Updates

What's new in Agentcard — new features, improvements, and fixes, shipped continuously.

Added
  • A cardholder can now draft an auto-approval spending rule on a computer that doesn't hold their account key — the phone that does hold it scans a code, checks it against what the computer is showing, and signs the rule to turn it on, without ever handing the computer a key of its own.
  • A company can now exchange a linked Vault session once for a connection token, so its agent can buy as that user without ever minting a token on its own.
  • Checkout now reads back whether a charge actually settled with the payment processor instead of stopping at "authorized." A payment resolves to settled, not settled, or unknown with a reason, and organizations now get a webhook when that answer lands.
Improved
  • Vault checkout approvals now survive a merchant's page giving up on a paused purchase — the checkout SDK keeps the approval alive and finishes the purchase when the merchant retries, instead of losing it to a timeout.
Fixed
  • Searching for an item now matches its plural or singular form — asking for a "battery" now finds a store listing "Batteries" — and an order-only store that doesn't carry an item now offers a plain search instead of naming two stores.
  • Fixed a Checkout.com ordering bug where a phone could be asked to approve a payment after checkout had already started, sometimes missing its own deadline, and a public-key formatting bug that kept one merchant's checkout page from completing.
Added
  • A company admin can now upload a Vault logo straight from their computer. The browser resizes it to fit the header, and an oversized file is told its exact size instead of getting a generic save error.
Improved
  • The Vault approval screen now leads with the amount and lets you choose which card pays from a sheet that shows each one. The unlock screen offers its ways in as buttons, saved cards read as a wallet, a card's details show its own art, who issues it and what it earns, and every card and approval screen names which account you're signed in as.
  • Vault checkout now survives brief disconnects and background browser tabs closing — the checkout SDK retries approval reads and runs dedicated workers, so an approved payment keeps going instead of stopping.
Fixed
  • Naming a live retail store now runs a search pinned to that store instead of a refusal listing a few store names, and a store we can't search says so plainly instead of sending you back to retry a search that can never return.
  • Searching for a table without naming a service now shows venues from more reservation providers together, and the vault.card_stored test webhook now carries a card id shaped like a real one so integrators stop expecting a vc_ prefix.
Added
  • You can now add a card to the Vault by photographing it — the number and expiry fill themselves in for you to check. The reading happens in an isolated frame on your phone with no network and no storage, so the photo never leaves your device. You still type the security code yourself.
  • An integration that manages its own users' addresses can now send delivery_address on POST /buy and the order ships there, instead of the buy loop re-asking about a saved default.
Improved
  • Delivery orders now show the store's name, its delivery estimate and item photos before checkout, and a placed order reports when it will arrive. Reconnecting a delivery account you've already linked now says it's already connected instead of sending you a second sign-in link.
  • Vault checkout now completes at more payment processors, including ones whose payment has to be approved before the shopper's tap so the request doesn't time out. A diner's restaurant card hold can now also be paid straight from their Agentcard vault with a single approval, no card typed anywhere.
Fixed
  • A retail order to a non-US shipping address is now refused up front instead of being approved and then unable to ship — an address whose postal code or region only looks American no longer passes as a US one.
  • Sign-in and connect emails now show the Agentcard mark instead of a broken image, and the Vault checks for an existing card before enrollment so an emailed code can't add a second permanent passkey to an account.
Added
  • Your agent can now book more than a restaurant table — fitness classes, event tickets and hotel rooms are bookable through Agentcard, each paid with a single-use card. A table reservation can now also hold a card or take a deposit on the venue's own secure page, and a booking can be cancelled or changed, all without a card ever being typed into Agentcard.
  • The Vault now has a Your devices screen that lists every way into your account with its type, badges and dates, and keeps each device's actions behind a menu on its row.
Improved
  • Orders priced outside US dollars now read clearly from end to end — an approval shows the amount in the store's own currency (for example CA$9.24) on any device, and the purchase conversation and receipts name the store's own total and currency.
  • Dashboard settings are now grouped into Company, Issuing, Vault and Developers, and you can rename the company or change its billing email in place. A company can also read each person's Purchase API activity as one timeline, with the order webhooks it was sent shown next to each request.
Fixed
  • Hosted identity-verification links now carry the user id and signature on every path, so they keep opening after our verification partner's upcoming requirement change.
  • Vault checkout now correctly identifies hosted, regional and versioned card forms, and a payment processor's own script loaded next to our SDK is no longer mistaken for the processor itself.
Added
  • Companies can now open Agents → Purchase in the dashboard and read every conversation their users had with the Purchase API, with each /buy request shown against its thread. A conversation stays tied to the company that owns it even if its integration is moved, switches between test and live, or is deleted.
  • Every card read now returns the cardholder name and billing address a merchant's payment form asks for, so an agent entering an issued card clears the issuer's address check instead of guessing. A verified cardholder's name is now locked to the one their identity check approved.
  • A company can now set the logo shown at the top of its users' Vault, with a live preview in the dashboard.
Improved
  • Saved cards in the Vault now each show their own network logo and open a details sheet where you can rename the card or remove it after one question, and the add-a-card screen shows the network's logo as you type the number.
Fixed
  • The checkout SDK now recognizes current payment-processor pages and confirmation fields and can confirm a merchant payment without an order number, so more checkouts complete.
Added
  • Every company now starts on a free plan with full production access — live keys, real card issuance and a live company balance — with no subscription needed. The paid plan only lifts the limit on how many cardholders you can have live at once (5,000 on the free plan), and letting a subscription lapse no longer takes your production access away: you keep it and only re-acquire the higher limit.
Improved
  • In the dashboard, a company can now open one of its users and see whether their deposit has arrived and what they can spend. A shared wallet's funding history stays in order, a new deposit shows up within about a minute, payments are scoped so a company only ever sees the ones it started, and a rejected user's profile now names the rejection, its date and its reason.
Fixed
  • Funding your wallet no longer wrongly refuses larger or repeat top-ups — top-ups around $1,000 and back-to-back top-ups that had been declined at payment now go through.
  • The Vault sign-in code screen now ignores late resends and sends one code per tap, a spent link is recognized, and a passkey stored in a password manager opens the vault on an iPhone after a failed attempt — a passkey-only account always keeps a way back in.
Added
  • You can now approve a new device for your Vault cards from the phone that already holds your key, using a scanned code or a link, so your cards follow you there without re-entering the master password. A linked device can open cards right away, but it can only change autopilot spending rules if you separately allow it. Every device that can open your cards now shows up in one list, with a note on which spending rules keep running if you remove it. If your only device is ever out of reach, a new device has to wait a day for the master password before it's let in, and both the old and new device are notified so you can stop it if it isn't really you. Turning autopilot on now requires setting a master password first, so losing your only device never strands your cards.
Improved
  • The merchant registry behind Strict category and place rules now learns from every approved Vault purchase within about a minute, instead of being rebuilt by hand once a week. A merchant is only added automatically once two unrelated companies have bought there under a category the card network or payment processor itself assigned, so an automatic addition can never loosen a company's spending rules on its own. When a newly confirmed merchant lets a Strict rule pass for your company, you're notified once and can block that merchant for your company alone in one click.
Fixed
  • Fixed community-event ticket search and purchase showing nothing on sale in production, because the live catalog reported every event's availability as unknown. Ticket tiers now decide what's actually on sale, so your agent can find and buy tickets.
Added
  • Your agent can now buy tickets to community events — it browses what's on sale, builds the order, and pays with a one-time Agentcard. Your ticket order stays intact even if you later link or merge accounts.
  • You can now check whether the Vault checkout supports a given payment processor before your agent ever enters card details. The checkout SDK (now 0.9.0) ships a preflight helper that identifies the processor from the checkout page and reports whether it is supported, running entirely on your side with no Agentcard account, card, or network call needed.
  • Behind the scenes, we started building Vault Autopilot: a card you've saved can carry a spending budget your connected agents draw from across every app, so an agent pays within a limit you approved once instead of stopping to approve each purchase, and the remaining budget stays correct even if the service restarts or is recovered. Opt-in and shipping dark behind a flag while we test it — nothing about today's approvals changes.
Improved
  • The Vault now speaks to whatever device you're on. Every prompt, notice, error, and guide describes your own phone or computer and the way you actually unlock it, instead of assuming an iPhone with Face ID, and none of them names a payment vendor. Every account also keeps a second way in: a master password set before your first card is stored, and a way to start over if the only key is ever out of reach.
  • Companies using promotional credit can now see where their credit sits and when the next top-up lands, right on the Balance page. A top-up whose last attempt failed now reads as "Delayed, queued and retried automatically" instead of wrongly showing as on its way.
Fixed
  • Fixed opening the Vault while a payment was waiting dropping you on your list of saved cards instead of on the approval that needed you — a pending approval now comes first, and a run of recent test purchases can no longer bury it.
  • Fixed the agent-cards account link command failing every time with an "Invalid JSON body" error before it could read your details — it now sends your one-time code and links the account as intended.
Added
  • Company presets on the Vault now judge category and place: Agentcard names the merchant from the checkout page your agent paid on and from the merchant identity inside the payment request, never from the text your agent typed, and a merchant Agentcard does not know is refused under a Strict category or place rule. The built-in presets weekday_meals and ai_labs work on both products.
  • Vault caps work without your agent sending an amount. The processor's own amount is the authority: read from the paused payment request on Tranzila, Razorpay, Nuvei, Paysafe and Adyen, or from the Stripe intent it names, right before the card is sent. Send amount as a hint to have a purchase judged the moment it opens.
Improved
  • One word for the amount, as Stripe defines it: every checkout authorization, preparation and webhook returns amount (an integer in the currency's smallest unit), currency, and amount_display (the human form), with amount_authority saying who named it. A decimal string with a point ("23.06") is accepted as normal units.
  • An Issuing settlement that arrives with no merchant code is judged on the merchant registry's category instead of being refused as unknown; the network's code wins whenever it is present.
Fixed
  • Breaking: amount_cents and charged_amount_cents are gone from checkout authorizations, preparations and the Issuing transaction webhooks (transaction.authorized, transaction.cleared, transaction.declined, transaction.voided). Read amount, currency and amount_display instead; the checkout SDK's amountCents is now amount, and chargedAmountCents is chargedAmount. Wallet funding, card creation and recovery amounts are unchanged.
Added
  • Your agent can now book a restaurant table for you — it searches restaurants, offers you the available times, and finishes the booking with the confirmation code the venue texts you. A reservation places for free, and no card is charged.
  • Delivery orders to a Canadian address now browse and build a cart priced in Canadian dollars. A cart in a currency we can't yet charge is refused at checkout, with the reason, instead of being charged as US dollars.
Improved
  • A product search across our retail merchants now covers every supported store at once, so you no longer have to name a store first. A search pinned to a store that doesn't carry the item now tells you which stores do, instead of failing as though the whole search were down.
  • The Vault checkout SDK (now 0.6.0) recognizes and completes checkout on more payment processors' hosted flows — it approves the payment before the processor's own card request runs, and reports a processor's validation error without ever sending the card.
Fixed
  • Fixed a couple of Vault display glitches, where the saved-card list could fall out of alignment and an approval's progress spinner could disappear before the payment finished.
Added
  • Companies can now brand the shared Vault themselves — set a display name and logo under Settings → General, and they show on the shared Vault pages your users see. This is the self-serve version of the partner branding added earlier; a company that sets nothing sees no change.
Improved
  • Every spending category a card can restrict now follows one rule — Strict refuses the charge and pauses the card, Watch allows it and tells you — and the older split where some categories only warned is gone. The paused and watched emails and texts now carry the exact command to allow a merchant or resume the card, with the card and merchant filled in; a currency-rule violation now names the charge's currency and the ones you allow, and notes that Agentcard enforces the currency rule, not the card network.
  • Every charge now settles all-or-nothing, and the card network is kept in step, so a card is never left open in one place and closed in the other. A card that is being paused or closed reads as Pausing or Closing everywhere it is shown — the CLI, the MCP tools, the dashboard, and the partner API — until the network confirms, then Paused or Closed.
Fixed
  • Fixed a personal sign-up being asked to name a company, and a failed company lookup dropping members off the company path — a personal link is now remembered on your device, and members stay on the company path while it loads.
  • Fixed some partner-routed accounts showing no spending power on a funded wallet — the amount you can spend now reads from the wallet balance itself, minus anything already reserved by a card being created.
Added
  • The dashboard is now a companies-focused console built around the two ways organizations use Agentcard — Vault (stored cards and checkout approvals) and Issuing (cards, transactions, and balance) — with a new guided onboarding that walks you from testing in the sandbox through subscribing to going live, and a one-tap link to accept your company's Slack invitation. The older personal dashboard has been retired, and its links now lead into the new console.
Fixed
  • Fixed personal accounts reached through an AI agent connection not always having their plan's per-card and monthly card limits applied — these connections now correctly follow the account's own plan limits, while company and partner connections continue to be governed by their organization.
  • Fixed identity verification showing an endless "final approval in progress" spinner when the card issuer had actually sent the application back asking for more information — you're now taken straight to the step the issuer needs, instead of waiting on a review that would never finish on its own.
  • Fixed consumer identity verification that could drop you back to the first step each time you checked its status, even after you'd finished, when an ID-document step hadn't been recorded — the missing step is now reconciled automatically so a completed verification stays completed.
  • Fixed the onboarding "connect" step leaving people with no way forward if they didn't want to type a test card into the sandbox wallet — there's now a working skip that runs the rest of the walkthrough on a sample purchase, plus clearer wording that your own account is already live even while the wallet is in test mode.
  • Fixed the Connected agents list never showing when each agent connected or was last used — every row displayed a dash regardless. The dashboard now reads those dates the same way the CLI and MCP tools already did.
  • Fixed Add funds collapsing three different reasons a top-up can be unavailable into a single generic "contact support" message — the dashboard now shows the specific reason for each, matching what the CLI and MCP already surfaced.
  • Fixed a funding session that failed before it ever reserved a payment staying open indefinitely, where it could keep counting against limits — these are now expired and cleaned up like any other abandoned session.
  • Fixed the wallet leaving you at a dead end when your only card was one we can't accept (for example, a consumer Visa issued outside the US) — you're now offered the option to create an Agentcard, which needs no bank card at all, instead of only "add a different card".
  • Fixed Vault's add-a-card form accepting an expired or malformed expiry date and only failing later — an expired, incomplete, or far-future date is now caught and explained right on the form, before the card is saved.
  • Fixed a case where the API might not automatically reconnect after a routine database credential rotation, which could leave requests erroring until it recovered on its own — the automatic reconnect now works as intended.
Added
  • Agentcard Vault can now be branded for a partner organization — a custom domain, product name, accent color, and support and return links, with card enrollment and passkeys scoped to that domain and sign-in codes sent under the partner's own name. It's live for the small number of partner organizations we've configured it for so far; on a branded domain the shared Agentcard sign-in isn't offered, and the partner delivers the approval link to its own user instead of Agentcard notifying them directly.
  • Added a checkout coverage API for integrators building on the Vault checkout SDK: one endpoint lists every payment flow we currently recognize, and a companion endpoint takes a batch of an integrator's own observed checkout requests and returns a weighted breakdown of what's recognized, unsupported, or still unverified — so integrators can see how much of their checkout traffic is covered before going live.
  • The checkout SDK (now 0.3.0) gained a full lifecycle controller for browser-driven checkouts — it tracks state through approval, merchant confirmation, and completion, can hold further card requests until the integrator's own merchant system confirms the order, and only allows a new attempt after that confirmation. A processor's approval or card token by itself is never treated as a completed order.
Fixed
  • Fixed a checkout gap where a payment processor's tokenization step (which returns a reusable card token rather than a bound charge) could be treated as authorizing a later payment or saved-card confirmation with no verified amount — that path now fails closed and asks for a separately validated checkout flow instead.
Fixed
  • Fixed identity verification getting stuck retrying and failing every ten minutes for applicants with no residential address on file (for example, some imported through a company account) — these are now parked cleanly pending an address instead of erroring repeatedly.
Added
  • Adding a card is now one single flow everywhere — the dashboard, the embedded wallet, the CLI, and any connected agent all open your Agentcard Vault instead of the old one-time network-token enrollment. That older hands-free enrollment is still available for integrators who want it, it's just no longer the front door.
  • Purchases now pay from your saved Vault card by default when it's the only way you have to pay, and callers can also request the Vault explicitly to make that choice deterministic.
  • The Purchase API gained a way to browse the merchant catalogue — a new read listing every supported merchant along with a documented connection-status value for each.
Fixed
  • Fixed an internal access gate that had briefly blocked the new merchant-catalogue read, and the existing purchase-conversation-status read, for some callers using the same credential as their purchase.
Added
  • Retail orders placed through our managed checkout integration now report the retailer's own confirmation once it accepts the order — its order number, quoted delivery window, and final total — plus a new order.confirmed notification for organizations; order tracking also now names the retailer's reason when an order fails, like a needed verification step versus an item being out of stock. Getting confirmations flowing reliably took a couple of same-day fixes to correctly read the retailer's live response format.
  • Cart and checkout screens now disclose a card's real spending ceiling as "charge up to $X" — retail merchants only finalize tax and shipping at order placement, so a one-time card is sized a bit above the item total, and this keeps that headroom from reading like an overcharge. Organizations can also opt in to automatically returning a cardholder's unused headroom to the shared company balance once they've been idle for a while.
  • Redesigned the Vault's "Your cards" list — cleaner per-network card previews, a safer two-tap way to remove a card, and fixed control styling (also fixed the page failing to render at all on older Safari versions).
Fixed
  • Fixed retail orders placed through your own linked retailer account sometimes still routing through Agentcard's shared account instead — checkout wasn't always able to tell which retailer a cart belonged to, retailer names could disagree between registration and checkout, and accounts linked before a naming fix needed healing. All of these now resolve correctly, and a cart that can't be resolved cleanly (for example, one mixing retailers) safely falls back to the shared account instead of erroring.
  • Fixed a cross-origin checkout error on some merchant integrations where an approved card payment could still show the shopper a connection error, even though the card had already been charged (checkout SDK updated to 0.2.1).
  • Fixed a device passkey approval error being shown as a generic failure — a device that hasn't set up a card's passkey yet is now correctly offered a way to set it up, instead of a dead-end retry.
  • Fixed a proxied storefront page (agentcard.sh/shop) that would load but never become interactive, because some of its supporting scripts weren't being served correctly.
  • Fixed a checkout idempotency bug where retrying a payment approval, switching cards, or starting a fresh purchase on the same cart could inherit a stale retry key and get wrongly refused; also fixed the checkout API not reading its idempotency key from the request body as documented.
Added
  • Vault checkout now supports two additional ways to pay with certain payment processors while keeping the raw card number away from Agentcard: one encrypts the card directly on your device before it reaches the processor and gets a normal confirmed-or-declined answer back; the other lets the processor's own hosted card form complete right inside the approval screen, though that method can only confirm the form was submitted from your device, not that the processor actually accepted the payment
  • Opening your Agentcard Vault now takes you straight to your saved cards (brand, last four, when each was added and last used) instead of the add-a-card form — partner links and a genuinely empty vault still go straight to adding a card
  • Partners doing a device-based Vault connection without a webhook receiver can now poll for its status directly — pending, linked, or expired — instead of only waiting on a callback
Fixed
  • Fixed Vault's master-password error showing a raw technical failure message — a wrong password (or, rarely, a damaged saved vault) now gets a plain explanation and, if you're sure the password is right, a pointer to support
  • Fixed Face ID/Touch ID failures in Vault showing a generic "Face ID didn't complete" with no explanation — you're now told exactly which device and browser your Face ID is set up on when it isn't available in the one you're using, instead of being sent into a retry that can never succeed
  • Fixed checkout for organizations that fund purchases from a shared company balance — new end users were being routed through a card-minting path meant for money already allocated to a specific person, which failed for them entirely; checkout now correctly draws from the organization's shared balance, with safeguards so a card is never left open and unaccounted for if a purchase fails partway through
  • Fixed dialogs (like the card-creation agreement step) getting cut off on phones with no way to scroll down to the confirm button — dialogs now fit the screen and scroll their own contents
  • Fixed identity-verification status incorrectly showing "rejected, cards are not available in your region" for people who had already been approved through a backup card issuer after their region was rejected by our primary one
  • Fixed organizations' card-issuing API looping forever on a verification-required error for end users who'd already been approved through a backup card issuer — card creation now automatically routes to the issuer that actually covers them, and clearly refuses card types the backup issuer can't support instead of silently failing
  • Fixed company-balance deposits (Apple Pay / Google Pay funding for organizations paying from a shared balance) being blocked for any admin who hadn't completed their own personal identity verification, even when the organization itself didn't need it — deposits now go by the organization's actual funding setup, with clearer messaging when one can't go through
  • Fixed retail checkout carts that could get stuck holding an item whose price was never confirmed — an item that can't be priced is now refused when added, and checkout won't proceed while one is still sitting in the cart
Added
  • Every response from the buy API (and buy chat) now says exactly what happened with an order — its order id, how it was paid (balance, a saved card, Vault, or an organization's balance), and whether anything has actually been charged yet, not just whether the request succeeded. If an item couldn't be found or added to the cart, it's now named and kept listed until it's actually resolved instead of silently dropped. You can also fetch the full state of a buy conversation — its last checkout, its orders, and anything still unmatched — at any time, and organizations now get webhooks when an order is placed or fails
  • Vault checkout approvals can now carry the exact charge amount alongside the display total, and for card payments that amount is checked against the payment processor twice — once when the approval is created and again right before your device confirms it. If the amount doesn't match what you approved, the charge is refused outright instead of going through for more or less than you agreed to
Fixed
  • Fixed organization-connected accounts sometimes showing as disconnected an hour after connecting even though nothing had actually been revoked — a connection now stays recognized as long as it can still refresh itself, and is treated as gone immediately once an account is suspended
  • Fixed typing vault.agentcard.sh directly landing on a dead-end placeholder page instead of your vault — visiting the vault's address now takes you straight in, the same as clicking a link would
  • Fixed sign-in codes sometimes never arriving for international phone numbers, because a delayed text was reported as sent even though it arrived too late to use. International sign-ins now also get the code by email at the same time, so whichever arrives first works, and the messaging everywhere now mentions both
Added
  • A partner can now send you straight to the card-entry screen to join Agentcard Vault, skipping the verification-code and account-setup step entirely. Saving your card creates your account on the spot, secured with a passkey (Face ID or Touch ID) instead of a password, and if you already have a vault you can sign back in with your passkey from a partner's link too
  • If you're connected to Agentcard through a company and your region is rejected by our primary card issuer, you're now automatically moved to a card issuer that serves you instead of waiting on manual review
  • Agentcard now runs a standing demo store where you can walk through a full saved-card Vault purchase end to end with test-mode payments, handy for trying it out before connecting it to a real storefront
  • You can now start and check on a return for an order placed at certain managed retailers, right from Agentcard — pick the items and a reason, and once the retailer receives them the refund lands back on the original card automatically. Starting a return that's already in progress, or checking one that doesn't exist, now gives a clear answer instead of a generic error
Improved
  • Every Vault screen — the unlock screen, the card form, and the payment-approval screen — now consistently calls it your master password, replacing wording that used to say just "password" in some places and implied there could be more than one
  • Shortened the cooldown between purchase approvals from 30 seconds to 5, so a burst of quick back-to-back approvals doesn't get wrongly refused as a duplicate
Fixed
  • Fixed sign-in and verification codes failing to reach international phone numbers; codes now deliver internationally, with new abuse limits on how many can be sent to one number
  • Fixed wallet funding being blocked for phone numbers from countries that already have a card issuer able to serve them (for example, Israel) — the check now follows real issuer coverage instead of a fixed list
  • Fixed an approved purchase that failed to go through after approval leaving no explanation for what happened; the next attempt now tells you what went wrong last time before asking you to approve again
  • Fixed failed orders paid from Vault at certain retailers leaving your spending budget looking used up even though nothing was actually charged — a failed order's amount is now credited back automatically, including for orders that fail without a normal refund
  • Fixed some Vault orders being declined because a last-minute shipping increase pushed the final price just past what the merchant's payment system would allow, and fixed declined purchases showing a generic "insufficient funds" message instead of the merchant's actual reason
Added
  • Behind the scenes, checkout can now pay directly from a card you've already saved in Agentcard Vault instead of minting a new one-time card. You approve the purchase with one tap, payment resumes immediately while the quote is still fresh, and a decline or hiccup lets the checkout retry cleanly rather than getting stuck. Rolling out merchant by merchant, dark behind a flag
  • Companies can now pin a specific Vault-saved card to a checkout authorization; the approval page preselects that card (while still letting you pick a different saved one), and the confirmation names the card that actually paid instead of guessing
Improved
  • Buy chat conversations can now stream live, word-by-word replies plus a running note of what the agent is doing (searching, adding to cart, checking out), instead of long silent stretches followed by everything at once. Progress updates never include the addresses, phone numbers, or emails involved
  • Buying from certain large single-store retail merchants is noticeably faster — the agent skips a store-selection step those merchants never needed in the first place
Fixed
  • Fixed several rough edges on the Vault payment-approval page found during its first live purchases: it could get stuck on a loading screen forever after a network hiccup instead of offering a retry; a decrypt failure showed a cryptic browser error instead of saying the password was wrong; a failed Face ID attempt didn't say why; the success screen said a card had 'paid' before the agent had actually placed the order; and a card saved on another device now points you to pick a different saved card instead of a dead-end recovery flow; an old password-recovery step could still dead-end a real payment instead of just steering to another saved card; and the 'use Face ID next time' offer no longer appears inside in-app browsers (like iMessage or Instagram) where it could never complete, showing a note to open the page in Safari instead
  • Fixed a Vault-paid checkout needing a fresh approval every time a store's price ticked down by even a cent between approval and payment, and fixed an item going out of stock mid-checkout leaving the order stuck retrying instead of telling you what happened
  • Fixed some organization-connected purchases minting a personal card and billing a personal wallet instead of drawing from the organization's own card pool and credits
  • Fixed a delivery merchant's purchase approval sometimes leaving out a tax line that showed up on the final charge, so what you approved could be a little less than what you were actually charged
  • Fixed some Vault-paid orders at certain retailers being wrongly refused before they could even be placed, because the approved amount didn't leave enough headroom over the item cost; the amount you're actually charged also now settles correctly instead of counting the unused headroom as spent
Improved
  • A mismatched sandbox/production connection error now says so directly — naming which mode the credential is for and that sandbox and production users are separate — instead of reading like a generic outage
Fixed
  • Fixed a Vault sign-in that was already open on a device claiming a partner-sent link into the wrong account instead of the link's own account, when the device was still signed in from an earlier session — a card could land somewhere other than where the link intended
  • Fixed several cases where an already-verified or already-active account could get bounced back into onboarding, or the reverse — a wizard that never marked itself complete after real progress, and a suspended organization's leftover verification incorrectly marking a personal account as done
Added
  • Agentcard Vault now sets up with just a password. The 26-character Secret Key — and the three setup screens that generated it, backed it up, and confirmed it was saved — is gone for new accounts, so opening your vault on a second device no longer means carrying that string with you. Existing key-based accounts are unaffected
  • Passkey-only Vault accounts (Face ID or Touch ID) can now add a backup password from the saved-card screen, so losing the device no longer means losing access to every card saved on it
  • Partner-sent Vault links now work when delivered as a path (like vault.agentcard.sh/v/<token>), not just as a query link, and partners can now check a session's status — pending, code sent, consumed, or expired — to tell whether a user opened the link at all
Fixed
  • Fixed several Vault setup rough edges found while building the password-only flow: accounts with no password were still offered "use your password instead" on both the add-card and payment-approval screens, which could leave a payment stuck; typing a password could still pop up the Face ID/QR prompt over it; a card whose number didn't match a known brand failed to save with a generic error; an expiry like "23 / 47" was rejected with a generic "could not save the card" instead of being caught on the page with the month named; and saving a backup password could fail outright before finally returning an error
  • Fixed a partner-sent Vault link landing on a static page that couldn't read it, leaving the user stuck on "open the link your agent sent you" despite having a perfectly valid link. Also fixed adding a card dead-ending on any account that had saved cards before Vault's password-based setup existed — a password field now appears exactly when it's needed, and if your vault already has cards saved under more than one password, you're told how many and asked to confirm before continuing
  • Fixed a checkout that failed three times in a row going silent for the rest of the session, so a genuinely new checkout on the same page could never prompt again. A declined or timed-out approval now buys a brief quiet period instead of shutting off entirely, and only one approval request is ever outstanding at a time, so a checkout with several card fields no longer sends two notifications for the same purchase
  • Fixed test-mode identity verification collecting real documents and personal details before disclosing it was a test — the disclosure now appears before the link is sent, the page itself presents a simple choose-a-result screen, and the wallet's verify screen says test mode up front. Also fixed a completed test-mode verification showing as pending forever in status checks, the CLI, and the MCP tools
  • Fixed the hosted account-setup and permission-approval screens rendering dark-mode text on a white background, making the email field, buttons, and permission list effectively invisible. They now match the rest of the hosted pages
  • Fixed the Account Opening Privacy Notice on the consent screen and the privacy pages linking to our general privacy policy instead of the card issuer's program-specific version — you may be asked to re-accept the agreements once, since the version changed
Added
  • Agentcard Vault now sets up with a passkey: Face ID or Touch ID becomes the key that opens your saved card, with nothing to memorize and nothing to write down. Setting a password and saving a recovery kit is still there, one link away, for anyone who wants a backup they can keep — and it stays the default on devices without a passkey. Your passkey never leaves your device, so we still can't open your card
  • Vault now uses one password for your whole account instead of one per card, so changing it takes a moment rather than re-saving every card, and any card can be opened by whichever method you have on hand. The setup flow was rebuilt around it: how the vault works is explained before you're asked for anything, unlocking is now its own step ahead of the card form instead of two unrelated questions on one screen, and every message is in plain language instead of protocol jargon
  • Companies can now send a connected user straight into Vault to save a card, instead of asking them to find it and sign in themselves. One endpoint returns a link you deliver however you like; another texts it for you. Opening the link sends a one-time code to the contact already on the person's account, so the link on its own is never a session — and it's the first Vault sign-in that works for phone-only accounts. A separate read tells you whether a user already has a card on file, so you can skip enrollment entirely
  • New organization webhooks for the Vault checkout flow: one fires when a user saves a card through a link your organization sent, and three more tell you how each payment approval ended — approved, declined, or expired. Payloads carry identifiers and display fields only, never the card or the merchant's response
Improved
  • Approving a payment in Vault now sends the receipt back into the same conversation the approval request arrived in, instead of ending in silence
Fixed
  • Fixed Vault being able to pause a checkout on 21 of the 22 supported payment processors but only able to complete the payment on about one of them. Form-encoded checkouts failed before the card was ever written in, replayed requests lost the processor's own signature and client headers, and several processors' expiry-date field names were never recognized. Worst of all, a partly filled card could still be sent and then declined by the bank, which read like your own card was broken — that now stops with a clear error instead of a silent decline. Payments complete across all 22
  • Fixed 17 of the 22 supported processors accepting a payment approval and texting the cardholder, only for the approval page to refuse it as an unrecognized processor — the agent saw success while the person hit a dead end. The two checks that guard where a card may be sent now stay in sync automatically
  • Fixed two supported processors where the integration merchants actually use was never intercepted at all: on one we covered only an older card-entry flow rather than the modern hosted payment element most current integrations use, and on the other our address list pointed at hosts the vendor's own SDK never posts to. Both cases completed the checkout with no approval prompt and no error anywhere. The checkout SDK now also ships every recognized processor built in rather than five, so an integration whose processor list hasn't refreshed yet still pauses the right requests instead of quietly letting the shopper's own card be charged
  • Fixed a failed card authorization turning into a retry storm: a merchant's page retries a failed checkout, and a misconfigured integration could hammer our API roughly ten times a second for as long as the agent kept running. Errors that can't clear now stop retrying immediately and quietly, while temporary failures still retry as before
  • Fixed payment approval messages arriving as "Approve $ at ?" — the rule that strips links out of approval texts and emails was also deleting the merchant's name and eating the decimal point in the amount. Both come through correctly now
  • Fixed a phone number supplied by a company outranking the contact already on your account when sending a Vault sign-in code, which meant an organization could have received a code for someone whose contact it had never proved control of. A phone or email already on file now always wins; a supplied number is only ever used for an account with no contact at all
  • Fixed the CLI's card-agreement step reporting that agreements were accepted and cards could be created even when the account had actually been declined — every outcome now says what it really is, and only a verified account is told it can create cards
  • Fixed organizations never being paid out promotional order credits they had already spent, when a grant was used up entirely between two top-ups or its window closed before the balance caught up — those credits are now made whole either way
  • Fixed shoppers with no card on file being told they needed identity verification to place an order, when adding a card was the only thing missing — the buy agent even steered them into a passport check for it. It now asks for a card, and the setup link it hands over is a real one instead of coming back empty
Added
  • Behind the scenes, companies integrating Agentcard can now try the wallet in test mode from the setup flow — a sandbox wallet that looks and behaves like the real one, but never moves real money and can never place a real order. Rolling out dark, deploy by deploy, with no change to the live wallet
  • Agentcard Vault checkout now recognizes 22 payment processors, up from four. Because a store inherits whichever processor it runs on, each one covers every merchant using it — so an agent can pay with a card you saved in Vault across a far wider slice of the web. The list of processors your card may ever be sent to is enforced on our servers, and every entry was tested against hundreds of lookalike and attacker-registrable addresses before it shipped
Improved
  • Promotional order credits granted to your organization now show as a running balance on the company Balance page and get applied automatically as you spend, instead of being deposited into your account all at once
  • Privacy references across the site and the card agreements now link directly to the card issuer's current hosted privacy policy, so you're always reading the version that's actually in force
Fixed
  • Fixed the wallet identity-verification form using your ID's issuing country to guess your phone number's country instead of asking — a US resident with a foreign ID, for example, could have a valid phone number rejected for missing a country code. The country is now only used for phone formatting once you've actually confirmed it, either by picking it yourself or because it's already on file
  • Fixed users paying with their own connected card being wrongly told their account still needs identity verification before they could place an order — that check no longer applies when you're paying with your own card. Also fixed organization members being unable to use their own connected card at checkout at all
  • Fixed the identity-verification form in the embedded wallet asking non-US applicants for a US Social Security number, state, and ZIP code — it now asks for the right national ID and address fields for your country, so it no longer looks like Agentcard is US-only
  • Fixed the wallet occasionally failing to confirm a card was successfully attached when two loading screens raced each other right after setup finished — it now reliably shows the successful attachment no matter which screen finishes first
  • Fixed some early accounts showing as identity-verified under an older verification method that current funding checks no longer honor, leaving them unable to add funds with no clear next step — those accounts are now correctly routed to complete verification, and the "Add funds" identity alert links straight to the verification page instead of just telling you to find it
  • Fixed a confusing generic error when funding your wallet from a residency our card issuer can't support — you'll now see the real reason instead of a message that reads like a fixable verification problem
  • Fixed the CLI dead-ending verified cardholders who still had a card agreement to accept: creating a card now presents the outstanding agreements right there and carries on, and running the identity command walks you through them instead of replying that you're already verified
Added
  • Agentcard Vault — the hosted page that stores a payment card so an agent can check out without ever touching the card number — now signs in with an emailed one-time code and remembers your device, and your encrypted card can follow you across devices instead of staying locked to one browser. The card is encrypted with your passphrase plus a separate secret key that only you hold; neither one is ever sent to us, so a stolen database alone still can't unlock your card
  • Agents can now hand a payment to the cardholder for approval on a hosted Agentcard page instead of relaying it themselves: the agent parks the request and gets back an approval link, the cardholder approves it, and the agent only ever receives the merchant's response — the card number never passes through the agent. Each approval is single-use, expires after 15 minutes, and can only ever be sent to a recognized payment processor
  • A device that's already verified with a passkey can now reopen an expired wallet link with Face ID or Touch ID instead of waiting on a new text message code
Fixed
  • Fixed a removed-and-re-added passkey not actually working again, and fixed brief connectivity hiccups hiding the "unlock with passkey" option on a wallet link instead of letting you retry
  • Fixed organization purchases made through the buy flow failing outright with a session error, and fixed some of those purchases resolving to test mode instead of the organization's intended live card
Added
  • Companies using attested onboarding can now check the status of an in-progress onboarding attempt through a new API endpoint — see whether it's pending, converted, or expired while you wait for the connection.created webhook
  • KYC API calls for document upload, applicant information, and imported verifications now accept an optional field for the end user's real IP address, so backend integrations and agent relays can make sure the right address gets screened
Improved
  • Paying with a connected card from the wallet no longer requires a phone number on file — your first payment now asks you to accept the card terms right there, inline, instead
  • The first time an agent ships a Purchase API order to a real address, that address is now saved as your default — future purchases open with it already filled in instead of asking again, unless you've set a different default yourself
Fixed
  • Fixed live one-time codes for phone verification — used when funding your wallet, verifying a wallet phone number, or during onboarding — silently failing to arrive instead of going out over SMS. Every live phone code now goes out over the same working delivery path
  • Fixed identity verifications submitted through a backend relay or agent integration being wrongly rejected as being in the wrong region, because the relay's own server address was screened instead of the real applicant's; also fixed the verification form asking non-US applicants for a "SSN" instead of the correct national ID or tax number for their document's country
  • Fixed duplicate-identity rejections not being recognized consistently across every verification path — the dashboard's account-linking prompt and the automatic self-heal that resolves a duplicate onto your already-approved account now behave the same way no matter which check flagged it
  • Fixed sign-in and connect codes sometimes arriving in two separate emails for the same code — every Magic Auth code email is now sent by Agentcard itself, worded for what you're actually doing, whether that's signing in, verifying a link, or connecting an account
  • Fixed Mastercard card art not appearing in the wallet — a security policy was silently blocking the images, so every Mastercard fell back to a plain placeholder even though the artwork loaded fine. Visa was never affected
  • Fixed the merchant.connected webhook event occasionally showing an internal supplier identifier instead of the merchant's public name
Added
  • Behind the scenes, rebuilt the onboarding flow into a single guided path: connect your own card, complete a real identity check in test mode, and make an actual purchase through the Purchase API — all in one live chat, with an optional developer view that shows every API request and webhook as it fires. Rolling out dark behind a flag while the current setup wizard stays in place
  • The CLI can now stream your company's webhook events straight to your terminal and forward them to a local server with a new listen command — no tunnel needed for local development
Improved
  • Organizations can now cancel a member's still-pending card-attach request through the API using their own platform credentials, matching the cancel option members already had for their own request; the full member-managed card API is now documented in the API reference
Fixed
  • Fixed identity verifications and card-attach ceremonies that could stall with no explanation — they now settle automatically with a clear status instead of sitting unresolved for up to 48 hours
  • Fixed the standard sandbox test card number being refused when added through the full card-attach flow, even though it's documented to activate instantly — it now activates instantly as documented
  • Fixed a bug in the card-attach flow where a single connection stall could get reported more than once, triggered by an unrelated screen re-render — this could burn through the retry budget and wrongly mark a still-in-progress card add as failed
Added
  • Behind the scenes, added an automated path for completing company-wallet fund recoveries that need collateral moved on our card issuer's side, instead of requiring a manual transfer every time. Shipping dark behind a flag while we verify it on real transfers
  • Added a new webhook event, user_wallet.funding_detected, that fires the moment a user's deposit is spotted and on its way in — before it's fully credited — so you can show a pending state instead of waiting for the funds to fully land. It fires for every organization holding a live cardholder for that user
Fixed
  • Fixed the wallet dashboard advertising a maximum withdrawal amount that didn't account for a withdrawal you already had pending, so retrying — even at the suggested max — failed with a confusing "more than your available balance" error. The balance and withdrawal dialog now both reflect what's already reserved
Added
  • Behind the scenes, laid the groundwork for a new onboarding path for partners who already know their user's phone number: a wallet link opens straight into a live wallet, and identity is only verified at the moment of the first real money action — adding a card — never before. Rolling out dark, company by company
  • Added a way for phone-only cardholders to receive their card-issuer verification code automatically through a dedicated Agentcard inbox when they have no email on file, instead of getting stuck with no way to add a card. Available per company on request
  • External agents connecting to the wallet through get_instructions now receive a full guide to the account tools — cards, funding, bringing your own card, identity verification, and support chat — not just shopping instructions
Improved
  • One card tool: create_card now starts with your own card — it absorbed the separate add_card tool. First-time users are guided to add their own Visa or Mastercard right inside card creation (no identity verification, no prefunding); a wallet-funded Agentcard, which requires identity verification, is offered only when that card can't be added. The add_card and attach_card tool names are removed — agents calling them are told to call create_card instead
  • Retired the guided "companies wizard" CLI command for implementing Agentcard — running it now points you to the setup docs instead of walking through the guided flow
  • Reusing an already-used sign-in refresh token now signs out every session tied to that connection, not just the one token, closing off a way a stolen token could otherwise be replayed to stay logged in
  • Updated the wording on the checkboxes you accept when creating a card and added a dedicated privacy-notice page linked from account setup — you may be asked to re-accept the agreement next time you create a card
Fixed
  • Fixed the standard sandbox test card number being rejected when added to a wallet in test mode instead of activating instantly as documented; other add-a-card failures now show the actual reason instead of implying the card details you typed were wrong
  • Fixed the org console sometimes reporting that a webhook destination couldn't be deleted when it actually had been — the list now always reflects what really happened
  • Fixed company-wallet fund recoveries that could sit unprocessed for days if the internal alert asking us to move the money failed to go out — these are now automatically re-flagged until the funds are back
Added
  • A new Integration progress checklist is now shown in the org console — sandbox call, test card, webhooks, going live — tracking where you are as you integrate, and collapsing to a simple "you're live" once you're in production
  • A React Native wallet package for embedding card views directly in a mobile app is now publicly available, no longer marked early access
Fixed
  • Fixed the dashboard's identity-verification page defaulting a non-US ID to US formatting and then surfacing a technical, unactionable error asking you to resubmit — it now resubmits automatically using the document's real type and country
  • Fixed org-created cardholder accounts sometimes never being asked for an email when adding a card — an internal placeholder login was being mistaken for a real one, which could have sent the card network's verification code nowhere
  • Fixed the card terms and legal footer on agentcard.sh still linking to our own retired copies of the E-Sign Consent and Prohibited Activities documents — they now link to the card issuer's current hosted versions, matching the rest of the site
Added
  • Adding your own card no longer requires having an email on file — if you signed up with only a phone number, you're now asked for an email right in the add-a-card flow (your bank needs somewhere to deliver its verification code), instead of the flow failing outright with no way forward
Improved
  • When the shopping and wallet assistant sends a payment approval over the newer, independent messaging channel, it can now show a native, tappable card right in the conversation too, not just a link — matching what the primary channel already does
  • The card-issuer agreements checklist shown when you create your first card now requires you to actually scroll through each linked document before its checkbox unlocks, instead of letting you accept it unread
Fixed
  • Fixed live organizations with no active subscription hitting dead ends on their way to checkout — a sidebar reminder card could disappear before a subscription was actually added, and some orgs that already held production credentials had no way to reach checkout at all. Both now lead straight to adding a subscription
  • Fixed identity verifications imported from a partner's own check getting stuck in review indefinitely when the imported record was missing a home address — these now ask for the missing address instead of stalling silently, and new imports include the address already on file so this can't happen going forward
  • Fixed an abandoned wallet-funding checkout sitting as 'pending' forever with no way to know it wouldn't complete — it now reads as expired once the window has passed, and starting a new one always works
  • Fixed identity-verification status checks still showing 'rejected' for an account after it had been merged into another, and fixed some purchases, withdrawals, and card-adding actions staying pinned to the old account instead of following it to the merged one
Added
  • If you already completed identity verification with one of our verification partners, you can now import that verification into Agentcard using a one-time share token from the partner, instead of verifying again from scratch.
Improved
  • Companies importing a user's existing identity verification can now find our verification-partner client ID and pairing token directly in their org console credentials page, instead of requesting them from us.
  • Behind the scenes, we added a new messaging channel for iMessage conversations, giving the shopping and wallet assistant one more independent, redundant path to deliver messages if another channel is down.
  • Behind the scenes, we started building a dedicated, standalone Agentcard app for iMessage, so payments and approvals can eventually run natively in the conversation.
  • Some legal documents referenced in the card terms — the e-sign consent and the list of prohibited card uses — now link directly to our card-issuing partner's hosted copies instead of pages on our own site; you may be asked to re-accept the agreement the next time you create a card.
Fixed
  • Fixed multi-use cards being canceled by the card network right after their first purchase, which made them unusable for the repeat spending they were meant for.
  • Fixed a case where a card canceled by the network without notifying us could keep showing a spendable balance — those cards are now detected and closed out automatically, with any remaining funds returned.
Added
  • If the device that verifies one of your added cards is no longer available, you can now re-verify the card on a new device instead of removing it and adding it all over again — no need to re-enter the card number.
Improved
  • The payment-approval screen has been redesigned to match the wallet's card-first look, with the merchant and amount shown up front. If the device that normally verifies your card isn't the one you're on, you can now set it up right from the approval screen instead of getting stuck retrying.
  • When shopping through Agentcard, the store you're buying from now shows its real name everywhere — merchant lists, carts, and order confirmations — instead of a generic wrapper name.
Fixed
  • Fixed several dead ends in the wallet — the card detail screen, payment receipts, and a few error and setup screens each now have a clear way back or a way to start over instead of leaving you stuck with no next step.
Added
  • Identity verification can now run fully hosted from start to finish — when a check still needs details like your name, address, phone, or ID number, the hosted verification page collects them itself and then runs the document and face scan, so an integration no longer has to build its own form for those fields. The whole check happens on our page and returns to your flow when it's done
Fixed
  • Fixed non-US national ID numbers being rejected during hosted identity verification — a UK (or other non-US) ID was being checked against the US Social Security number format and dead-ending. It's now validated against the applicant's own country of residence
  • Fixed adding your own card getting stuck in an endless retry loop when a bank's verification step failed on every attempt — after repeated failures the flow now settles with a clear outcome instead of looping forever
Added
  • An agent can now text you a wallet link that opens straight to the payment-approval sheet for a specific charge — with the merchant and amount already filled in — instead of a link that just shows your cards. Approve it and you're done
Improved
  • When a shopping assistant over iMessage needs you to add a card or approve a payment, it can now show a native, tappable card right in the conversation instead of only a link
  • Agentcard's forward-deployed engineer now sets up on a single shared Slack app instead of installing a dedicated one for every new partner engagement, and message delivery between you and the engineer is now guaranteed end-to-end — a lost connection or restart on either side can no longer drop a report, question, or approval
  • The text-based shopping and wallet assistant now runs across two independent phone lines for reliability, and proactive nudges (funding reminders, KYC follow-ups, and founder takeover replies) now reach you correctly no matter which line your conversation is on
Fixed
  • Fixed tapping Confirm on the wallet pay sheet failing with an error when the card it listed couldn't actually be charged on that connection — the sheet now offers only cards it can charge, and sends you to add one when you have none. A card you added on your own personal dashboard can now also be used to pay on a company's surface, instead of being shown but never chargeable
  • Fixed new company onboarding sometimes sending two duplicate Slack channel-invite emails when a company was created and the forward-deployed-engineer setup was run in quick succession
Added
  • You can now verify your identity and get an Agentcard without ever leaving the wallet. A new 'Add to Wallet' chooser lets you either add your own bank card or apply for an Agentcard, and the whole identity check — the details form, document capture, and face scan — runs right inside the sheet, then drops you back on your brand-new card
  • Agents can now hand you a single hosted wallet link — for viewing your cards, adding a card, or verifying your identity — through a new get_wallet_link tool, instead of a different single-purpose page for each step
  • Agentcard's forward-deployed engineer now proactively reaches out right after you connect, to help get your Agentcard wallet set up — sending that first message directly instead of waiting on a human approval step
Improved
  • Putting your own card in the wallet is now called 'adding a card' everywhere you read it — across the MCP tools (add_card, list_added_cards, remove_added_card), the CLI (agent-cards add), and a new /api/v2/cards/add endpoint. The previous 'attach' names keep working as aliases, so nothing in your integration breaks
  • The hosted identity-verification link now comes back at more points in the flow — including while documents or extra information are still needed — so a REST-only integration can hand users a hosted verification page from the very start instead of pushing documents through the API first
  • Companies now have an ask-AI documentation assistant built right into the organization console
  • Behind the scenes, we kept hardening the newer card-issuing connector that's still rolling out dark — including catching and fixing a vendor authentication mismatch on an early production canary before any card was actually issued, with the customer's money kept safe throughout
  • Behind the scenes, we closed the last public network path to our production database — all traffic now reaches it over a private link, part of our ongoing SOC2 and PCI work. Nothing changes about how you use Agentcard
Fixed
  • Fixed the Purchase API (POST /buy) rejecting a user's connection access token even though it's the documented credential for that endpoint — those tokens are now accepted there
  • Fixed the org console's Credentials page ignoring the Live/Test toggle, so switching to Live mode could still show your sandbox secret — each mode now shows only its own client ID and secret
  • Fixed a forward-deployed-engineer conversation getting split across multiple Slack threads (and duplicated across daemon restarts) — the whole conversation with Agentcard's engineer, including reports, questions, and approvals, now threads under one root and survives a restart
Improved
  • Agentcard's forward-deployed engineer now replies shorter and more human, always back in the same Slack thread instead of sometimes posting top-level
  • Approvals for the forward-deployed engineer now go to a private DM with the approver instead of a shared partner channel, posting into the partner's channel only once approved — with a matching "Authorize" action on your side for any change proposal it sends you
Fixed
  • Fixed two bugs found during the very first live cross-organization run of the forward-deployed engineer: a closed engagement sharing a Slack channel with an active one could wipe out the active one's channel mapping, silently dropping every message so the agent never responded; and the engineer's own bot was never actually invited into its engagement channel, so it couldn't see or post anything
  • Fixed CLI and MCP sessions getting rejected at sign-in during a sign-in-provider outage — auth now falls back to checking with the backend directly when the fast local check can't verify a session, instead of failing every session at once
  • Fixed a checkout-confirmation loop where declining once made the assistant think the whole conversation had expired — it would restart from scratch, lose the cart, and re-ask the same question, so a customer's "yes" could never actually land
Improved
  • Both sides of a forward-deployed-engineer conversation now post a short one-line summary in the channel with the full detail kept in a thread, so busy channels stay scannable
Fixed
  • Fixed sandbox card creation over the REST API not recognizing a funded sandbox wallet, falling back to demanding a saved payment method even with test balance available — and fixed sandbox pending holds being counted twice against your test wallet's available balance
  • Fixed re-tapping "add a card" starting a brand-new attachment instead of resuming the one already in progress — repeated taps could pile up several pending attachments, so the one you actually finished wasn't necessarily the one being watched, leaving it looking stuck at "connecting to your bank" forever
  • Fixed two early bugs in the forward-deployed engineer rollout: a background CLI daemon that silently ran in the foreground and hung the shell instead of detaching, and the partner-side Slack bot never actually being invited into the engagement channel it needed to post in
Added
  • A forward-deployed engineer for integration partners — page a real Agentcard engineer over Slack straight from your coding agent, using new CLI commands and MCP tools to ask a question, report an issue, or check status, with a human reviewing everything before it's sent. Rolling out to select partners
  • Organizations can now pull a running feed of their accrued earnings through a new API, with each row tied back to the transaction that earned it
  • Accrued organization earnings can now actually be paid out — once a month, they land as real funds at your org's pool automatically instead of just accruing on a dashboard
  • Companies can now self-register the web origins allowed to embed the Wallet SDK — up to 10 https origins through GET/PUT /api/v2/embed_origins — instead of asking us to add each one by hand. The wallet's framing rules pick up your registered origins automatically
Improved
  • Behind the scenes, we started rolling out a rebuilt card-issuing layer — a cleaner internal routing system that can steer a new signup to a different card issuer if the first one can't serve their region, plus support for an additional issuer connector running fully dark. Ships gradually behind flags; nothing changes about how you create or use cards today
Added
  • A new Wallet SDK lets partners drop a single script tag into their own site to open the wallet — pick a card, approve the bank window, and see a receipt — without building the flow themselves. Currently rolling out with design partners
  • The Wallet SDK now has a native track too — an iOS package and a React Native component — so partners can embed the same pick-a-card-and-pay experience directly inside their own native apps, not just on the web. Bank approvals open in your device's browser, and an in-progress payment resumes correctly even if the app is closed or the screen is torn down mid-approval
Fixed
  • Fixed the bank-verification window during a purchase approval sometimes getting silently blocked by mobile Safari's popup blocker or an in-app browser (e.g. iMessage, ChatGPT), stalling a real approval with no way forward — the flow now pre-opens the window inside your tap so it isn't blocked, and if it still is, offers a tappable link that finishes the same approval
  • Fixed a dead end where a company's connected session could attach a card but never actually spend from it — card creation now checks for an active attachment first — and fixed the flow's agent-facing tool getting stuck asking for information it can't collect from a company session, looping forever instead of pointing the agent to the right next step
Added
  • The 'Buy Me Anything' embedded wallet can now actually complete a payment inside the chat — pick one of your attached cards on a redesigned pay sheet, confirm, and see an in-chat receipt when it's done, using your real cards and a real charge rather than just viewing them. Shipped alongside a run of same-night polish: the sheet now blends into the chat's own frame instead of showing a sheet-inside-a-sheet, pinch-to-zoom is disabled, the sheet holds a fixed height as screens change, duplicate card rows are gone, and card names no longer show the last four digits twice
  • Shopping conversations can now hold a live cart for each merchant at once — pick items across two stores in the same chat and confirm each independently, with per-merchant results instead of an all-or-nothing checkout
  • Add a default payment method to your wallet — balance or an attached card — so every card an agent creates and every purchase it makes follows your choice automatically, with no need to specify it each time. Manage it from the dashboard, CLI, or MCP tools
  • Save a default delivery address on your wallet once, and shopping agents will use it automatically instead of asking you to dictate it every time. Set it from the dashboard, CLI, or MCP tools
  • Companies can now pull unused spending power back out of a cardholder's wallet into the shared company pool — a new recover-funds action, with matching webhooks, for money you've allocated to someone but they never spent
  • Companies can now see exactly which step a cardholder's identity verification is stuck on — waiting on the applicant vs. under active review — on the Users page and in the cardholder drawer, instead of a flat 'pending' status. The same detail now comes back in the v1 API's kyc_required error, so your integration can tell a user precisely what's left without a second lookup
  • The card-attach flow now recognizes when you already have a matching card attached under a different connection and offers to reuse it instead of asking you to add it again — and if you have more than one card, you can choose which one instead of it silently picking the newest
Improved
  • The Purchase API's response envelope now returns a stable public merchant id and display name instead of an internal identifier, and these purchases fund directly from your minted card through the card network's own tokenization step rather than an interim funding leg
Fixed
  • Fixed a rare case where a live purchase made with an attached (not issued) card was charged against a test payment method instead of the real one, causing a false decline — and fixed links in shopping-agent replies sometimes breaking when a bare URL was immediately followed by a new line
  • Fixed the bank-verification and purchase-approval steps in the card-attach flow sometimes hanging on 'Connecting…' forever with no way out — they now time out automatically and offer a retry or a different card, and the recovery message stays inside the chat instead of asking you to open Safari
  • Fixed a government ID number typed during identity verification over iMessage being stored in plain text in our internal logs — it's now automatically redacted, the same way one-time codes already are
Added
  • Sandbox test accounts can now read and fund a personal wallet — not just mint test cards — so an integration's full read-wallet-then-fund-then-spend flow can be rehearsed end to end without touching real money or a live identity check
Fixed
  • Fixed people funding from certain countries getting a message that sounded like an identity-verification failure when the real issue was that their country isn't supported yet — one plain message ('Funding isn't available in your country yet. Contact support.') now shows everywhere this can come up, including a gap in the newer wallet flow that told already-verified people to redo verification. A few previously-blocked countries were also enabled, and anyone declined earlier for country reasons can now be retried once support confirms it's cleared
Added
  • Webhook subscribers now get a reward.reversed event when a refund or return claws back tokens you'd already earned — it carries the same transaction id as the original reward.earned event so you can pair them up, and it's delivered reliably even if a notification attempt fails along the way
Improved
  • Behind the scenes, we retired the last of an older card-issuing path that had been dark in production for months — every card has been issued through the current path for a while now, and removing the unused code changes nothing about how you create or use cards today
Fixed
  • Fixed organization API tokens minted via client credentials being rejected on core card, funding, and withdrawal REST endpoints — those endpoints now accept the same tokens your integration already uses elsewhere
  • Fixed sandbox withdrawal requests being processed twice when safely retried with the same idempotency key — a retry now returns the original result instead of creating a duplicate withdrawal and double-counting against your test balance
  • Fixed some CLI sessions started via device login being rejected when connecting to the MCP server, even though the session was still valid — expired sessions now refresh automatically, and older CLI versions that can't yet do that get a clear 'update the CLI or sign in again' message instead of a bare invalid-token error
  • Fixed identity verification retry-looping forever with a 'try again' message for some users whose verification was rejected outright — you now get a clear, final decision instead
  • Fixed identity checks silently stalling in review when a home address was too long or an old rejected document was left on file — these now resolve automatically instead of sitting stuck indefinitely
  • Fixed the support chat assistant telling people already inside a support conversation to go start a new one — it now recognizes it's replying in an existing chat and can bring in a human there instead of sending you in circles
  • Fixed identity-verification rejection messages sometimes showing internal fraud-screening codes to the rejected user — these are now filtered out everywhere, leaving only genuinely actionable reasons (like a mismatched document) visible
Added
  • Companies funding cards for their cardholders can now create reusable (multi-use) cards, not just single-use ones — and add more balance to a card they've already funded, topping it up again whenever they need to. Available through the API and MCP tools, which now let you set the card's type and expiry
Improved
  • Adding funds now shows the funding provider's privacy notice upfront and remembers once you've accepted it — so your first click goes through instead of bouncing off an error, and future top-ups don't ask again
Fixed
  • Fixed dashboard identity verification wrongly denying genuine US applicants as out-of-region — the check was reading our servers' datacenter location instead of the applicant's own, so valid US users were being rejected. Verification now uses the applicant's real location; other sign-up surfaces were unaffected
  • Fixed wallet funding letting you start a top-up while your identity was still in manual review — those orders always expired unpaid, so some people could burn several dead attempts in a row. Funding now pauses with a clear message — nothing was charged, this clears within a few hours, try again once review completes — across the dashboard, CLI, and agent tools
Fixed
  • Fixed merging two accounts leaving the person who started the merge stranded — their in-flight session could die mid-merge with no explanation, and signing back in afterward with the merged-away email or phone quietly created a brand-new empty account instead of landing on the one they'd merged into, forcing a fresh identity check that could only fail. Signing in with a merged-away login now redirects you to the account you actually merged into
  • Fixed accounts created through a company's verification link or a teammate invite being dropped into the personal 'what do you want to do?' setup wizard — these accounts already know their starting point, so they now skip straight past it
  • Fixed public promo and giveaway codes showing as 'sold out' even with capacity left — a code claimed by someone whose identity check was ultimately rejected kept holding its slot forever. Slots held by claims that can never complete are now released back into the pool, and a previously rejected claimant can't immediately grab the freed slot back
Fixed
  • Fixed the dashboard, public view, and agent surfaces showing an endless 'final approval in progress' spinner for people whose card application had actually been declined (for example, an unsupported region) — a declined application now shows a clear, final outcome with the reason instead of spinning forever
  • Fixed merging a duplicate account silently doing nothing: entering the verified account's phone number found no owner, so the transfer quietly degraded and the dashboard claimed 'verification is transferring' forever — linking now resolves the owner through verified identity and completes the merge, or routes you back with honest next steps
Fixed
  • Fixed wallet funding getting stuck in an endless 'try again' loop for some people once they passed a funding threshold that requires full identity documents — the documents from your identity check are now shared with the funding provider automatically, and if funding genuinely can't proceed you get a clear 'more identity info needed' response instead of a repeating error
  • Fixed a setup dead end where the 'Finish setup' banner sent you to the verify page but the User Agreements checklist only appeared inside the create-card dialog — you can now accept the agreements right on the verify page, so verified users (including giveaway claimants) can finish setup and release any held credit
  • Fixed already-verified cardholders getting stuck on a 'you're verified' screen with no way to submit a document the identity check later asked for (for example, a passport or ID number needed for international funding) — the verification flow now reopens so you can upload exactly what's requested
Added
  • Promo codes now travel end to end from a campaign link — open the app with a code in the link and it's applied automatically on your first visit to the dashboard, surviving sign-up along the way
  • Giveaway and promo codes handed out before you've verified can now hold their credit until your identity check passes: you redeem the code right away, the wallet shows an 'awaiting verification' note, and the credit lands automatically once you're verified
  • Companies that embed the 'attach your own card' link in their own interface can now request a chrome-free version of the hosted page that shows just the checkout, so it drops cleanly into an existing flow
Improved
  • The dashboard home banner now speaks to exactly where you are in setup — a fresh 'verify your identity' prompt, a short 'one step left' nudge when only the agreements remain, or a quiet 'verifying…' while review is in flight — and once you're verified with no cards yet, a new banner invites you to create your first card
  • Company card notifications (card created or closed, transactions, low balance) now respect each admin's own mute settings instead of emailing every owner and admin unconditionally
  • Sandbox now matches production for attach-your-own-card flows — test-mode card creation honors a connected card and rejects the same unsupported combinations production does, org 'card.created' webhooks now fire for sandbox connection mints, and the documented sandbox-only testing helpers work again
  • Behind the scenes, card issuance has moved onto a single, newer issuance path with the card issuer, consolidating several older paths into one — with no change to how your cards work
Fixed
  • Fixed the cards API silently turning a request for a multi-use card funded by your own attached card into a single-use card that then failed on its second charge — it now returns a clear, documented error up front so the request can be corrected
  • Fixed the attach-your-own-card flow showing an endless 'Try again' when a setup problem on our side blocked enrollment — it now shows a clear 'this is on our side' message instead
Added
  • A texted 'wallet link' is quietly rolling out behind the scenes — off for everyone while it's still being finished: a customer's agent texts a link that opens a lightweight wallet, a native App Clip on iPhone or a hosted web page everywhere else, with no install and no separate account, where the customer can add their own card and see the cards their agent creates for them. The link carries no credentials, works only for a limited window, and stops working the moment the connection is revoked
  • Companies onboarded through a partner platform now land on a new free Lite plan — full production access with no subscription, capped at 200 live cardholders — with a clear upgrade path to the full Company plan shown right in billing
Improved
  • Embedded wallet funding is now much faster — top-ups that could take up to ~30 seconds while an identity review ran now typically finish in a couple of seconds
  • Funding a wallet now credits the exact amount you request — send the amount the customer should receive and that's what lands, with no need to gross it up
  • Agent clients can now discover the MCP server's available tools without credentials (rolling out), and expired or invalid credentials now come back with the standard 'refresh your token' signal instead of a generic challenge
  • Being added to a company on Agentcard — whether an admin sets up your account or a teammate invites you — now sends a designed invite email with a one-tap sign-in link and no password to remember
  • Attached-card lists now read the same everywhere, including the MCP tools — a clean issuer-and-nickname label instead of a raw network name — and stale, no-longer-usable attached-card entries stop piling up in your history
Fixed
  • Fixed fetching details for a card that's already closed returning a confusing, retryable error — closed cards (including one-time cards that auto-close after payment) now return a clear, final 'card closed' response so integrations stop retry-looping
  • Fixed the company wallet dashboard still showing 'attach your own card' as unavailable for company accounts even though it went generally available for every organization the week before — the tile now links straight to the setup guide
  • Fixed identity verification failing to start on the hosted flow because the cardholder's address wasn't being sent — the address is now included, and if it's genuinely missing you get a clear 'needs more info' response instead of a dead error
  • Fixed the MCP server rejecting valid tool requests sent without a JSON content-type header, which had been surfacing as spurious authentication failures for some agent clients
  • Fixed hosted onboarding hitting a company's cardholder cap with a generic error — it now shows a clear message naming the company, and the onboarding link works again once the plan is upgraded
Added
  • The newest wallet-funding rail is now the default for every user, not just the small group it had been rolling out to — completing a behind-the-scenes retirement of the older guest-checkout rail it was replacing. Funding no longer requires a US phone number or a one-time phone code at all; the only country restriction left is the standard restricted-countries list
  • Card issuance now requires accepting the card issuer's User Agreements at your first card creation — a short checklist whose contents depend on whether you're in the US or elsewhere, shown right after identity verification so it never blocks the identity check itself. It applies to everyone, including anyone who verified before this shipped, and agents and the CLI get a matching per-agreement confirmation step
  • Embedded funding on the newest wallet-funding rail can now boot the provider's native mobile SDK directly, so partner apps show a true native Apple Pay / Google Pay sheet instead of a webview — and it can also hand partners a fully pre-built, ready-to-embed wallet-button page instead of raw provider details to assemble themselves
Improved
  • Platform partners can now redeem a one-time connection code on its own, without also tracking which session it belongs to — one less piece of state they need to keep on their side
Fixed
  • Fixed a partner's embedded wallet view failing to load because its origin was missing from the embed's security allowlist
Fixed
  • Fixed some 'Buy Me Anything' iMessage shoppers being blocked at checkout with a verification-required error even though their identity was already verified — card issuance and the checkout preflight now read the same verified identity the rest of the product was already showing
Improved
  • The newest wallet-funding rail (still rolling out to a small group) now accepts international users — it verifies a passport or national ID instead of requiring a US-only identity check, and eligibility is now decided by the card issuer's actual restricted-country list instead of a blanket US-residents-only rule
Fixed
  • Fixed two brief windows where the MCP server returned errors on every request right after a deploy — a stale type-check exception and a runtime-incompatible library import both got fixed at the root cause
  • Fixed redeemed promo credits sometimes taking up to five minutes to become spendable — the balance now updates immediately once the on-chain deposit confirms instead of waiting on the backup sweep
Added
  • The 'Buy Me Anything' iMessage experience now has a full wallet screen embedded right in the conversation — view your cards, attach your own card (a bank one-time code plus a Visa or Mastercard passkey), and see card details, all without leaving the chat
  • Partners can now onboard companies into Agentcard themselves and receive that company's org credentials through a one-time, OAuth-style code exchange — similar to how Stripe Connect onboards a merchant — instead of the company signing up separately and creating API keys by hand
  • A new partner-facing API is quietly rolling out behind the scenes, fully dark for now: it lets an approved partner platform create, view, and close cards, and attach a card, using a signed-in user's own access token instead of needing org-level credentials for every action
  • Attaching your own card now carries over automatically to every other organization you connect to afterward — approve the bank verification once, and each newly connected org can mint cards against that same card, no re-entry and no repeat bank ceremony
  • Signing in from the CLI now starts with a device code you approve in any browser — on your phone or your laptop — instead of typing in an emailed code; every device or sandbox gets its own session this way. The old emailed-code flow is still there as a fallback
  • The foundation for a new sign-in system for MCP connections is rolling out behind the scenes, fully flag-gated for now — new connections would authenticate through a dedicated identity provider instead of Agentcard's own homegrown login, with no visible change to how you connect today
Improved
  • Every mention of a 'magic link' across the CLI, docs, and the Agentcard skill has been swept and corrected — sign-in has used a device code or an emailed code for a while now — and the skill's tool table was reconciled to match the live set of MCP tools exactly
  • MCP tool descriptions were rewritten to state what a tool does as fact instead of issuing instructions from inside the description itself, every tool now carries complete safety annotations (read-only, destructive, and so on), and the MCP server's packaging was hardened so it builds and installs cleanly as a standalone package outside this repo
  • The organization dashboard's tables and status indicators got a clarity pass: status colors that hold up in dark mode, spending filters that filter the full result set instead of just the page you're looking at, exact timestamps on hover, and success confirmations that no longer rely on color alone
Fixed
  • Closed a batch of internal security gaps found in an audit: a sandbox test connection could no longer be confused with a live account, a revoked or expired connection can no longer authorize wallet actions, only an organization's owners can remove another owner, and the one-time approval links for revealing card details or creating a card can now each be used exactly once. Also locked down outbound webhook delivery against a DNS-rebinding attack and fixed a spot where inbound email content could be used to spoof messages in our support Slack channel
  • Removed an extra 'choose an organization' screen that could interrupt sign-in for members of more than one organization — which organizations you can act on is governed by Agentcard, not by the sign-in screen
  • Fixed a set of rare timing issues where two sign-ins or session refreshes happening at the same moment on one machine could corrupt a session or let a command run under the wrong account's credentials
  • Fixed the buy tool's delivery-address step rejecting valid Canadian postal codes, which had been silently blocking Canadian users from checking out
  • Fixed MCP tool calls failing with a confusing generic error when your session had actually expired — you're now prompted to reconnect right away instead of every call quietly failing the same way
  • Fixed two sources of intermittent server errors: a brief database connectivity blip and rate-limited wallet-balance checks under load are now retried automatically instead of failing your request
  • Fixed creating a production API key failing with a generic error when the sandbox key it was cloned from had no redirect URLs set
Added
  • Attaching your own card is now on for every organization by default — no waitlist required — and works with Mastercard as well as Visa (Mastercard attaches from any country; Visa still needs a US-issued card). Verifying your card no longer asks for a phone number at all — your signed-in email is enough — and companies connecting through their own agent session can attach a card the same way their users do
  • A fourth wallet-funding rail is quietly rolling out behind the scenes to a small group of users, fully dark for everyone else — like last week's new rail, it skips the phone-verification step and checks your identity inside its own hosted checkout
  • Organizations get a new Logs screen (Settings → Developers) listing every API request and webhook delivery across the org, and a pending-interchange estimate now shows up on the earnings page before a purchase clears
  • The CLI can now redeem a promo code and manage your approvals inbox from the terminal, asks which card or your balance to charge when it's genuinely unclear which one you meant, and agents get matching read-only tools for listing withdrawal recipients and pending approvals
  • Attached cards can now be viewed, marked as default, and removed right from the web dashboard, matching what the CLI and agent tools could already do
Improved
  • Card issuer names shown in the CLI and agent tools are cleaner and easier to read, cards now say whether they're funded by your balance or your own attached card, and the attach command's card list matches the look of the regular cards list
  • Agents can now discover gated tools like cancel_plan or update_settings from the tool they extend, and a mistyped tool name suggests the closest real one instead of just failing
  • The shared Slack-channel banner on an organization's dashboard home page can no longer be dismissed away
Fixed
  • Fixed a background-jobs bug that silently skipped critical scheduled work — funding reconciliation, withdrawals, ledger reconciliation — for about seven hours with no visible error
  • Fixed a rare case where a brief internal hiccup could bump an already-verified funding user onto a rail that needed extra verification, making the same funding request succeed and then fail minute to minute
  • Fixed a funding webview embedded in some partner apps that could spin forever, and fixed signed-out visitors to the web dashboard landing on a dead end instead of the sign-in screen
  • Fixed several attach-status bugs where two apps sharing one wallet could see contradictory or stale statuses for the same attached card
  • Fixed a connected (attach-your-own-card) card's details page showing your identity-verification address as if it were the card's billing address
  • Fixed the card-spending-limit tool rejecting a validly named parameter, and fixed rejected tool calls reporting themselves as successful
Added
  • Attaching your own card now supports more than one: keep several of your own Visa cards enrolled at once, pick which one a new virtual card charges, and see which is the default. Agents can list the enrolled cards and remove one on request, and removing a card closes any virtual cards minted against it so nothing keeps charging
  • Attach your own card from the terminal: a new attach command starts the enrollment (a one-time code from your bank plus a passkey, about a minute), resumes one you left pending, and can list, add, replace, or remove enrolled cards, no identity verification and no funding step required
Improved
  • Agents connecting to the MCP server now see a tighter default tool list: nine niche tools (one-off compliance steps, rare analytics views, settings writes) moved out of the default list so agents find the right tool faster. Everything stays callable, and the full catalog is one command away in the CLI's api namespace
Added
  • Your cards from every app and company you're connected to can now appear together in one wallet view, each labeled with the app or company it came from. And when one app tries to act on a card another app created (revealing its details, closing or pausing it), nothing happens until you approve it from an emailed link; the agent simply retries once you have
Improved
  • The CLI's help now fits on one screen, with the full command board available behind a flag instead of scrolling past everything on every run
  • The instruction blocks that wire coding agents to the Agentcard tool catalog now refresh themselves whenever the CLI updates, so agents always steer by the current tools instead of a snapshot from install day
Fixed
  • Fixed the CLI's self-update getting permanently stuck on some machines: an over-eager version cache could pin the CLI to an old release forever; it now double-checks npm and unfreezes itself
Added
  • The two Agentcard CLIs are now one: agent-cards covers both personal cards and the companies product (a companies namespace inside the same tool), with a guided first run when you're new; the old agent-cards-admin package keeps working as a shim that forwards to agent-cards companies
  • A new api namespace in the CLI projects the entire MCP tool catalog through the shell, so coding agents and scripts can search, describe, and call every Agentcard tool without an MCP connection; a companion agents add command wires Claude Code, Codex, or Gemini to it by installing a steering block into their instruction files
  • Wallet now means your cards and balance means your cash, everywhere: the CLI's wallet command shows the cards you hold plus your balance, balance shows the cash that funds new cards (with new top-level fund and withdraw commands to move it), and the agent-facing tools were renamed to match, with the old names still accepted during a transition window
  • Signing in now spots look-alike accounts that belong to the same person and offers to link them, laying the groundwork for one shared wallet across everything you connect
Improved
  • The Chrome extension has been retired: everything it did lives in the CLI and the MCP server now, and its page redirects to the personal product
Fixed
  • Fixed the CLI's self-update refusing to run on machines with more than one npm installation; it now picks the right one and repairs itself
  • Signed-out runs of any command now open the sign-in flow inline instead of erroring with instructions to run a different command first, and JSON output stays valid JSON even when signed out
Added
  • A new wallet-funding rail is quietly rolling out to a small group of users behind the scenes — unlike the existing options, it doesn't require the one-time phone verification code, and it can recognize a user's already-verified identity to skip re-verifying inside the funding page too; a few extra questions are collected conversationally through the agent only when the rail actually needs them
  • The foundation for attaching your own card keeps building out behind the scenes — the pages that walk through connecting a card and approving a purchase now run against a live identity-verification and approval process instead of a placeholder, and the underlying tool an agent would call to attach a card is wired up, still fully dark with no visible change to how you create or use cards today
  • The still-dark tokenback rewards program (see yesterday's entry) grew a dedicated rewards card that redeemed value lands on automatically — minted the first time you redeem, then topped up on every redemption after
  • New sign-ups through the personal web dashboard are paused for now — existing users can still sign in as usual, and anyone new is pointed to installing the CLI instead, which stays fully open
Improved
  • Dialogs and money-entry fields across the web dashboard got a visual pass — bigger, clearer amount inputs, smoother resizing when a dialog's content changes, taller form controls, and a redesigned wallet page for both individual and organization accounts
Fixed
  • Fixed the CLI's wallet fund command telling an unverified account to expect a verification code by email or text that was never actually sent, leaving the command stuck forever; it now sends the code and walks through verifying it the same way card creation does
  • Fixed identity-verification imports skipping older accounts with no nationality on file, even though their verified ID already recorded an issuing country — that document's country is now used as a fallback
  • Fixed the dashboard's test-card walkthrough dead-ending on a pending identity check instead of auto-approving it in sandbox, and identity verification results no longer requiring you to close and reopen the panel to show a freshly simulated outcome
Added
  • The building blocks for two new card types and a rewards program are now in place behind the scenes: multi-use cards that stay open across repeat charges instead of closing after one purchase, AI-lab-scoped cards that can only be spent at a locked set of merchants, and token-based rewards ("tokenback") that accrue on card spend and can be redeemed for AI-credit-style spending power — all still fully dark, with no visible change to how cards work today
  • The narrower, still-dark API surface for companies picked up a way to fund a user's wallet with a native Apple Pay sheet embedded directly in the company's own app, instead of only a hosted funding page
  • New sandbox tools let you test a full transaction lifecycle end to end — authorize-only holds, partial captures, voids, and refunds as their own webhook-firing steps — instead of only a single simulated charge; the dashboard's "issue a test card" flow now walks through the same steps with a live trail of what fired
Fixed
  • Fixed more edge cases in how a company's own money is told apart from its users' money when a company mints cards through its own connection — the connection that created a card couldn't always read that same card's details, balance, or transaction history right after creating it, and some spend could briefly post against the wrong ledger before a background sweep corrected it automatically
  • Fixed a gap where a sandbox identity-verification result could, in a narrow window, be mistaken for a live one and influence a real card decision — verification webhooks are now checked against which environment actually sent them before anything is applied
Added
  • Organizations and individual accounts can now withdraw funds to a bank account — by domestic transfer or international wire — instead of only cashing out through a crypto exchange or address; save a payout destination once, request a withdrawal, and our team wires it by hand and keeps you posted at each step
  • Withdrawing now happens through one consistent dialog with a rail picker instead of separate flows for each method — bank transfer up front, with the crypto-address option tucked under "other methods" — for both individual accounts and organizations. The international-wire form has a searchable country picker instead of a free-text field, and the organization wallet page now shows any withdrawal still in progress, with a way to cancel it, instead of just a balance that dropped with no explanation
  • New sandbox tools for testing identity verification end to end: an endpoint that instantly forces a chosen outcome (approved, rejected, needs more info) — the identity-verification counterpart to test payments — a matching test-mode version of the hosted verification page, and a way for organization admins to simulate an outcome for a sandbox user right from the dashboard, all firing the same webhook a real review would send
  • The foundation for attaching your own card instead of only using an Agentcard-issued one keeps building out behind the scenes — the logic that charges an attached card per purchase is now in place, still fully dark with no visible change to how you create or use cards today
Improved
  • Adding funds from an agent conversation is smoother when phone verification is required — the add_funds tool now sends the verification code itself and tells the agent exactly what to do with it, instead of expecting a separate step first
Fixed
  • Fixed a cluster of bugs affecting organization-connected accounts, where identity verification, wallet balance, and phone verification could be checked against a leftover personal record instead of the organization's own account — causing confusing splits like verification reading approved in one place and not verified in another, a funded wallet showing a $0 balance, or an on-file phone number appearing missing
  • Fixed a bug where sending funds directly to a wallet's deposit address, instead of funding through the usual flow, could leave the balance showing $0 on the dashboard even though the money had arrived; affected accounts have been corrected automatically
Added
  • Organizations can now withdraw funds out of their company wallet — cash out to a bank account or send USDC directly to an address — from the dashboard or the API, using the same one-time-code confirmation as other sensitive wallet actions
  • Organization admins can now see full identity-verification detail for each cardholder right in the dashboard's Users drawer — the specific decision reason, checks performed, submitted documents, and whether a rejection matches the card issuer's restricted-countries list — instead of just a pass/fail status
  • The org dashboard's settings area has been reorganized: wallet balance and earnings now live on separate pages (money you hold vs. money you've earned), team, billing, revenue, card funding, credentials, and webhooks all moved under one Settings entrance, and billing can now be managed directly through a self-serve portal — payment method, invoices, cancellation — instead of contacting support
  • The foundation for letting you attach an existing card, instead of only using Agentcard-issued virtual cards, is rolling out behind the scenes — pure infrastructure for now, with no change to how you create or use cards today
Improved
  • The company plan now shows its full $5,000/month price plainly on the billing page, replacing the discounted $500 startup-price comparison
  • The narrower API surface for companies that only need to connect a user and verify their identity (still rolling out behind the scenes) now creates a wallet and records sign-in activity the same way a regular sign-in does, reaches a few more early users with a wallet-creation backfill fix, and returns a clear, retryable error when the identity-verification provider is temporarily unavailable instead of a generic failure
Fixed
  • Fixed the org billing page showing the generic list price for every organization — companies on legacy or negotiated pricing now see what they actually pay instead of the standard rate
  • Fixed a card-issuer webhook format change that silently prevented some approved cardholders' spending power from ever activating — affected accounts have been backfilled
Added
  • Organizations can now set their own markup — a percentage fee added on top of every checkout and wallet-funding transaction their integration drives — so companies earn revenue on their own terms, in addition to the card-interchange share already flowing into the company wallet. The fee is disclosed and priced into the total shown before checkout, and refunds automatically claw back the org's share proportionally
  • Companies can now design their own branded email for the "connect your account" flow — upload your logo and write your own message under Developer → OAuth, with a live preview that matches exactly what your users receive; the verification code is part of the design now, not something you need to reference in your copy
  • Ahead of retiring API keys in favor of OAuth client credentials everywhere, the dashboard's API playground — the last place that still handed out a test key — now provisions a client credential instead, and the infrastructure to sunset existing keys, with clear migration guidance and a grace period for teams still transitioning, is in place behind the scenes
Improved
  • The narrower API surface for companies that only need to connect a user and verify their identity (still rolling out behind the scenes) now also covers funding that user's wallet with Apple Pay or Google Pay from your own UI, and picked up a run of identity-verification fixes ahead of its public release
  • Dashboard tables — billing, team, transactions, and more — are now sortable and filterable, with a refreshed look in both light and dark mode
Fixed
  • Fixed identity verification dead-ending when a review came back needing a correction — you're now guided to fix the specific field or re-upload the right document instead of landing on a blank "almost there" screen with no way forward, and the verification page always renders in your own language
  • Fixed two separate ways a successful subscription payment could leave an account stuck on the free tier — a bug in our duplicate-checkout safeguard that silently ignored the very first activation, and a serverless timing issue that could cut post-payment setup short right after checkout succeeded; both are now also healed automatically by a recurring safety check if anything still slips through
  • Fixed signing in with GitHub for the first time dead-ending with a confusing "invalid code" error when your email needed verification — you're now walked through verifying it and land signed in, same as any other sign-in method
  • Fixed getting a production credential requiring an email to support — organization admins can now create and reveal their production OAuth client secret directly from the Credentials page, with no subscription needed just to get the credential itself
Added
  • Organizations now automatically earn back a share of every transaction their cards make — credited into a company wallet that's created automatically for every organization once it goes live, and shown right on the wallet page alongside your balance and activity
  • A narrower API surface for companies that only need to connect a user and verify their identity is rolling out behind the scenes — it doesn't change how you integrate with Agentcard today, and everything transactional still goes through MCP as before
Improved
  • Funding a company wallet now also works with Apple Pay and Google Pay, not just a wallet transfer, and organizations can switch between user-funded and company-funded billing after creation — as long as no money has moved yet — instead of being locked into their original choice forever
  • The organization Users page now shows when a user's identity verification started, not just whether it finished, so you can follow up with people who started and never came back
Fixed
  • Fixed the organization wallet page showing balances and funding controls that didn't match how the org actually pays for cards — user-funded organizations no longer see company-wallet-only screens, and switching the dashboard's Live/Sandbox toggle no longer briefly shows the wrong mode's balance or deposit address
Added
  • Signing in now supports your phone number as well as email, and if you sign in a different way than usual and it looks like you already have an account, you'll be offered to link the two together instead of ending up with separate accounts, balances, and cards
  • Behind the scenes, virtual cards are now issued by default through our current card-issuing platform in every environment — this has quietly been the case in production for a while, and now it's the standard everywhere; there's no change to how you create or use a card
  • The organization billing page now shows a startup discount when you haven't subscribed yet — a $500/month price alongside a crossed-out $5,000 comparison — with a matching green highlight on the "Go live" prompt in the sidebar
Improved
  • Setting up your integration with the `agent-cards-admin` wizard now provisions only a client ID and secret — no separate API key — and walks you through recovering from mistakes along the way (a bad directory, a mistyped sign-in code, switching accounts) instead of stopping the run; when it finishes, it also gives you the link to your new dashboard
Fixed
  • Fixed a dead end after subscribing an organization — paying customers landed on a page with no obvious next step instead of being guided straight to registering their production app
  • Fixed a bug where the dashboard could keep showing the onboarding flow to users who had already completed it — for example after signing out, on a new device, or in Safari — instead of remembering that you're done
  • Fixed company and organization connections being incorrectly told they were capped at the personal plan's $50-per-card limit — company-governed cards have never actually had that cap
  • Fixed identity verification for an organization's own cardholders sometimes completing without ever unlocking the card, and got a small number of previously-stuck verifications — ones that had never actually been started — moving again
Added
  • The self-serve web dashboard is now live — manage your cards, wallet, activity, connections, and settings outside of chat, plus a full console for organizations covering team members, spending, API keys, webhooks, and billing; sign in with email, Google, or GitHub
  • Choosing how your organization funds cards — user-funded or from a company wallet — is now part of creating an organization in the dashboard, with a clearer picker in place of the old billing-email field
  • Setting up an organization now includes a ready-to-use credential from the start — a sandbox client ID and secret are created automatically when your org is created, so there's no separate step to mint a key. The dashboard's new "Implement Agentcard" page walks you through connecting your app, and you can now connect to your org's MCP server by pasting the client secret in directly instead of exchanging it for a token yourself
Improved
  • Live (non-sandbox) use of a company wallet now requires an active organization subscription, the same requirement as live API keys and OAuth clients; sandbox company-wallet usage stays free
  • Identity verification is more forgiving: a photo that can't be read is now caught the moment you pick it instead of failing later in the process, and when your card issuer denies an application for a reason other than your documents (for example, an unsupported region), you now see a clear, truthful explanation instead of a generic "verification did not pass" message
  • The organization's "Go live" page now shows the subscription price up front, instead of only revealing it after you click through to checkout
  • Signing in to order over iMessage no longer requires a one-time code — texting in now authenticates you automatically using your phone number
Fixed
  • Fixed a DoorDash bug where an order that failed a restaurant's own cart-total check (like a combo needing one more item to hit the required total) could be misread as a temporary glitch and retried blindly — minting and voiding a new card on every attempt and burning through your monthly card allowance in the process. It's now recognized immediately with clear guidance on what to fix, and failed attempts no longer count against your card limit
  • Fixed inviting an existing teammate to an organization silently adding them without any notification — invited teammates now get an email, and the team page shows a clear "invited" badge until they've signed in
  • Fixed a bug in the DoorDash ordering bridge where switching residential proxy providers could silently break per-request session pinning, causing checkout requests to rotate through different IPs mid-session instead of staying on one
Added
  • Organizations can now authenticate API requests with OAuth2 client credentials in addition to an API key
  • Organizations can now integrate with Agentcard over MCP alone — connect with your org's OAuth2 client-credentials bearer for a full set of tools covering cardholders, identity verification, cards, and the company wallet, instead of calling raw REST endpoints; the public REST reference for these endpoints has been retired in favor of the MCP docs
  • New MCP tools let an agent complete phone verification and fund a wallet entirely within the conversation — previously only the CLI, dashboard, and buy agent could get through that step, so an agent connected purely over MCP had no way past the funding gate
  • The org console now has a Live/Sandbox toggle, so you can switch between test and live views without leaving the dashboard
Improved
  • For organizations, sandbox and live are now fully separate worlds end to end — a cardholder, card, or transaction belongs to whichever key created it and stays invisible to the other mode, webhook endpoints only ever receive events from their own mode, and how cards get funded (each user's own wallet vs. a shared company wallet) is now a choice you make once when the organization is created rather than a setting you flip later
  • Setting up a company account is smoother — onboarding leads with what you're building and how cards should get funded, and the dashboard's organization home and company-wallet pages got a round of polish from early feedback
Fixed
  • Fixed a bug where some personal MCP connections kept minting test cards that can't actually be spent, even though personal accounts are meant to be live-only — every personal connection now always issues a real, spendable card
  • Fixed a timing issue where closing a company-funded card could leave its unused balance stuck instead of returning it to the organization's wallet, plus related edge cases — retrying a card request right after a hiccup could occasionally fund a card twice, and the company-wallet dashboard now refreshes on its own instead of needing a manual reload
  • Fixed a bug where an OAuth-connected app could occasionally resolve the wrong mode (sandbox vs. live) when creating or reading a card
  • Fixed a bug that could prevent signing in to the dashboard if you belonged to more than one organization
Added
  • Organizations can now fund a shared company wallet and issue cards directly from it, instead of requiring every end user to fund their own — you choose "user-funded" or "company wallet" once when your integration is set up
  • New `agent-cards-admin wallet` commands to view and manage your organization's company wallet from the terminal
  • Identity verification for organizations now happens natively inside the dashboard — take a photo of your ID and the form fills itself in, instead of being redirected to a separate hosted verification page; ID photos taken on an iPhone (HEIC format) are now accepted too
  • The org console now includes full webhook management — create, test, and inspect webhook endpoints right from the dashboard without needing an API key
  • The dashboard's onboarding flow is more guided — a wallet-first home screen and a short, step-by-step setup instead of upfront homework
  • Companies can now set up webhook endpoints and fire a test event to confirm a destination is wired up correctly before going live — deliveries are signed so you can verify they're genuine, and failed ones are retried automatically
Improved
  • The `agent-cards-admin` onboarding wizard is more reliable for coding agents — re-running it now reuses your existing credentials instead of failing, a stray comment in your `.env` file no longer breaks credential detection, and a new `--app-name` flag lets you name your integration up front
  • The `agent-cards` CLI now checks for and installs updates automatically before every command, instead of just nudging you to update it yourself
  • The dashboard has a refreshed visual design with light and dark themes
Added
  • Started building a full self-serve web dashboard for managing your Agentcard account outside of chat — cards, wallet, activity, connections, and settings for individual accounts, plus a console for organizations to manage team members, spending, API keys, webhooks, and billing, with sign-in by email or your Google or GitHub account. It's not public yet, but the foundation is now in place
  • For organizations integrating directly via our API, cardholder identity verification now runs through the same verification pipeline used everywhere else in the product, and sandbox-mode verification is instant instead of needing a real provider
  • A new interactive playground inside the dashboard lets you try the full card lifecycle — create, fund, and close a sandbox card — without writing any code
  • In test mode you can now take a card through its entire life without any real money or outside setup — attach a payment method, verify identity, issue the card, reveal its number, run a charge that settles and fires the same events as production, and watch it auto-close after a single use
Improved
  • Inviting a teammate to your organization by email now works even if they don't already have an Agentcard account yet — previously that failed outright; now they get an invite and their first sign-in takes them straight into your organization
Fixed
  • Fixed a DoorDash bug where adding a second item to your cart could unexpectedly force a DoorDash account connection or fail outright — multiple items are now added in a single step so this can't happen
Fixed
  • Fixed a rare bug where a backend deploy could swallow an inbound text mid-conversation — it looked received but never got a reply. Deploys now hand off in-flight conversations cleanly instead of dropping them
  • Fixed a DoorDash bug where a run of guest-checkout hiccups could burn through several carts in under two minutes and dead-end in a forced login on a small first order — the agent now falls back to a single-item order instead of looping
  • Fixed automatic texts — cart reminders, scheduled order updates — sometimes silently failing to reach people who'd signed up with just a phone number and hadn't finished verification yet
Added
  • You can now ask your agent for your promo code history — which codes you've used, which are still processing, and which failed attempts are worth retrying
  • Right after verifying your phone number, your agent will now offer to link it to an existing email-based Agentcard account so everything carries over instead of leaving you with two separate accounts
  • Started moving the shopping agent onto its own dedicated, always-on server behind the scenes — no change to how you shop today, but it's the foundation for noticeably faster replies
Improved
  • Replies from your agent come back noticeably faster — you'll see a read receipt and a quick "one sec..." if it needs a beat, and several behind-the-scenes checks that used to slow down every single reply no longer do
  • Ask what's actually included in a total and the shopping agent can now show the real breakdown — subtotal, delivery fee, service fee, tax — instead of just saying the fees are bundled in
  • When your identity verification finishes, your agent now tells you right in the conversation instead of leaving you to find out on your next message
Fixed
  • Fixed the shopping agent telling users there was no way to add funds when they were short on balance — it now offers the funding link directly
  • Fixed the shopping agent losing track of things it told you outside a normal reply (order updates, broadcasts) — it now remembers what it said when you reply to it
  • Fixed new sign-ups occasionally hitting a dead end on a brief connection hiccup during phone verification — it now quietly retries instead of telling you to try again later
  • Fixed wallet funding showing a generic "Could not start payment — please try again" when an account had actually hit a funding limit — it now explains the limit clearly, and daily limits say to try again tomorrow instead of inviting a retry that can't work
  • Fixed the agent sometimes repeating the exact same "sorry, I couldn't complete that" reply several times in a row after a brief hiccup
  • Scheduled orders now text you the outcome — placed, skipped, or failed — instead of leaving you to find out later
  • Fixed a DoorDash bug where an item requiring a choice (like a size) could get stuck bouncing back and forth forever — it now picks a sensible default and tells you what it picked
  • Fixed DoorDash delivery addresses with a building name or note (like "... at the ISEC building") failing to match — the agent now tries a few sensible variations automatically
  • Fixed the shopping agent claiming the Agentcard Pay browser extension doesn't exist
  • Fixed order confirmations occasionally quoting the pre-checkout estimate as the amount charged when the real charge came in slightly different — confirmations now wait for the real, settled amount
  • Fixed the agent insisting a blurry or unrelated photo was a valid ID after failing to read it — it now says plainly that it couldn't read the image
  • Fixed identity-verification guidance pointing people back to the website to "finish there" — the hosted verification link is the only place that ever happens
  • Fixed a bug where asking the agent to "surprise you" could occasionally spiral into a runaway loop of automatic purchase attempts behind the scenes, briefly slowing the shopping agent down for other users
  • Fixed two knock-on issues from that same hiccup — a brief connection blip no longer makes the agent wrongly conclude identity verification is unavailable, and repeated connection failures now end the conversation with an honest message instead of retrying forever
Added
  • Ask your agent to "surprise me" and it'll buy you something small, fun, and genuinely surprising — capped at $10 by default, up to $25
  • DoorDash orders can now be picked up instead of delivered — just ask; delivery stays the default
  • If you build a cart over iMessage and go quiet, your agent now follows up with up to two short nudges before letting it go
Improved
  • DoorDash orders now default to your account's saved address and just confirm it with you, instead of asking you to enter one every time
  • Pricing always shows one combined 'service fees' line (platform fees, taxes, delivery, and ours) plus the real all-in total — cart, checkout, and order confirmations all agree on the same number now, and our fee is never quoted separately
  • Identity-verification reminders now arrive on whichever platform you actually use — iMessage first, email as a fallback — instead of skipping phone-first users entirely
  • Lists sent over iMessage (cart items, choices, options) now use a plain dash instead of a bullet character
  • Funding guidance no longer mentions sending USDC — wallet funding is Apple Pay / Google Pay only, and payment-method tools are now described accurately as being for flight bookings
Fixed
  • Fixed a bug where texting a photo of your ID could get lost entirely, with the agent wrongly claiming it can't receive images — ID photos are now received reliably and handed straight to identity verification
  • Fixed a bug where an ID photo sent mid-conversation wasn't submitted until your next message — sending the photo is now enough on its own
  • Fixed a loop that could leave someone in an unsupported country stuck, and made the identity-verification link more reliable
  • Fixed the shopping agent flatly refusing to reveal your card details
  • Fixed the shopping agent claiming it doesn't support promo or coupon codes — it now recognizes and redeems them mid-conversation
  • Closed a gap where an order could still ship to an old delivery address even after you'd confirmed a different one at checkout — the address is now re-verified right before the order is placed
  • Fixed a bug where the 'Buy Me Anything' concierge didn't realize your cart had carried over after connecting your account, and could ask you to re-add items you'd already added
  • Fixed a follow-on issue from yesterday's fix where restaurant items with a required choice (like a drink size) still couldn't be ordered properly — those items work as expected again
  • Fixed a bug where a scheduled DoorDash pickup order could reserve funds and mint a card for an order that was never actually going to be allowed to place
  • Fixed the second abandoned-cart reminder sometimes arriving too soon after the first
  • Fixed order confirmations quoting the price before fees instead of the amount actually charged to your card
  • Fixed a regression where the shopping agent temporarily lost the ability to answer general Agentcard questions, like billing or the Pay browser extension, mid-conversation
  • Fixed a short window where overlapping deploys could make the 'Buy Me Anything' iMessage line stop receiving messages entirely
  • Fixed a short window where the MCP server could fail every request right after a deploy
Added
  • You can now redeem a promo code to add credit straight to your wallet — just ask your agent to redeem it
  • During identity verification over iMessage, you can now just send a photo of your ID right in the chat instead of using a separate upload link — Agentcard figures out the document type and country automatically, and the verification link now opens a phone-friendly screen
  • The 'Buy Me Anything' iMessage line can now do everything your agent can do on Agentcard — check your balance, review transactions, handle identity verification — not just shop
  • If you stop partway through identity verification, you'll now get a reminder email with a link to pick up right where you left off; the ID-number question also asks for the right thing based on your document's country (a Social Security Number only for US-issued IDs)
Improved
  • Funding your wallet now sends two texts: one confirming your money was received and is settling, then a second once it's actually credited and ready to spend — instead of one early text that arrived before the funds could actually be used
  • The shopping agent now always tells you what it's doing right before a longer step, like starting identity verification or looking up a menu, instead of sometimes going quiet for 10-20 seconds
  • Identity verification now skips a screen that asked you to re-confirm information you'd already given earlier in the conversation
  • Cards issued through a company's connected app, or by an organization, are no longer capped by the personal-plan card-count and per-card limits — only the company's own billing controls apply
Fixed
  • Fixed a security gap where a company's API key could, in some cases, reach an individual user's personal account — cards, wallet balance, and orders — instead of staying scoped to the company's own integration
  • Closed a gap where, if a certain legacy payment-webhook setting were ever left blank, a forged webhook request could have triggered a real refund or settlement
  • Fixed several cart bugs: adding items in quick succession could fork your order into duplicate carts, a cart that got silently reset could lose every item except the newest one, and some new guest sessions couldn't hold more than one item at all
  • Fixed a bug where ordering an item with a required choice (like a drink size) could get stuck looping forever instead of completing or clearly failing
  • Fixed a bug where switching from browsing as a guest to your real account mid-checkout could ship your order to an old saved address instead of the one you'd just chosen
  • Fixed a bug where a shopping request over iMessage that took a bit longer to complete could incorrectly tell you it failed, even though it finished successfully in the background
  • Fixed a bug where a routine deploy could cause the iMessage concierge to suddenly lose track of what you were just talking about mid-conversation
  • Fixed a bug where items added to your cart before connecting a merchant account could vanish once you connected, instead of carrying over
  • Fixed identity verification asking for your phone number again, even when you'd already verified it at sign-in
  • Fixed the shopping agent bringing up identity verification before you'd even said what you wanted to buy — it now only comes up once you're actually ready to check out
  • Fixed a bug where the link to add funds to your wallet could be silently invalidated by link-preview scanning before you had a chance to tap it
  • Fixed a same-day issue where approval-gated purchases were wrongly denied even after being approved
  • Fixed a bug where an end-customer of a connected company app could be wrongly asked to upgrade to a paid plan after their first order, even though the company — not the individual — pays for usage
Added
  • You can now sign in with just your phone number — a text with a one-time code — as an alternative to email, both when connecting your account to a company's app and in the 'Buy Me Anything' iMessage concierge, which verifies you this way before shopping on your behalf instead of quietly creating an account for you behind the scenes
  • A second, self-hosted option for identity verification is being built out behind the scenes, running invisibly alongside today's verification flow — groundwork for a more resilient identity check, with no change to how you verify today
  • Groundwork is being laid for Agentcard to open and manage a merchant account on your behalf automatically instead of asking you to connect one you already have — not turned on for anyone yet, but the foundation for shopping at more places without a manual connect step
  • Ask your agent for a full account snapshot — plan, subscription status, and identity verification progress — or a breakdown of your spending grouped by how it was paid (wallet balance, saved card, and more)
  • The company integration wizard (the `agent-cards-admin` CLI) can now run non-interactively, so a coding agent or CI pipeline can complete company onboarding end to end instead of needing a human at the keyboard
  • Behind the scenes, groundwork was laid to safely merge two accounts belonging to the same person (say, one made by email and one made by phone) into a single account — not available to anyone yet, but a step toward automatically resolving duplicate accounts
Improved
  • The 'Buy Me Anything' concierge now remembers your name and delivery address across visits, so a returning conversation can offer to ship to "your usual place" instead of asking you to repeat yourself
  • A brand-new 'Buy Me Anything' conversation now gets an instant reply while your account finishes setting up in the background, instead of waiting on setup before you hear anything
Fixed
  • Fixed an intermittent bug where a restaurant search could briefly return the wrong results, a cart item could fail to add right after a successful search, or a checkout could get stuck — browsing and checkout are reliable again
  • Fixed a bug where signing up with a different capitalization of the same email address (e.g. Name@example.com vs name@example.com) could create a second, duplicate account instead of reusing the existing one
  • Fixed a gap where a company's connected app (OAuth) could issue real, live-money cards even without an active paid subscription — brought in line with API keys, which already required one
  • A reply containing a table now renders as readable lines over iMessage instead of raw markdown table syntax
  • Fixed a same-day regression, caught before it spread, where flight booking and saved traveler profiles briefly stopped working in the buy agent following an internal engine update
  • Fixed a bug where a backend restart could make the 'Buy Me Anything' concierge lose track of cards it had created for you in an earlier session
Added
  • Identity verification now happens right inside the connect flow — after you link a merchant, you fill out a short identity form (with address autocomplete) and complete a photo ID check without leaving Agentcard, instead of being routed to a separate page to track down
  • The 'Buy Me Anything' concierge can now send and receive photos over iMessage — a team member can share a picture with you mid-conversation, and a photo you send back is visible to the team helping with your order
  • The buy agent can now describe a restaurant's full menu, organized by category with item descriptions, so a question like "what pizzas do you have?" gets an instant answer instead of a search
Improved
  • While your agent is working on something over iMessage, the "typing…" indicator now stays on for the whole turn instead of disappearing after its first reply
  • If a team member steps into your 'Buy Me Anything' conversation and then goes quiet, it now automatically hands back to the AI agent after a few hours instead of leaving you waiting indefinitely
  • There's now a single Agentcard API address — api.agentcard.sh — for both testing and live use; which mode you're in is decided by your API key (sk_test_ vs sk_live_), not by which URL you call
Fixed
  • Sending a photo with no caption in the 'Buy Me Anything' chat now gets a clear "tell me what you'd like" response instead of being silently treated as an order
  • Fixed a bug where an address lookup could fail with a false authorization error during checkout — this could show up as a misleading store-outage message, or leave a guest session stuck at the delivery-address step
  • Fixed a cart error on certain build-your-own items (e.g. picking a required topping) that could incorrectly appear as a site outage instead of asking you to complete the choice
  • Fixed a bug where a single-use card that closed automatically right after being spent could keep showing a small leftover balance instead of $0
  • Fixed a rare timing issue where issuing several cards for the same account at nearly the same moment could mint more cards than your available balance actually covered
  • Fixed a security issue where an organization admin could, in rare cases, remove or change the role of a member belonging to a different organization than their own
  • Hardened outbound webhook delivery against a security issue where a configured webhook URL could be pointed at internal network addresses
  • Fixed a bug where the shopping concierge over iMessage stopped replying to every message after an underlying AI model upgrade
Added
  • Connecting your Agentcard account to a company's app now happens on its own dedicated site — a rebuilt connect and sign-in experience with a cleaner authorization screen that clearly shows which app is requesting access and what it can do before you approve it
Improved
  • Gift orders now default to letting the recipient enter their own delivery address by text, instead of requiring you to already know where they live; the recipient also now gets an SMS when their order is on the way
  • Checkout now gives a clear, actionable message when a scheduled delivery window fills up, instead of a generic error that made your agent keep retrying the same unavailable time slot
  • Adding a brand-new delivery address is now more reliable — a flaky first lookup while validating the address no longer fails the whole request
Fixed
  • Fixed an intermittent issue where a brand-new guest session could get stuck right at the delivery-address step; sessions are now verified as fully working before they're ever handed to you, so this class of dead-end can no longer happen
Added
  • Browse and build a cart before signing in — search restaurants, add items, and see your order build up as a guest, then connect your account only when you're ready to check out
  • The buy agent's replies now stream in as they're written instead of arriving in one burst at the end, so you see progress ("let me find that...") while it's still working instead of waiting for the whole turn to finish
  • Richer replies over iMessage — the buy agent can react with a tapback to a quick "yes," send a celebration effect when your order is confirmed, and (in limited testing) offer a native poll for simple choices
  • B2B companies can now onboard cardholders who only have an email on file, with no phone number required
  • The buy agent can now check your wallet balance directly, so it can tell you whether a top-up has landed instead of leaving you guessing
  • You'll now get a text the moment a wallet top-up finishes landing, instead of having to ask
  • After paying to fund your wallet, you now see a clear "payment complete" confirmation screen
Improved
  • Buy conversations now remember what your agent already looked up across messages, instead of re-searching and re-adding the same items on every follow-up — this also fixes a case where a scheduled order could loop endlessly asking you to confirm
  • Hitting your monthly card limit during checkout now gives a clear, plan-aware explanation and a way to upgrade on the spot, instead of a confusing message that could tell you to upgrade to the plan you're already on
  • Identity verification pages now open with your real name left blank instead of a placeholder like "iMessage User" — since the page requires your legal name to match your ID, a stray placeholder could otherwise cause verification to fail
  • Identity verification now asks for and prefills your real email and phone number where we have them, instead of a synthesized placeholder address, so the hosted verification page starts filled in correctly
  • A clearer message now appears if your identity verification is rejected because you already verified through Agentcard elsewhere, instead of a generic dead-end pointing you back to the website
  • Buy agent replies sent one line at a time over iMessage now read like natural status updates ("one sec, pulling up your addresses...") instead of sometimes sounding like a question that's about to be answered by the next line
Added
  • The CLI `buy` command now runs a full local AI agent — it connects directly to your Agentcard MCP server and exposes every tool (shopping, wallet, cards, KYC, connections, support) to the model, so you can shop, fund your wallet, check balances, and manage your account all in one conversational session without a separate MCP host
  • The buy agent can now fund your wallet on the spot when an order comes up short — if checkout is declined because you need more USDC, the agent opens a hosted funding session (Apple Pay / Google Pay) and walks you through phone verification if it is your first time, rather than stopping with a dead-end message
  • Shop for anything over iMessage — text the 'Buy Me Anything' number with what you want and an AI concierge handles the conversation, gathers your order details, and routes it for fulfillment; a Stripe payment link is sent to you once your order is ready to charge
Improved
  • In-flight deposits are now visible while funds are still confirming — right after you fund, there is a brief window where money has left your funding source but has not yet landed in your balance; the balance view, `get_balance`, and the CLI now show the in-transit amount as 'confirming' so your balance looks right throughout the transfer instead of dropping to zero
  • Saved delivery addresses in the buy chat are now shown in pages — the first 3 appear immediately and the rest are available on request, keeping the conversation readable when you have many addresses on file
  • The buy chat now keeps your cart, address, and order state across the full session — previously each message could lose track of what was already in your cart or re-ask for an address you had already set; the conversation is now threaded end to end so nothing gets repeated
  • Buy chat output is now clean plain text — tool names are hidden, internal markers are stripped, and the model no longer wraps text in Markdown asterisks that appear as raw symbols in the terminal
Fixed
  • Card issuance now checks your true available balance before approving — previously, funds already reserved by your other open cards were counted as available, so a $30 wallet with a live $10 card could still mint another $30 card; Agentcard now subtracts those reserved amounts first and shows you the correct net figure
  • The verification code is now described as an email everywhere — the code is delivered by email, but the CLI prompt and OTP email subject were saying it was sent to your phone; messaging across the verification email, CLI flow, and funding-gate prompts now correctly names email as the delivery channel
Added
  • Agentcard now runs on a rebuilt card-issuing rail — we re-platformed the entire issuing stack end to end, with embedded wallets you fund directly, a faster identity check, and a clean one-time cutover that carries your existing cards across automatically. It's the foundation for real wallet funding and broader card coverage, and it rolls out behind the scenes with no change to how you create or use cards today
Improved
  • The wallet and account view now shows your true spending power alongside incoming deposits — wallet funding movements appear as green credits in the transaction list, so you can see money in as well as money out
  • The `buy` tool now checks out correctly for wallet-funded accounts — the checkout flow was routing card creation through a path that didn't know about the current issuer, causing failures at the payment step; all buy checkouts now go through a single issuer-aware minter
  • Cards minted during a `buy` checkout are now attributed to the OAuth connection that created them — previously they were left with no owner, which caused `close_card` and `list_cards` to 404 on cards you had just minted via the buy flow
Fixed
  • The CLI no longer declares KYC rejected while you are still working through the verification page — statuses like `requires_input` are now treated as in-progress and polling continues until a real verdict arrives
  • Your card list no longer shows sandbox or test cards when you are in production mode — cards are now filtered to match the mode of the caller
  • Orders are now confirmed as fully placed before being reported as successful — we verify the order actually landed in your account, so a placement that's silently dropped is caught and surfaced as a failure rather than a phantom success
  • A `buy` checkout order that placed but was never charged no longer holds your wallet balance indefinitely — the reconciliation job now cross-checks against the payment ledger and releases the reservation when no charge is found
Added
  • Send an order as a gift — tell your agent a recipient's name and phone number and the order is delivered to them (or sent as a link so they enter their own address)
  • Locale meal subscriptions are now available in the `buy` tool — connect once and your agent can browse the menu, manage your subscription, and pause or cancel it
  • B2B cardholders can now complete identity verification through your application — Agentcard starts a Stripe Identity session scoped to the individual, and card issuance on live keys is only unlocked once the end user has verified
  • The `buy` tool now covers the full shopping lifecycle: unlink a merchant, track an order, set item substitution preferences, manage a monthly budget, and skip or unskip upcoming subscription deliveries — all conversationally
  • Seven new MCP tools bring the consumer MCP server to full CLI parity: `start_kyc`, `get_kyc_status`, `get_settings`, `update_settings`, `revoke_connection`, `buy_connect`, and `buy_connect_status`
  • The `buy` tool now handles onboarding inline — if a B2B end user is missing KYC or a payment method, the tool returns direct links to complete each step without any extra calls from your application
  • KYC is now enforced in sandbox mode using Stripe Identity's test mode — sandbox (`sk_test_`) integrations go through the same verification flow as production, with test-mode sessions that can never satisfy a live issuance check and vice versa
Improved
  • The `wizard` command now handles full onboarding in one pass — it signs up or logs in, creates your organization, mints a confidential OAuth client, and writes the client secret and sandbox API key directly into your app's env file, never into the LLM prompt
  • Flight bookings no longer need a separate connect step — the flights merchant is linked automatically to your account the moment you ask to search or book
  • The `wizard` command now registers every Agentcard MCP tool in your integration dynamically instead of a fixed subset — tools added in future releases are picked up automatically with no code changes on your side
Fixed
  • Identity verification now shows the exact reason a document was rejected (e.g. 'the document is invalid') instead of a generic photo hint, and suggests trying a different ID type
  • Address selection no longer gets stuck in a retry loop when the agent refers to an address by its position in the list instead of its id — the position is now resolved to the correct saved address automatically
Added
  • Cancel a booked flight and get a refund — your agent can quote the refund amount before cancelling, then issue it back to your original payment method; non-refundable fares are handled cleanly
  • Confidential OAuth clients — `agent-cards-admin` now issues a `client_secret` by default when you create an OAuth client, so your server-side app authenticates the token exchange instead of relying on PKCE alone
  • Subscription gate on card issuance — paid-plan accounts with a lapsed or cancelled subscription are now blocked from issuing new cards immediately, with a direct link to reactivate; free-plan and test-mode accounts are unaffected
Improved
  • The `agent-cards-admin wizard` command now shows a live progress UI as the integration agent works through your codebase
  • Multi-turn buy conversations are faster and more reliable — the agent carries resolved store, item, and option ids across turns instead of re-deriving them on every message, eliminating a loop that could trigger ~12 redundant calls per customization
Fixed
  • Identity verification webhooks no longer get orphaned — previous retries created new verification sessions and overwrote the stored session id, silently dropping completed webhooks and stranding users at 'KYC required' indefinitely; ~98 accounts unblocked
  • Good Eggs delivery windows are parsed correctly again after a site update changed the page structure — closed time slots are also filtered out so only bookable windows appear
  • Declining a checkout no longer erroneously consumes a free-order quota — the free slot is returned if the card mint step fails
  • A `do_not_honor` decline is now correctly attributed to the card issuer rather than Stripe's fraud system, so the error message points you in the right direction
  • Cart items whose ids differ between search results and the live cart are now resolved by name — previously these mismatches caused item-not-found errors when modifying a cart
  • OAuth clients that don't send an RFC 8707 resource indicator no longer get a 500 at token exchange — the missing field is now accepted, unblocking some MCP clients
Added
  • New Slack app for shopping — install the Agentcard Buy bot to your Slack workspace and DM it in plain language to place orders directly from Slack
Improved
  • The buy flow checks payment readiness before you build a cart — if your account is missing KYC, a phone number, or a payment method, your agent tells you upfront with every missing step and how to fix each one, instead of failing at checkout
  • Restaurant search now picks the right location when a store name matches multiple categories — results are filtered to the correct type (e.g. food vs. pharmacy) before presenting options
Fixed
  • Checkout now sizes the card with a small buffer over the confirmed cart total, preventing declines when the final charge runs slightly over the pre-checkout estimate
  • Connecting a merchant account with a non-US phone number no longer gets stuck — the country code is selected correctly for any supported country
  • B2B API calls that send explicit `null` on optional body fields no longer return a validation error
Added
  • Book flights end to end — tell your agent where and when you want to fly and it searches real flights, confirms the fare, and pays from your Agentcard balance, no separate login or connect step required
  • Save a traveler profile so flight bookings reuse your details instead of re-asking every time
  • Good Eggs is now a first-class merchant in the `buy` tool — order groceries the same conversational way as any other store, with its own address and scheduling flow
  • New `list_all_transactions` tool (MCP + CLI) returns every transaction across all your cards in one list, each row tagged with the card it belongs to
  • The Agentcard Pay Chrome extension can now reveal a card's full number, expiry, and CVC on demand from the cards list, and the post-creation screen adds See card and Fill card buttons
Improved
  • Consumer test mode has been removed — every card you create is now a live, real-money card funded by your saved payment method, with no mode toggle to manage
Fixed
  • Connecting to an MCP client is more reliable — expired or rotated tokens now return a clean re-authentication signal instead of failing, so clients stop retry-storming
  • Editing the quantity of a customized item in a cart (e.g. a build-your-own order) now works correctly instead of erroring
  • Removed a false "something went wrong" error that could appear after a successful merchant connection
Fixed
  • Identity verification no longer hangs — if a verification doesn't pass, your agent now tells you it failed and how to retry instead of waiting indefinitely
Added
  • Watch a live demo: an AI agent placing a real food-delivery order from Claude, with the checkout paid by an Agentcard virtual card — a real order completed end to end
Added
  • Connect a merchant through a hosted, Plaid-style login — you sign in to the store in a secure browser view and Agentcard seals the session for your agent, with a mobile-friendly login form
  • Free-plan accounts now get one free real order to try AgentCard end-to-end — after that, browsing stays open and a clear upgrade prompt appears when you go to order; paid plans are unlimited and test mode is never gated
Improved
  • Beta and waitlist wording has been removed from user-facing messaging — AgentCard is generally available
  • Clearer errors when finishing a connect flow fails, with a tighter timeout so a stuck connection surfaces quickly instead of hanging
Added
  • New conversational `buy` tool — tell your agent what to order in plain language ("order a caesar salad from Zuni") and it runs the whole flow: finds the store, builds the cart, asks for your delivery address, and confirms the total before checkout. Available over MCP, in the CLI (`agent-cards buy`), and via a short connect link
  • New Pro plan at $100/mo — 50 cards per month with up to $1,000 per card — selectable from the CLI, MCP, and dashboard
  • Order tracking — check the status and ETA of a placed order
  • Scheduled delivery — pick a delivery time at checkout instead of ordering for right now
  • Set a default delivery address and per-item substitution preferences so reorders and checkouts use your saved choices
  • Tip your delivery driver directly at checkout
Improved
  • Checkout is more reliable — orders use a stable idempotency key and are uniquely scoped per client, so a retry can never accidentally place a duplicate order
  • Carts self-heal — if a store drops a line item or a cart goes stale, AgentCard rebuilds it from the live cart instead of failing, including duplicate reorder lines and quantity edits
Fixed
  • Your agent can no longer fabricate an order-placement or order-status claim — it only reports an order as placed once checkout actually succeeds
  • Fixed a connect loop that could leave the merchant-connection flow stuck
Improved
  • Cards created for a purchase are now sized to the exact order total, including the pinned tip, so the charge always goes through cleanly
  • Documentation, the API integration guide, and CLI help were overhauled to fix points where agents previously got stuck setting up and using AgentCard
Fixed
  • Hardened the purchase money-path — idempotency, ledger accuracy, spend policy, and cart handling fixes prevent a charge from being double-counted or wrongly reversed, with a reconciliation safety net that confirms each charge and repairs any pending state
  • OAuth sign-in now works correctly for more MCP clients — discovery is fixed and the authorization step is properly separated, so connecting from clients like Kilo no longer fails
Added
  • You can now link external service accounts to AgentCard over OAuth — each connected account gets its own isolated card, so spending and limits never bleed across the agents and services you've connected, and known clients are recognized automatically
Improved
  • The OAuth consent and magic-link sign-in screens now show the actual app requesting access instead of always saying "Claude", so you can see exactly which client you're authorizing
Fixed
  • Refunds now go back to your original funding card instead of being stranded — a refund that previously landed in the wrong place is returned to the source it was paid from
  • Company onboarding is more reliable — the email action button is no longer blocked from opening, and onboarding-completion webhooks are no longer dropped when a delivery has to be retried
  • The CLI now retries transient network errors while waiting on a result instead of giving up, so a brief connection blip no longer aborts the command
Added
  • New CLI command `agent-cards cards close <id>` to close a specific card directly from the terminal
  • New CLI commands `agent-cards payment-method list` and `agent-cards payment-method default` to view your funding methods and choose which one is used by default
Improved
  • The MCP server now matches the API and CLI feature-for-feature — switching between test and live mode, listing and defaulting payment methods, and cancelling a plan are all available to agents over MCP
  • The CLI `mode` command is now listed in `--help` and no longer prints a misleading beta notice
Fixed
  • Slack Connect channel setup for new company accounts is now resilient to Slack rate limits — invites are paced and retried instead of being silently lost, and re-running setup reuses the existing channel rather than failing or sending a duplicate invite
Improved
  • All transactional emails redesigned to the dark agentcard.sh brand — magic links, approval requests, card and transaction notifications, billing emails, and onboarding sequences now share one consistent look
  • Every standalone browser page — auth verification, OAuth success, approvals, funding, identity verification, and subscription pages — now matches the dark agentcard.sh design instead of using bare HTML
Added
  • New company accounts now get a shared Slack Connect channel with the AgentCard team, created automatically when the organization is set up — the founders join and your billing contact is invited
  • Company accounts now receive an onboarding email from the founder when the organization is created — the team counterpart of the welcome email individual users already get
Added
  • Card creation now sends a confirmation email — just like transactions and card closures — whenever a card is created via the API, CLI, MCP, or dashboard; you can opt out per account in your notification settings
Improved
  • Test mode is now called "test mode" everywhere — CLI banners and docs no longer say "sandbox", making it clearer that new accounts start in test mode and go live with `agent-cards mode prod`
Fixed
  • Single-use cards now close the moment they're charged, so a follow-up charge is no longer wrongly declined as "card closed" while the card still showed as open
  • Closing a card after a purchase no longer occasionally fails — an already-closed card is now treated as a successful close
  • A declined charge caused by card-network fraud throttling no longer removes your funding card, and the decline message now suggests paying with Apple Pay or Google Pay instead
Improved
  • `agent-cards-admin keys list` now shows each API key's age and flags keys overdue for rotation, with a reminder to rotate stale ones
Fixed
  • Production API keys are no longer revoked without warning — orgs now get an email when a subscription goes past due (keys keep working through the billing grace period) and a notice if keys are eventually revoked
  • Rotating an API key now keeps the old key valid for 24 hours, so in-flight requests using the previous key don't fail the instant you rotate
  • Revoking or rotating an API key now only affects keys that belong to your own organization
Improved
  • The MCP server and CLI welcome screen now tell you that new accounts start in test mode and show the exact `agent-cards mode prod` command to switch to live
  • Sign-ups using disposable email addresses are now blocked, and repeated sign-up attempts from the same IP are rate-limited
Added
  • New users now receive a welcome email from the founder the first time they verify their magic link and sign in
Added
  • `get_plan` and `upgrade_plan` MCP tools — agents can now read your current plan, card limits, and monthly usage, and kick off a Stripe Checkout upgrade to Basic directly from a conversation
Improved
  • `create_card` is now plan-aware — when you hit a card limit, the error message points the agent at `get_plan` and `upgrade_plan` instead of showing a generic limit message
Fixed
  • Database connections are now automatically refreshed when AWS rotates RDS credentials — long-running Vercel instances that previously produced 503 errors after a rotation now recover on their own without a redeploy
Improved
  • Blog refreshed and restyled across all posts
  • About page updated with black-and-white portraits of our angel investors and founders
  • Agent-discovery metadata refreshed — agent.txt, llms.txt, and the .well-known endpoints (agent-card, agent-skills, API catalog, and MCP server card) now reflect current capabilities
Fixed
  • Webhook auto-disable now measures the 7-day failure window from the start of the current failure streak — not the endpoint's age — so a long-idle endpoint is no longer disabled on its first failed delivery, and the clock resets the moment a delivery succeeds
Improved
  • Admin dashboard now shows decline analytics — top decline reasons, declines by merchant, and a caller-type breakdown (human vs agent) so you can see exactly why and where transactions are being declined
Added
  • Outbound webhooks for the Public API — organizations can now subscribe to card, cardholder, transaction, and balance events via signed HTTP POST instead of polling. Supports 10 event types, 5-stage automatic retries, and endpoint auto-disable after 7 consecutive days of failures
  • AgentCard-Signature header on all webhook deliveries — timestamped HMAC-SHA256 signature (t=…,v1=…) makes payloads replay-safe and easy to verify in any language
  • `agent-cards-admin webhooks` command group — list, create, update, delete, reveal and rotate secrets, and inspect delivery history from the CLI
  • CLI auth now validates your stored token before any command runs — stale or revoked keys are caught immediately with an interactive re-login prompt instead of a mid-command error
Fixed
  • card.updated events now fire on balance changes — webhook subscribers previously received no notification when a transaction settled and updated the card balance
Improved
  • Backend and MCP server migrated from Railway to Vercel with AWS RDS Postgres — more reliable infrastructure with auto-scaling, advisory-lock-safe cron jobs, and DB-backed webhook retry queues
Fixed
  • Sandbox and live Stripe customer IDs are now stored separately — mixing a sandbox API key with a live cardholder row no longer returns a 500
Improved
  • Card issuance is now exclusively through Privacy.com — Stripe Issuing code paths have been removed, simplifying the backend and eliminating a source of confusion between providers
Added
  • Test mode — new accounts default to test mode, where card creation uses fully in-process sandboxing with no payment method, KYC, or plan limits required. Switch modes with `agent-cards mode [test|prod]`
Fixed
  • CLI card creation no longer prompts for confirmation when the backend requests approval — you're already at the keyboard, so approvals are auto-resolved immediately
Fixed
  • Sandbox API keys now mock card issuance entirely — sandbox_priv_ cards with deterministic 4242 PANs are returned instead of minting real cards
  • CLI login no longer hits rate limits during magic-link polling — /auth/me is now excluded from the auth rate limiter
  • Admin CLI shows actionable recovery steps on an invalid API key error — previously showed a terse message with no path forward
Improved
  • Identity verification now requires a selfie that matches your document — the KYC session is rejected if the photo doesn't match
  • `cards details` now shows the billing address — agents filling checkout forms no longer need to look it up separately
Fixed
  • KYC start no longer returns a 500 on Stripe errors — upstream failures are now caught and return a proper error response
Fixed
  • Sandbox payment intents are now routed correctly — webhook handlers and card close no longer fail with "No such payment_intent" on sandbox cards
  • Closing a card is now idempotent — concurrent close attempts no longer throw an error when the payment intent is already in a terminal state
Added
  • Identity verification — card creation now requires a government-issued ID, verified via Stripe Identity. Your name and date of birth are populated automatically from the verified document
Added
  • Org subscriptions — organizations can now subscribe to a paid plan via the admin CLI (`subscribe`), unlocking production API keys (`sk_live_`)
  • Production vs sandbox mode switching — `agent-cards-admin env` lets you switch between environments and all subsequent commands use the right API and key prefix automatically
Fixed
  • Admin CLI now defaults to the production API — previously defaulted to sandbox, causing cryptic JSON parse errors on first run
Improved
  • Unhandled async errors across all routes now fail fast with a proper response instead of timing out
Fixed
  • auth/me and slack/install endpoints returned errors in some environments — both now respond correctly
Added
  • Promotion codes — discount codes can now be applied when upgrading to a paid plan at checkout
Improved
  • Transactional emails, approval pages, and MCP consent page updated with a cleaner monospaced design
  • Support emails now route to Slack in real-time — human replies from Slack are sent back as email replies automatically
  • MCP server now listed on Glama — discoverable by agents browsing the MCP directory
Fixed
  • Approval route errors now return a proper response instead of hanging — unhandled async failures are caught across all routes
Added
  • CLI auto-upgrade — `agent-cards` now checks for new versions on each run and upgrades itself automatically
  • Uptime monitoring across all API endpoints — incidents are detected and tracked automatically
Improved
  • Card list now shows full card IDs and creation dates — easier to identify and reference specific cards
Fixed
  • CLI update check no longer runs during the `update` command itself, preventing a redundant loop
Added
  • Subscription plans — choose a plan that fits your usage, billed via Stripe with lifecycle emails at each stage
  • Monthly card usage shown in `agent-cards plan` — see how many cards you've created this billing period
Improved
  • Transactional emails, approval pages, and the MCP consent page updated to match the new Agentcard design
Improved
  • Card issuance upgraded — more reliable authorization and faster card delivery
  • CLI help output redesigned with grouped commands, examples, and a step-by-step 'How it works' flow
Fixed
  • Sandbox cardholder creation now uses the correct individual type to avoid issuing rejections
Added
  • Remove payment method — available from the CLI, MCP, and backend API
  • Sandbox mock services fully wired — card creation and payments in sandbox mode are fully isolated
Added
  • Refund endpoint for card transactions — admins can issue refunds directly via the API
  • Structured error codes for card creation and transaction failures — easier to handle errors programmatically
Improved
  • Card notification emails now sent to all org admins in addition to the cardholder
  • Spend limit and balance are validated before a transaction is processed — clearer errors on failure
Fixed
  • Stale card cleanup now correctly handles cards with a 2-hour timeout
Added
  • sk_live_ API key support — production keys now work alongside sandbox sk_test_ keys
Fixed
  • IP blocklist now correctly handles IPv6-mapped addresses and proxy headers
Added
  • Webhook notifications for card events — get notified when cards are created, authorized, or closed
Added
  • Slack integration — link your account, create cards with /card, and receive DM notifications for transactions and closures
  • Card creation requests in Slack require approval — admins are prompted in-channel before a card is issued
Improved
  • Card type language updated across all product copy and documentation
Improved
  • setup-mcp now automatically prompts new users to sign up — no extra steps to get started from the CLI
Added
  • Agentcard Pay Chrome extension — lets your AI agent detect checkout pages in the browser and fill card details automatically
  • pay_checkout, detect_checkout, and fill_card MCP tools — agents can now complete purchases end-to-end without manual card entry
  • Billing address collected at card creation and shown in card details
Improved
  • Payment method declines now return detailed error messages — failed methods are auto-removed so you can retry with a new one
  • Phone number is now required at signup to meet identity verification requirements
  • Card limit lowered to $50 — clearer upgrade messaging shown when the limit is hit
Added
  • Payment method onboarding — add a debit or credit card once and use it to fund all future cards
  • Hold-based card funding — funds are held on your payment method at card creation, captured when used, and released when the card is closed
  • Real-time authorization webhook — transactions are confirmed in real time
Improved
  • Wallet and x402 removed — funding is now handled directly via your saved payment method for a simpler flow
  • Stale cards are automatically cleaned up and the MCP and CLI messaging updated to reflect the new funding model
Added
  • Sandbox test mode is now live — create sk_test_ API keys and integrate against api.agentcard.sh without real charges (test vs live is decided by the key prefix, same base URL)
  • REST API under /api/v1/ — organizations, cardholders, and wallets accessible via API key
  • Unified Cardholder model — identity, wallet, and cards all scoped to a named cardholder
  • Admin CLI for managing organizations, API keys, and team members
  • Multi-key management in the CLI — store and switch between API keys with `keys set`
  • API key authentication for CLI login — use your API key instead of email magic link
Added
  • Transaction history — view past charges per card in the CLI (`cards transactions`) and via MCP (`list_transactions`)
  • AI auto-reply in support chat — common questions answered instantly without waiting for a human
  • IN_USE card status shown while a transaction is being authorized
Improved
  • Full card lifecycle handled — declines, reversals, expirations, and refunds all tracked correctly
  • Rate limits relaxed to reduce false positives for normal usage patterns
Fixed
  • Card creation no longer crashes after collecting user info for the first time
  • Closed cards now behave correctly and sandbox mode removed to match production behavior
Added
  • add_funds MCP tool — agents can now top up your balance directly
  • wallet balance and wallet fund commands added to the CLI
  • User info collection during card creation — the CLI and MCP now guide you through submitting identity details on first use
  • ChatGPT app store compatibility — Agentcard now works as a ChatGPT plugin
Improved
  • MCP tools now include safety annotations so agents understand which actions are read-only vs. destructive
  • Card creation returns a checkout URL when your wallet balance is too low — no more silent failures
Fixed
  • MCP create_card now correctly handles the 202 approval-pending response
  • One-time use card cancellation now uses native lifecycle controls
Added
  • Wallet system — fund a wallet balance once, then create cards instantly without a new checkout each time
  • Real card issuance — physical-network virtual cards backed by your wallet
  • Inline approval flow for CLI and MCP — approve or deny card requests without leaving your terminal or chat
Improved
  • Card limits enforced — $500 maximum per card, up to 5 active cards at a time
Fixed
  • Nurture email sequence now respects step delays correctly — emails send in the right order at the right time
  • Failed nurture emails are now retried after delivery errors instead of being silently dropped
Added
  • Chip logo with robot face easter egg across the site and dashboard
  • OAuth 2.1 support — connect Agentcard directly to Claude.ai as a native connector
  • MCP server now has a favicon so it appears with the Agentcard icon in Claude.ai
  • Waitlist reactivation email campaign for users who signed up but haven't gotten started
Improved
  • Onboarding email sequence expanded to 4 steps with bounce filtering — fewer failed deliveries
  • OAuth magic link emails now use the same polished template as all other Agentcard emails
Fixed
  • OAuth magic link verification now works correctly regardless of middleware order
Added
  • MCP package published to npm as @agent-cards/mcp with auto-sync from monorepo
  • Rewritten MCP README with quick setup instructions and clearer product description
Improved
  • MCP bumped to v0.2.1
Added
  • MCP auto-discovery via .well-known/mcp/server-card.json endpoint
Added
  • Automated nurture emails to help you get started after signup
  • Clear decline reasons shown when a transaction is rejected — in CLI, MCP, and email
Improved
  • Content and technical optimizations for AI search engine visibility (GEO)
Fixed
  • Admin CORS headers now included on rate-limited responses
  • MCP server deploy now targets the correct service
Added
  • Full merchant category detection — every transaction now shows what it was spent on
  • Enhanced security controls — detailed audit trail for all card activity
Improved
  • Support notifications now include more context so issues get resolved faster
  • Login attempt limits relaxed — fewer lockouts during normal use
  • Better error messages when creating cards that need approval
Fixed
  • CLI no longer crashes when creating a card that requires approval
Added
  • Live support chat directly from the CLI and MCP
  • Agents now request your approval before taking sensitive actions
Improved
  • Cards are clearly marked as single-use — they close automatically after the first transaction
Added
  • setup-mcp command in CLI — connect your AI agent to Agentcard in one step