# Agentcard (slim) > Agentcard gives AI agents a way to pay at card checkouts. Its Vault stores a user's own cards for approved purchases, and Issuing creates single-use or multi-use virtual Visa cards. Access is by REST API, MCP server and CLI. - Full: https://www.anchorterminal.com/tools/agentcard.md (~9,500 tokens) · this version ~2,180 tokens · JSON https://www.anchorterminal.com/tools/agentcard.json · canonical https://www.anchorterminal.com/tools/agentcard - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **C · 56.5/100 · rank #632 of 950 · #6 in Agent wallets & spending controls · not agent-ready · confidence medium** Assessment: Purchases need the user's passkey approval by default, cards carry spending rules, and card creation takes an idempotency key. No status page, published rate limits beyond the token endpoint, or privacy policy of Agentcard's own was found, and the Trust Centre could not be read. Issuing costs $5,000 a month. ## Facts - Kind: HTTP API · vendor: Agentcard Corporation · category: Agent wallets & spending controls · legal entity: Agentcard Corporation · provenance 51/100 - Endpoint: `https://api.agentcard.sh` (HTTP) - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under Agentcard's terms of use. The `agent-cards` CLI on npm declares no licence, `@agent-cards/checkout` is marked as having none, and the repository they name is private - Probe metrics: not measured yet (probes haven't run) - Custody: Vault cards are encrypted on the user's device with a passkey before storage, and the site says Agentcard never sees the full number. Issued cards draw on a balance held as USDC on Base as collateral, per the terms and the Issuing page - Spending limits: Each issued card holds a set amount in cents (minimum 100). Presets add caps in total and per rolling 24 hours, 7 days and 30 days, plus merchant, category, country, currency, day and hour rules, in `strict` or `watch` mode - Approvals: Vault purchases wait for the user's passkey or master password. Production `POST /api/v2/cards` returns `approval_pending` with an `approval_url`. Users can opt in to auto-approval under an amount and budget they set, and can require approval for each reveal of card details - Revocation: `pause_card`, `close_card`, `revoke_connection` and `agent-cards companies credentials revoke`. Connection tokens last one hour and each refresh invalidates the old pair - Cards: Virtual Visa cards issued by Third National (Rain), single-use or multi-use with an optional expiry up to 365 days. The Vault stores Visa, Mastercard, American Express and Discover cards. No physical cards per the FAQ - Funding: Apple Pay, Google Pay or card through MoonPay and Crossmint, or USDC on Base, held as USDC. A company wallet can fund users' cards. No ACH or wire per the FAQ. Wallet funding is US only per the terms - Identity checks: Issuing needs KYC through Sumsub (document and face scan). The Vault needs none - API: REST at https://api.agentcard.sh under `/api/v2`, plus `/buy`. OpenAPI 3.1.0 file, version 2.0.0, with 20 paths and 21 operations. Vault, preset and webhook endpoint routes are documented on Markdown pages only - MCP: Streamable HTTP at https://mcp.agentcard.sh/mcp. The docs hold pages for 25 organisation tools and 92 user tools. The overview lists 39 user tools, and others are hidden unless `x-expert-tools: 1` is sent. A shopping-only connection gets only shopping tools - CLI: `agent-cards` 0.8.2 on npm (28 September 2026), Node 22 or later, 116 documented commands. `agent-cards api` lists, describes and calls every account tool with JSON output - Credentials: OAuth 2.0 client credentials. `client_id` and `client_secret` (`acs_`) per sandbox or production client, platform tokens for one hour with scope `api`, user connection tokens (`act_`) with rotating refresh tokens (`rct_`), and public PKCE clients - Rate limits: 30 requests per 5 minutes per IP on `POST /api/v2/oauth/token`. The MCP `create_card` tool can return `rate_limited` with advice to wait about a minute. No other figure found - Errors: `{"error":{"code","message","docs"}}` with a stable `code`. MCP tools return a `status` discriminator that names the next step, such as `kyc_required` or `approval_pending` - Webhooks: Signed with HMAC-SHA256 in `AgentCard-Signature`, delivered at least once, retried up to five times over about 96 minutes, with a delivery log by API and dashboard - SDKs: `@agent-cards/checkout` 0.23.6 on npm (9 October 2026) for Playwright and CDP browsers. No Python SDK found - Card fees: No annual fee, 0 per cent APR, 1 per cent on international transactions and a late fee of 2 per cent of the outstanding balance, per the card terms of 10 July 2026 - Status: No status page found on the site or in the docs. An SLA is listed for the Enterprise plans only - Prices: Purchase Agent request (listed price, free in beta) $0.15 per call; Issuing plan $5000 per month (plan); Vault Free plan, up to 5,000 users free per month (plan); Issued card international transaction 1% percentage fee - Scores: Reliability 29, Performance pending, Schema & documentation 80, Agent ergonomics 63, Security & auth 68, Payments & pricing 42, Task success pending, Maintenance & community 74, Transparency & trust 44 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service on the REST API at api.agentcard.sh and the MCP server at mcp.agentcard.sh. · Schema & documentation, A public OpenAPI 3.1.0 file at docs.agentcard.sh/openapi.json, version 2.0.0, with 20 paths and 21 operations for tokens, connections, ident… · Agent ergonomics, The docs hold pages for 92 user tools and 25 organisation tools on the MCP server, which is the more-than-30 band (5). · Security & auth, OAuth 2.0 client credentials. · Payments & pricing, Payment platforms and wallets take the highest step that applies on the 40-point protocol line. · Maintenance & community, `@agent-cards/checkout` 0.23.6 was published on 9 October 2026, `agent-cards` 0.8.2 on 28 September 2026, and the newest changelog entry is… · Transparency & trust, A closed service. - Sources: 39, open questions: 17, both in the full twin - Capabilities: payments.card, wallet.spend-limits, wallet.custody - JSON: https://www.anchorterminal.com/api/v1/tools/agentcard.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/agentcard.svg` or a link to https://www.anchorterminal.com/tools/agentcard from a page on agentcard.sh or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Mint a platform token with `POST /api/v2/oauth/token` and cache it for its one hour. The endpoint allows 30 requests per 5 minutes per IP 2. Send the same `Idempotency-Key` on every retry of `POST /api/v2/cards`, and the same `idempotency_key` on every retry of `buy_checkout` 3. Pass `source: "issued"` to the MCP `create_card` tool for a card number. Without it the tool may start Vault setup and return a link 4. Call `get_card_details` only at the payment form and never log the result. Each read notifies the member and may return `approval_required` 5. Treat `transaction.authorized` and `order.*` webhooks as the record of a payment, and deduplicate deliveries on the event `id` ## Connect ```bash npm install -g agent-cards ``` ```bash curl -X POST https://api.agentcard.sh/api/v2/oauth/token -d grant_type=client_credentials -d client_id=$AGENTCARD_CLIENT_ID -d client_secret=$AGENTCARD_CLIENT_SECRET ``` ```bash claude mcp add agentcard --transport http https://mcp.agentcard.sh/mcp --header "Authorization: Bearer YOUR_CLIENT_SECRET" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/agentcard ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Sponge Wallet | E | 43.2 | wallet.spend-limits, payments.card, wallet.custody | https://www.anchorterminal.com/tools/sponge-wallet.min.md | | Turnkey Agentic Wallets | BB | 76 | wallet.spend-limits, wallet.custody | https://www.anchorterminal.com/tools/turnkey-agentic-wallets.min.md | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | wallet.custody, wallet.spend-limits | https://www.anchorterminal.com/tools/circle-wallets.min.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | wallet.custody, wallet.spend-limits | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.min.md | | Openfort | BB | 70.1 | wallet.spend-limits, wallet.custody | https://www.anchorterminal.com/tools/openfort.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)