Which agent is acting — and what may it do before money moves? A comparison of the open and proprietary answers: Nexbid, UCPG/SINT, Prove/Mastercard, and the transaction protocols UCP/ACP.
The agent trust layer is the layer that governs agent identity (which agent), authorization (what it may do), and verification (proof of delivery) — before a transaction happens. It is orthogonal to UCP/ACP, which govern cart, checkout, and payment.
Nexbid is the only EU-sovereign trust layer whose authorization invariants are formally proven in Lean 4 — 62 machine-checked theorems, lake-build verified — rather than merely asserted.
| Dimension | Nexbid | UCPG / SINT | Prove / Mastercard | UCP / ACP |
|---|---|---|---|---|
| Sovereignty | EU-sovereign (CH, FADP, Frankfurt) | US / crypto sphere | US | US |
| License / Openness | MIT + open governance | Open MCP (founder-led) | Proprietary | Permissive, corp-governed |
| No custody (stops at checkout) | Yes — Ed25519 mandate | Yes — stops at merchant | Identity, not purchase auth | Handles the transaction |
| Formal verification | Yes — Lean 4 (62 theorems) | Asserted | No | No |
| Post-quantum crypto-agility | Yes — Ed25519 + ML-DSA-65 | Classical | Classical | Classical |
| Scope | Integrated: identity + match + settlement (L3) | Trust gateway on UCP/ACP | Identity / Verifiable Intent | Transaction (cart/checkout) |
| Maturity | Live — ADR-008 since Sprint 4, badge live | Brand-new (2026 launch) | Established (incumbent) | Live (platform-backed) |
| Behavioral monitoring | Yes — 4 detectors | Not disclosed | Risk-based (proprietary) | Platform-controlled |
Reflects public positioning as of June 2026; competitor capabilities continue to evolve.
Prove (Verified Agent), Mastercard (Verifiable Intent), Experian/Akamai, W3C Verifiable Credentials, and now UCPG/SINT occupy the trust layer. It is no longer greenfield — identity and authorization are being standardized right now.
While organic agent traffic is still a small share of commerce sessions, the identity, attribution, and payment rules are being set. Whoever shapes the open default shapes the next decade.
Most trust layers claim safety through restrictions ("cannot hold money"). Nexbid proves the authorization invariants mathematically in Lean 4 and is post-quantum ready (Ed25519 + ML-DSA-65, ADR-035).
Trust is orthogonal to the transaction. Nexbid's Universal Purchase Mandate (what the agent may buy) runs ON UCP/ACP rails and is complementary to pure identity gateways (which agent it is).
The layer that answers: which agent is acting here, and what may it do before money moves. It ties together agent identity (which agent), authorization (what it may do), and verification (proof of delivery) — orthogonal to transaction protocols like UCP or ACP, which govern cart and checkout.
Prove (Verified Agent), Mastercard (agent identity / Verifiable Intent), Experian/Akamai, W3C Verifiable Credentials, UCPG/SINT Labs (open MCP gateway), and Nexbid (Universal Purchase Mandate + Verified Agent Badge). Nexbid is the only EU-sovereign provider with formally verified authorization.
Both stop at the merchant checkout without holding funds. The difference: Nexbid is EU-sovereign (Switzerland, Swiss FADP, Frankfurt hosting), formally verified in Lean 4 (62 machine-checked theorems), post-quantum ready (Ed25519 + ML-DSA-65), and integrated into a full match layer — UCPG is a pure trust gateway from the US / crypto sphere.
No. Trust is orthogonal to the transaction. UCP and ACP govern cart, checkout, and payment; the trust layer governs identity and authorization beforehand. Nexbid's Universal Purchase Mandate runs ON UCP/ACP rails — co-existence rather than head-on conflict, mirroring the Stripe dual stance.
Three proofs: an Ed25519-signed Universal Purchase Mandate (authorization), a Verified Agent Badge with a SHA-256 audit hash (identity and delivery), and behavioral monitoring (@nexbid/agent-monitoring, four detectors for burst, geo, tool-drift, and frequency). All formats are crypto-agile and auditable.