're both, uh, employees at the same company that badged in, right?

s48
00:03:58.800 --> 00:04:05.480
So, um, that's kind of like the analogy I may I may use later in the presentation.

s49
00:04:05.520 --> 00:04:11.000
Okay, so based on those key questions, we kind of think about like, "Hey, what's the mental model that we can build off of this, right?"

s50
00:04:11.000 --> 00:04:17.040
And we have this like stakes and evidence matrix, and we're going to talk about, uh, these three different scenarios.

s51
00:04:17.040 --> 00:04:25.440
Um, and so, uh, we're going to first uh, and you'll see at the top it's kind of like the stakes and counterparty part that I was just talking about the context,

s52
00:04:25.440 --> 00:04:25.680
right?

s53
00:04:25.680 --> 00:04:28.840
Counterparty is like the open or closed ecosystem.

s54
00:04:28.840 --> 00:04:36.760
And then authority and like evidence is really about how you answer those those those three questions I had shared in in the prior slide, right?

s55
00:04:36.760 --> 00:04:46.960
Um, so we'll talk a little bit first about like cloud code since that's what most people are very familiar with, and, uh, basically, you know, when you as a human you're going, you know, using your cloud code,

s56
00:04:46.960 --> 00:04:56.880
uh, you know, you might be, uh, then setting up, uh, your your connectors with your GitHub or or, um, you know, Jira or whatever, uh, linear or whatever uh, tool you're using.

s57
00:04:56.880 --> 00:05:06.520
And, um, you know, you're as part of that process you're kind of like authenticating, so that's how you kind of like get that that human authorization and consent um, with those those applications

s58
00:05:06.520 --> 00:05:09.680
and to for the for cloud container act with them.

s59
00:05:09.680 --> 00:05:14.440
Um, in terms of the, uh, actual like, uh, scopes, right?

s60
00:05:14.440 --> 00:05:19.160
The the example here would be that about, you know, cloud's like, uh, tool permissions.

s61
00:05:19.160 --> 00:05:28.720
Like people are very familiar probably with, uh, the fact that you can allow cloud cloud to to use certain tools, um, uh, deny or ask cloud to ask you,

s62
00:05:28.720 --> 00:05:32.080
uh, before for before doing something, right?

s63
00:05:32.080 --> 00:05:43.200
And then in terms of, uh, the action of like a cloud, uh, we generally think, um, because it's a kind of closed ecosystem and it's like you're coding, uh, the stakes are relatively low here.

s64
00:05:43.200 --> 00:05:49.640
And so in terms of the evidence or proof, you don't really need to have like that cryptographic proof um, at that point in time.

s65
00:05:49.640 --> 00:05:57.000
You can kind of just look at like system logs in order to to or you have the ability to just revert revert your changes, right?

s66
00:05:57.000 --> 00:06:07.240
So, that's kind of like an example of applying like this mental model and using cloud code in terms of that scenario.

s67
00:06:07.240 --> 00:06:21.600
Okay, so the next example we're going to talk about is a more medium stakes scenario and why why we're calling this medium stakes even though it's within a known or kind of closed ecosystem is because it has to do with money

s68
00:06:21.600 --> 00:06:23.040
and and payments.

s69
00:06:23.040 --> 00:06:28.200
And so that's like the shared vault and OAuth scope example.

s70
00:06:29.919 --> 00:06:38.560
So, in this example where the use case is is like hey you're like a let's say a merchant or Trip Advisor, right?

s71
00:06:38.560 --> 00:06:45.120
And you have a travel travel company and you have a lot of great content that you want to monetize.

s72
00:06:45.120 --> 00:06:48.680
It could be occupancy data, it could be like reviews, what have you.

s73
00:06:48.680 --> 00:06:50.200
And you have a new customer now.

s74
00:06:50.200 --> 00:06:59.120
You have like a trap like travel agents or like you know agents that that are buyer agents that are are coming to you and you want to be able to

s75
00:06:59.120 --> 00:07:02.120
monetize monetize your data, right?

s76
00:07:02.120 --> 00:07:04.000
Through machine payments.

s77
00:07:04.000 --> 00:07:15.000
So, we work with a partner and Never mind to be able to enable that that that use case and leveraging our they're leveraging our infrastructure.

s78
00:07:15.000 --> 00:07:15.760
Right?

s79
00:07:15.760 --> 00:07:26.480
So, there is two pieces of infrastructure that they that I like to kind of to call out or primitives that they use that as part of the Braintree or PayPal enterprise

s80
00:07:26.480 --> 00:07:27.080
infrastructure.

s81
00:07:27.080 --> 00:07:28.880
One is like the vault, right?

s82
00:07:28.880 --> 00:07:42.680
And the vault by itself, which is storing all these like payment credentials on behalf of the on behalf of the buyer agents, on itself doesn't really do much, but in order to create

s83
00:07:42.680 --> 00:07:58.680
what nevermind creates is a a more eco closed ecosystem, they then off you're able to um offer uh or offer access to those payment credentials through OAuth, right?

s84
00:07:58.680 --> 00:07:59.880
To all those merchants.

s85
00:07:59.880 --> 00:08:06.240
So, in our example before we talked about that that travel travel um travel company, right?

s86
00:08:06.240 --> 00:08:17.880
So, by doing so, they're able to then create like an ecosystem um of buyer agents and seller agents uh and have a more trusted environment, right?

s87
00:08:17.880 --> 00:08:28.600
So, um in the in the just kind of talking more about the use case, like the human then is then going to be authorizing authorizing their their payment.

s88
00:08:28.600 --> 00:08:31.840
Usually, this is a commercial card commercial use case.

s89
00:08:31.840 --> 00:08:36.400
So, you're using like a commercial card, they share it with the buyer agent, travel agent.

s90
00:08:36.400 --> 00:08:43.719
Um then that uh it it also has scopes associated with that mandate.

s91
00:08:43.719 --> 00:08:54.360
So, that's how you're able to do controlled authority, but in terms of like the actual like dispute handling, we really uh don't have like a we're not using like

s92
00:08:54.360 --> 00:08:58.600
cryptographic proof that's being sent as part of that that request, right?

s93
00:08:58.600 --> 00:09:09.000
At the end of the day, they can since it's more of a closed ecosystem, they're able to leverage like the just the existing transaction logs.

s94
00:09:09.000 --> 00:09:09.640
Right?

s95
00:09:09.640 --> 00:09:23.400
So, that's kind of an example of like a medium stakes and use case or scenario, and we we believe it's medium stakes because of the fact that it is a more closed ecosystem

s96
00:09:23.400 --> 00:09:33.200
and doesn't require all like the you know, evidence in terms of or proof, right?

s97
00:09:33.200 --> 00:09:35.520
So, that's kind of like my part.

s98
00:09:35.520 --> 00:09:40.680
I'll going to turn it over now to Ben and uh take it from here.

s99
00:09:40.680 --> 00:09:43.080
Uh thanks, Jay.

s100
00:09:43.760 --> 00:09:50.800
Yeah, so the last slide that Jay talked about, um you know, we're kind of going over the medium stakes example.

s101
00:09:50.800 --> 00:09:56.480
Uh um In that scenario, um you know, both parties know each other.

s102
00:09:56.480 --> 00:09:59.360
Uh they're acting within, you know, the same system.

s103
00:09:59.360 --> 00:10:11.240
They they know you know, they're borrowing trust from, you know, Nevermind to make sure that, you know, the buying agent is falling within, you know, the instructions that a human has given it.

s104
00:10:11.240 --> 00:10:19.720
Um and then the selling agent that's also on Nevermind can feel comfortable taking a payment um from another user of of Nevermind.

s105
00:10:19.720 --> 00:10:26.440
And And so, what we want to talk about next is what happens when the parties are are not known to each other and they're not vetted.

s106
00:10:26.440 --> 00:10:38.680
Um And so, like we think, you know, we believe that the best option for that, you know, is actually do these autonomous payments, um where, you know, you know, not everyone's known.

s107
00:10:38.680 --> 00:10:40.600
Like you know, the stakes are high.

s108
00:10:40.600 --> 00:10:47.160
You know, we think that the industry should converge on the FIDO verifiable intents and AP2 mandate.

s109
00:10:47.160 --> 00:10:53.320
Um You know, the TLDR of that is, you know, it's a a multi-layered selective disclosure jot.

s110
00:10:53.320 --> 00:10:58.960
Uh The first layer is, you know, created by a trustworthy credential provider.

s111
00:10:58.960 --> 00:11:01.320
You know, in this case, hopefully it would be PayPal.

s112
00:11:01.320 --> 00:11:05.720
Um The second layer, you know, encapsulates the user's instructions to the agent.

s113
00:11:05.720 --> 00:11:09.160
Um The user signs that with their private key.

s114
00:11:09.160 --> 00:11:15.440
And then the third layer, if there's going to be a third layer, is when um we're doing autonomous payments.

s115
00:11:15.440 --> 00:11:19.160
So, that case, the agent would, you know, sign that third layer.

s116
00:11:19.160 --> 00:11:30.200
And And so, the where that's powerful is that, you know, party involved in a transaction can can verify the part that's, you know, important to them.

s117
00:11:30.200 --> 00:11:34.360
So, merchants can verify that the checkout is correct.

s118
00:11:34.360 --> 00:11:38.200
Um Um payment processors can verify that the payment mandate is correct.

s119
00:11:38.200 --> 00:11:42.080
Um And no one has to have any relationship to each other.

s120
00:11:42.080 --> 00:11:50.400
Um And so, like I think, you know, if there's going to be a ton of payments, you know, at scale, we think that that's going to be the best

s121
00:11:50.400 --> 00:11:52.960
um way to accomplish it.

s122
00:11:52.960 --> 00:11:57.920
Uh pictures on the screen are depicting our PayPal approval token.

s123
00:11:57.920 --> 00:12:10.520
Um This is a new primitive that allows users of PayPal to basically start the order process with an agent um for that agent has actually found an item at a merchant to transact with.

s124
00:12:10.520 --> 00:12:14.040
Uh historically, PayPal orders have been synchronous.

s125
00:12:14.040 --> 00:12:22.440
Um You know, users on checkout, they find their item, they go to their PayPal app, they approve it, um and it's done.

s126
00:12:22.440 --> 00:12:24.960
Uh here, it's a little bit different, you know.

s127
00:12:24.960 --> 00:12:35.240
Users on their agent, um they get redirected to PayPal to confirm the instructions that are given to the agent, and then uh PayPal hands back this JSON payload.

s128
00:12:35.240 --> 00:12:44.000
Um you know, similar to the verifiable intent, uh includes the amount, the expiry, uh the merchant that is supposed to be transacted with.

s129
00:12:44.000 --> 00:12:47.680
Um Similar concept, but not quite the same.

s130
00:12:47.680 --> 00:12:52.839
Um it's an opaque string that only PayPal can approve right now.

s131
00:12:52.839 --> 00:13:01.160
But we're about to ship this into production, um and users of Jet and I that pick PayPal as a payment method will will use this.

s132
00:13:02.000 --> 00:13:07.080
Um so, going to our last slide, um you know, we showed this slide earlier.

s133
00:13:07.080 --> 00:13:10.400
It we didn't have the two columns filled out on the right-hand side.

s134
00:13:10.400 --> 00:13:24.120
Um You know, we wanted to reinforce this mental model where, you know, starting at the top, we have, you know, the low-stakes scenario, you know, you're you're using Claude, you've given it access to connectors, you know, granular permissions to do things on your behalf.

s135
00:13:24.120 --> 00:13:27.440
Um you feel comfortable doing that because the stakes are low.

s136
00:13:27.440 --> 00:13:29.640
You know, you can reverse those actions or redo them.

s137
00:13:29.640 --> 00:13:33.600
It's not a big deal if Claude produces, you know, the wrong output.

s138
00:13:33.600 --> 00:13:36.680
Uh going down a level, we have the medium stakes scenario.

s139
00:13:36.680 --> 00:13:42.000
You have two parties that know each other that are acting within the same system's boundary.

s140
00:13:42.000 --> 00:13:44.840
Um you know, the the actions are a little bit higher stakes.

s141
00:13:44.840 --> 00:13:54.200
You know, there is money movement here, but both parties can can feel comfortable, you know, transacting with each other because they're relying on this this third party to enforce

s142
00:13:54.200 --> 00:13:56.680
uh the payment mandate.

s143
00:13:56.680 --> 00:14:05.160
And then the third level, you know, the highest stakes one um that we haven't actually really seen in production yet, it's, you know, the user's giving an agent some

s144
00:14:05.160 --> 00:14:11.320
instructions to do something on their behalf autonomously, and you don't know who they're going to interact with, who they're going to transact with.

s145
00:14:11.320 --> 00:14:17.320
Um and those parties need some verifiable proof that the agent has permission to do the transaction.

s146
00:14:17.320 --> 00:14:24.360
And so, we believe that that will be um either verifiable dents and and AP2 mandates.

s147
00:14:24.360 --> 00:14:34.360
Um I think the interesting thing is it's also our belief that, you know, this is a model that can't won't just be used for payments, but we think it could be for

s148
00:14:34.360 --> 00:14:36.480
any sort of high-stakes action that's hard to reverse.

s149
00:14:36.480 --> 00:14:44.760
So, medical orders, e-signatures, securities trading, um you know, basically any hard-to-reverse agent action.

s150
00:14:45.000 --> 00:14:46.200
That's all I have.

s151
00:14:46.200 --> 00:14:54.360
Yeah, I mean, I think um if we could just go back to analogies, uh you know, like in the low stakes is kind of like, "Hey, you're within the the building.

s152
00:14:54.360 --> 00:14:56.800
You've uh put a badge in and you're within the building."

s153
00:14:56.800 --> 00:15:02.520
Whereas in the um high stakes is kind of like, "You are on the street and you meet somebody."

s154
00:15:02.520 --> 00:15:09.400
And uh you know, you need a way to be able to uh get comfort that that's someone you can trust, right?

s155
00:15:09.400 --> 00:15:13.440
Um is a badge is them showing you their badge good enough?

s156
00:15:13.440 --> 00:15:14.440
Uh probably not.

s157
00:15:14.440 --> 00:15:19.320
You need to have something that's a little bit more um you know, verify verifiable.

s158
00:15:19.320 --> 00:15:21.040
Or I guess at a verifiable standard.

s159
00:15:21.040 --> 00:15:34.240
So, um you know, just kind of like using that analogy and like how to think about like the you know, what you need to do in order to prove the that the human authorized the agent.

s160
00:15:34.240 --> 00:15:39.640
Hopefully that that helps and now you have kind of like a tool set to use.

s161
00:15:39.640 --> 00:15:43.080
So you can kind of prevent Skynet from taking over your wallet.

s162
00:15:43.080 --> 00:15:45.800
So, thank you very much for your for listening.

s163
00:15:45.800 --> 00:15:48.200
Hope that helps.

s164
00:15:49.105 --> 00:15:51.105
[applause]

s165
00:16:04.826 --> 00:16:06.826
[music]
