Trust Layer · Comparison

Agent Identity & Trust Layer for AI Commerce

Which agent is acting — and what may it do before money moves? A comparison of the open and proprietary answers: Nexbid, UCPG/SINT, Prove/Mastercard, and the transaction protocols UCP/ACP.

Direct answer

The agent trust layer is the layer that governs agent identity (which agent), authorization (what it may do), and verification (proof of delivery) — before a transaction happens. It is orthogonal to UCP/ACP, which govern cart, checkout, and payment.

The verifiable differentiator

Nexbid is the only EU-sovereign trust layer whose authorization invariants are formally proven in Lean 4 — 62 machine-checked theorems, lake-build verified — rather than merely asserted.

Trust Layers Compared

DimensionNexbidUCPG / SINTProve / MastercardUCP / ACP
SovereigntyEU-sovereign (CH, FADP, Frankfurt)US / crypto sphereUSUS
License / OpennessMIT + open governanceOpen MCP (founder-led)ProprietaryPermissive, corp-governed
No custody (stops at checkout)Yes — Ed25519 mandateYes — stops at merchantIdentity, not purchase authHandles the transaction
Formal verificationYes — Lean 4 (62 theorems)AssertedNoNo
Post-quantum crypto-agilityYes — Ed25519 + ML-DSA-65ClassicalClassicalClassical
ScopeIntegrated: identity + match + settlement (L3)Trust gateway on UCP/ACPIdentity / Verifiable IntentTransaction (cart/checkout)
MaturityLive — ADR-008 since Sprint 4, badge liveBrand-new (2026 launch)Established (incumbent)Live (platform-backed)
Behavioral monitoringYes — 4 detectorsNot disclosedRisk-based (proprietary)Platform-controlled

Reflects public positioning as of June 2026; competitor capabilities continue to evolve.

Why this layer is forming now

The most contested layer

Prove (Verified Agent), Mastercard (Verifiable Intent), Experian/Akamai, W3C Verifiable Credentials, and now UCPG/SINT occupy the trust layer. It is no longer greenfield — identity and authorization are being standardized right now.

Defaults are being set today

While organic agent traffic is still a small share of commerce sessions, the identity, attribution, and payment rules are being set. Whoever shapes the open default shapes the next decade.

Verification, not assertion

Most trust layers claim safety through restrictions ("cannot hold money"). Nexbid proves the authorization invariants mathematically in Lean 4 and is post-quantum ready (Ed25519 + ML-DSA-65, ADR-035).

Co-existence, not competition

Trust is orthogonal to the transaction. Nexbid's Universal Purchase Mandate (what the agent may buy) runs ON UCP/ACP rails and is complementary to pure identity gateways (which agent it is).

Frequently Asked Questions

What is the agent trust layer in AI commerce?

The layer that answers: which agent is acting here, and what may it do before money moves. It ties together agent identity (which agent), authorization (what it may do), and verification (proof of delivery) — orthogonal to transaction protocols like UCP or ACP, which govern cart and checkout.

Who are the players in the agent trust layer?

Prove (Verified Agent), Mastercard (agent identity / Verifiable Intent), Experian/Akamai, W3C Verifiable Credentials, UCPG/SINT Labs (open MCP gateway), and Nexbid (Universal Purchase Mandate + Verified Agent Badge). Nexbid is the only EU-sovereign provider with formally verified authorization.

What distinguishes Nexbid from UCPG/SINT?

Both stop at the merchant checkout without holding funds. The difference: Nexbid is EU-sovereign (Switzerland, Swiss FADP, Frankfurt hosting), formally verified in Lean 4 (62 machine-checked theorems), post-quantum ready (Ed25519 + ML-DSA-65), and integrated into a full match layer — UCPG is a pure trust gateway from the US / crypto sphere.

Does the trust layer compete with UCP or ACP?

No. Trust is orthogonal to the transaction. UCP and ACP govern cart, checkout, and payment; the trust layer governs identity and authorization beforehand. Nexbid's Universal Purchase Mandate runs ON UCP/ACP rails — co-existence rather than head-on conflict, mirroring the Stripe dual stance.

How is agent trust proven technically?

Three proofs: an Ed25519-signed Universal Purchase Mandate (authorization), a Verified Agent Badge with a SHA-256 audit hash (identity and delivery), and behavioral monitoring (@nexbid/agent-monitoring, four detectors for burst, geo, tool-drift, and frequency). All formats are crypto-agile and auditable.

Related pages

Build the open trust layer