
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@bolyra/payment-protocols
Advanced tools
ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce
ZKP privacy layer for agentic commerce payment protocols. Open-source protocol research — not production software.
When AI agents make purchases on behalf of humans, payment networks need to verify:
Today, Visa's Trusted Agent Protocol (TAP) and Google's Agent Payments Protocol (AP2) answer these questions with centralized registries and plain-text mandates. The merchant sees everything — the user's identity, their exact budget, their full policy.
Bolyra replaces that with zero-knowledge proofs. The merchant learns only:
The merchant never sees: the human's identity, the exact spend limit, the full vendor allowlist, or the delegation chain structure.
┌──────────────┐ ┌──────────────────┐ ┌──────────────┐
│ Human │────▸│ Bolyra SDK │────▸│ ZKP Proof │
│ (identity) │ │ (handshake + │ │ (public │
│ │ │ spend policy) │ │ signals │
└──────────────┘ └──────────────────┘ │ only) │
└──────┬───────┘
│
┌───────────────────────┼───────────────────────┐
▼ ▼ ▼
┌────────────────┐ ┌────────────────┐ ┌─────────────────┐
│ Visa TAP │ │ Google AP2 │ │ Spend Policy │
│ Adapter │ │ Adapter │ │ Encoder │
│ │ │ │ │ │
│ TAP payment │ │ AP2 mandate │ │ Bitmask │
│ signal + │ │ proof + │ │ encoding + │
│ trust score │ │ delegation │ │ verification │
└────────────────┘ └────────────────┘ └─────────────────┘
| TAP Concept | Bolyra Equivalent |
|---|---|
| Agent registry lookup | ZKP proof of human authorization |
| HTTP Message Signature (RFC 9421) | ZKP proof + scope commitment |
| Payment Instructions API | Spend policy encoded in permission bitmask |
| Payment Signals API | Scope commitment + agent nullifier |
| Trust tier | Score-based grading (A/B/C/D/F) |
| AP2 Concept | Bolyra Equivalent |
|---|---|
| Intent Mandate | Bolyra handshake proof (human → agent) |
| Cart Mandate | Spend policy ZKP (covers specific transaction) |
| Payment Mandate | Off-chain verified proof (batch mode) |
| Agent-to-agent delegation | Bolyra delegation chain with hop tracking |
| Mandate signature | ZKP proof (Groth16 for human, PLONK for agent) |
| Stripe ACP Concept | Bolyra Equivalent |
|---|---|
| Acting agent | Leaf delegatee in the v=2 bundle's delegationChain |
| Originating agent | Root credential the human authorized at handshake |
| Delegation depth | chainDepth from the verified context |
| Spending cap | Collapsed from cumulative FINANCIAL_* bits (2/3/4) on the leaf scope |
sign_on_behalf flag | Bit 5 of the leaf scope (for pi.confirm flows) |
The narrowing wedge: a root agent with FINANCIAL_UNLIMITED can delegate down to a sub-agent with FINANCIAL_SMALL ($100 cap). Stripe ACP sees only the leaf's $100 cap, even though the root could have spent more.
import { createVisaTAPVerification } from '@bolyra/payment-protocols';
const result = await createVisaTAPVerification(
humanIdentity,
agentCredential,
{
maxTransactionAmount: 50_000, // $500
maxCumulativeAmount: 100_000, // $1,000
currency: 'USD',
timeWindow: { start: now, end: now + 86400 },
},
{
agentDid: 'did:bolyra:base-sepolia:...',
merchantId: 'visa-merchant-123',
amount: 5_000,
currency: 'USD',
transactionId: 'txn-abc-123',
},
);
// result.verified: boolean
// result.score: 0-100
// result.grade: 'A' | 'B' | 'C' | 'D' | 'F'
// result.paymentSignal: opaque token for TAP Payment Signals API
import { createAP2AgentCredential, verifyAP2AgentCredential } from '@bolyra/payment-protocols';
// Agent side: create credential
const credential = await createAP2AgentCredential(
humanIdentity,
agentCredential,
[
{ name: 'purchase', maxAmount: 50_000, currency: 'USD' },
{ name: 'price_compare', maxAmount: 0, currency: 'USD' },
],
);
// Merchant side: verify credential
const verification = await verifyAP2AgentCredential(credential);
// verification.verified: boolean
// verification.score: 0-100
import {
authContextToStripeACPContext,
verifyStripeACPSpend,
} from '@bolyra/payment-protocols';
import { verifyBundle } from '@bolyra/mcp';
// 1. Verify the v=2 bundle once (handshake + delegation chain).
const ctx = await verifyBundle(bundle, mcpConfig);
// 2. Reshape into a Stripe ACP context. The leaf delegatee becomes the
// acting agent; the root credential the human authorized stays as the
// originating agent for audit.
// rootAgentDid comes from ctx.did (set by verifyBundle from the verified
// credential commitment) — no caller-supplied root, no chain rebinding.
const acp = authContextToStripeACPContext(
ctx,
'base-sepolia', // DID network for actingAgentDid (must match ctx.did's network)
'usd', // ISO 4217 currency; lowercase per Stripe convention
);
// 3. Gate each PaymentIntent against the leaf-narrowed cap.
const decision = verifyStripeACPSpend(acp, 5_000, 'USD'); // $50
if (!decision.allowed) {
throw new Error(`Stripe ACP denied: ${decision.reason}`);
}
// Example: root had FINANCIAL_UNLIMITED, but the chain narrowed the leaf
// to FINANCIAL_SMALL. Stripe sees a $100 cap, not the root's authority.
// decision.tier === 'small'
// decision.capChecked === 10_000 // $100 in cents
import { encodeSpendPolicy, verifySpendPolicyProof } from '@bolyra/payment-protocols';
// Encode for ZKP circuit
const bitmask = encodeSpendPolicy({
maxTransactionAmount: 50_000,
maxCumulativeAmount: 100_000,
currency: 'USD',
timeWindow: { start: now, end: now + 86400 },
categoryRestriction: { allowedMCCs: ['5411', '5812'] },
});
// Merchant-side verification (from ZKP public signals)
const { satisfied, reasons } = verifySpendPolicyProof(bitmask, {
minTransactionAmount: 10_000,
requiredMCCs: ['5411'],
});
@bolyra/sdkApache-2.0 — open-source protocol research.
FAQs
ZKP privacy layer for Visa TAP and Google AP2 — Bolyra as the identity backbone for agentic commerce
We found that @bolyra/payment-protocols demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.