A payment and entitlement gate for AI agents purchasing expert services
SSRN · Working paper · Version 2.9 ·
Sets out an architecture and a formal model for one decision an AI agent’s purchase needs inside a single request: whether it may start. One gate admits a quote on a payment credential or on an entitlement the client already holds, and the paper establishes, within its model, that fulfilment starts only after admission and that committed spend under a mandate stays within its cap when purchases run concurrently.
Versions of this paper
- Version 2.9 (this page) Posted 30 September 2026 · 68 pages · DOI 10.2139/ssrn.7543686
- Version 1.7.2 Posted 24 June 2026 · 46 pages · DOI 10.2139/ssrn.6928639
Version 2.9 revises and retitles the paper first posted in June 2026. Each version keeps its own SSRN record and DOI.
The document
- Title
- A Payment and Entitlement Gate for Self-Serve Agentic Expert-Access: Architecture and a Formal Admission Model
- Version
- 2.9, dated
- DOI
- 10.2139/ssrn.7543686
- SSRN record
- SSRN 7543686
- Posted
- Length
- 68 pages
- JEL classification
- D47, L86, D82, E42
Abstract
A software agent buying expert work for a principal needs an answer, inside one request, to whether a purchase may start. This paper gives an architecture and a formal model for that decision. One gate state separates quotation and authority checks from fulfilment and admits a quote on one of two branches: a payment credential presented against the operator’s internal payment requirement, or a plan check against an entitlement the client already holds.
Four structural facts and one invariant theorem are established over the task model: fulfilment starts only after admission; a request key yields at most one activation; a task consumes at most one admission token; a delivered artefact carries an operator-signed receipt that verifies against the operator’s own records, with no independent party attesting it; and gross committed spend under a mandate stays within its cap when purchases run concurrently, under a per-mandate serialised reserve-and-commit. A corollary adds the entitlement side: a prepaid balance never goes negative under concurrent draws. A validation supplement, identified in the paper by its hash, checks the results on fulfilment, token consumption and spend, and the corollary by exhaustive search of five bounded instances of a Python encoding of the model. The Machine Payments Protocol (MPP) is the candidate wire protocol for the payment branch, and the paper fixes how an adapter binds MPP challenges to the internal requirement, what each response carries and how a refused credential leaves the task at the gate.
The model departs from the author’s Internet-Draft of July 2026: it adds a separate entitlement branch and the concurrent budget result, and it differs from the draft on the timing of the payment challenge, gate refusals, deadlines and mandate revocation. Admission records an accepted credential, a billing receivable or a consumed allowance; collection of funds, provider behaviour and any deployed implementation lie outside the results.
Sources
- The paper on SSRN 68 pages · DOI 10.2139/ssrn.7543686
- The paper as a PDF 68 pages · version 2.9
- The Internet-Draft the model departs from IETF · individual Internet-Draft
- SSRN author page King Yew Choo
- ORCID record 0009-0002-5244-6082