Engineering Journal

Know Your Agent: Identity and Trust in the 402 Era

For a long time the reserved HTTP status code 402 - "Payment Required" - did nothing. Now it does: the x402 pattern lets a service answer a request by asking for payment, and an AI agent can settle it and retry, no human at the checkout. Agents can pay. That quietly moves the hard problem somewhere new. The question is no longer only "can this agent pay," it's "who is this agent, who does it act for, and what is it allowed to spend." That layer - Know Your Agent - is the one nobody can skip.

We solved this for humans and businesses. Then the caller changed.

Finance built KYC to answer "is this person real," and KYB to answer "is this business real and trustworthy." Those checks assume the thing on the other side has a passport, a registration number, a physical existence you can verify. An AI agent has none of that by default. It's software - spun up in seconds, copied for free, as easy to impersonate as a username. Give that thing the ability to pay, and you have payments moving at machine speed with no idea who's behind them. Payment without identity isn't convenience. It's fraud with a faster clock.

What does "Know Your Agent" actually ask?

Four questions, and a payment rail answers none of them on its own. Who is this agent - a stable, verifiable identity, not a display name. Who does it act for - the human or business principal behind it, because an agent buying something is really someone's mandate. Can it be trusted - a history you can inspect, not a first-time promise. And what is it allowed to do - a scope and a spending cap, so a compromised or confused agent is a bounded problem, not an open account.

An agent that can prove all four is a counterparty. An agent that can prove none of them is a stranger you just handed a card.

The standards are arriving - carefully

The good news is that the missing pieces are being built in the open, and it's worth being precise about how early they are. x402 revives HTTP 402 so software can pay software inline. Account-abstraction standards give an agent a programmable wallet with rules baked in - limits, allowlists, revocable permissions. And there are draft ERCs proposing trustless-agent identity and reputation registries - a way for an agent to have an on-chain identity and an accumulated, checkable reputation. These are emerging and, in places, still draft; none of them is a finished, universal answer yet. But the direction is unmistakable: identity and reputation are being wired next to payment, not bolted on after.

KYB and KYA are the same discipline, pointed at a new thing

Here's the part that matters for how we build. The engine that verifies a business already does most of the job. It resolves an entity from scattered evidence, keeps identity confidence separate from risk, scores across dimensions, ties every conclusion to evidence, and keeps monitoring after onboarding. Point that same engine at an agent and the shape holds: resolve the agent's identity and its principal, score its reputation, check its mandate, and watch it over time. This is exactly why we built OpenKYB the way we did - business verification first, with agents as the next thing it learns to see.

And it has somewhere to live. Africa Connect, our MCP gateway, is already the place agents meet verified African businesses. The natural next question at that gateway is not just "is this business real" but "is this agent, asking to transact, one we can trust" - Know Your Business and Know Your Agent standing on the same counter.

Identity before access, mandate before money

None of this is a new principle for us - it's the old one with a new subject. We've argued that identity comes before access when you let an agent act, and that every naira should explain itself when software touches money. Know Your Agent is those two ideas meeting the 402 era: verify who is acting before you let them act, and bound what they can spend before the money moves. The agent economy will be huge, and it will be a fraud economy for anyone who wires payment without identity.

The takeaway

"Agents can pay now" is the headline. "Prove who the agent is, whose mandate it carries, and what it may spend" is the actual work. The businesses and platforms that treat agent identity as first-class - verified, reputational, scoped, monitored - are the ones the agent economy will be safe to transact with. The ones that treat 402 as just a faster checkout will learn the hard way that a payment rail is not a trust layer.

At Mpaukwu, we're building for the trust layer: business verification today, agent verification next, on the same evidence-and-reputation foundation - because in the 402 era, knowing your agent is knowing who you just did business with.


Mpaukwu Trading builds founder-led SaaS products, automation systems, and applied-AI platforms for African businesses, including OpenKYB and Africa Connect. Read more from the Engineering Journal or start a project.