Present vs. Provable: A Conformance-Testing Methodology for the Authority Layer of Agentic Payments

Michael K. Saleme · Zenodo (CERN European Organization for Nuclear Research) · 2026

Autonomous agents now authorize and execute payments without a human approving each transaction. Existing payment protocols verify identity, cryptography, and settlement, yet they leave one question unanswered: can a verifier prove that an executed payment is the one the principal actually authorized? This paper isolates that question as the distinction between a payment parameter being present on the wire and being provable at the boundary, and it introduces a conformance-testing methodology for the authority layer where the answer is decided. The methodology uses fail-closed differential vectors executed against a reference verifier, together with distinct constructions for three attack classes a tampered-input test does not capture: liveness at settlement finality, adversarial interposition by an intermediary that mutates a well-formed request in transit, and binding-scope drift across a multi-leg payment route. We ground the central requirement in an existing regulatory precedent, PSD2 Strong Customer Authentication dynamic linking, and we validate the methodology through an open-source implementation of 540 conformance tests, including fail-open defects the methodology surfaced in its own reference verifier. Part of the series: Machine-Verifiable Governance for Autonomous Systems.Version 2 (2026-07-08): incorporates external technical review. Scopes the authority claim as execution ⊆ mandate(t) ⊆ intent(t) (intent-capture out of scope; mandate-liveness at execution in scope); adds a binding-oracle independence (separation-of-duties) precondition; a multi-leg integrity-with-authorized-mutation construction; and separates authentication-time (gate) from receipt (forensic) verification. Central property and validation results unchanged.

Read the paper · More papers on PaperTik