Mercury Launches Virtual Cards for AI Agents Mercury launched Agent Cards on August 12, enabling AI agents to retrieve dedicated virtual-card credentials through its API or CLI and make online purchases within administrator-set limits. Mercury's documentation says agents cannot create agent cards, raise their limits, unfreeze them, or access cards not explicitly assigned to them, while the customer remains responsible for every transaction. Mercury Launches Virtual Cards for AI Agents Mercury launched Agent Cards on August 12, enabling AI agents to retrieve dedicated virtual-card credentials through its API or CLI and make online purchases within administrator-set limits. Mercury's documentation says agents cannot create agent cards, raise their limits, unfreeze them, or access cards not explicitly assigned to them, while the customer remains responsible for every transaction. Mercury launched Agent Cards on August 12, a virtual-card type that businesses can assign to AI agents for autonomous online purchases. Mercury's support documentation says an agent can retrieve a card number, expiration date, and CVC through the company's API or command-line interface, allowing checkout without a person entering the credentials. The product is designed for tasks including vendor and procurement payments, flight bookings, online advertising, API usage, developer tools, and SaaS subscriptions. Mercury says Agent Cards are accepted anywhere Mastercard is accepted online and that Mercury Business customers can designate both debit and credit virtual cards as agent cards. Card-level controls A human must create the Agent Card in Mercury's web or mobile app and set its daily, weekly, or monthly spending limit. The documentation says the agent cannot create an Agent Card, change its limit, unfreeze it, or retrieve credentials for another card that was not explicitly assigned to it. A human administrator can freeze or cancel the card. The credential isolation is the central product change. An agent can obtain the payment details needed to complete an online purchase, but its authority is constrained to the assigned card and the limit set by a person. Mercury also says it records standard transaction details and certain API or CLI requests used to reveal Agent Card credentials. PYMNTS independently reported the launch and described Agent Cards as dedicated credentials with spending limits and an audit trail separate from human cardholders. The publication also reported that customers had already been manually issuing ordinary virtual cards to agents, while the new product adds controls designed for autonomous use. The liability boundary Mercury's documentation makes an important limitation explicit: the customer is responsible for Agent Card transactions, which are treated as authorized even if the agent acted outside the authority the company intended. Standard dispute rights still apply, including when credentials are stolen by an outside party, but the card controls do not determine whether an agent chose the correct item, vendor, or moment to buy. For teams building purchasing agents, that means card controls are only one layer. The workflow still needs application-level approval rules, vendor allowlists where appropriate, idempotent transaction handling, and monitoring for prompt injection or flawed task logic. Agent Cards reduce credential sharing and cap card-level exposure; they do not validate the business intent behind a purchase. Key Points - 1Mercury Agent Cards give AI agents dedicated virtual-card credentials for autonomous online checkout while separating their access from human cardholders and other cards. - 2Mercury documents hard controls: humans create the cards and set limits, while agents cannot raise limits, unfreeze cards, or retrieve credentials for unassigned cards. - 3Mercury treats Agent Card transactions as customer-authorized, so workflow-level approvals and intent checks remain necessary beyond the card controls. Scoring Rationale The launch provides a concrete payment credential for businesses deploying purchasing agents, with scoped access and hard card-level controls. Its impact is practical but bounded to Mercury customers, and the customer remains responsible for transactions that the agent initiates. Sources Primary source and supporting public references used for this report. Practice with real Retail & eCommerce data 90 SQL & Python problems · 15 industry datasets 250 free problems · No credit card See all Retail & eCommerce problems /problems/datasets/retail