Skip to main content
Agentcard lets your agent shop with a user’s card through the Vault. The agent submits a placeholder card, the SDK pauses a supported payment request, and the user approves on their own device with a passkey. Their device sends the real card to the payment processor; the real card stays out of the agent’s task and browser.
Agentcard’s legacy wallet API is deprecated. New integrations should use the Vault flow below instead of the old agentcard_wallet_id integration. Vault attaches over CDP; it does not require a wallet ID on a Browser Use run.

What you need

  • A Browser Use API key in BROWSER_USE_API_KEY.
  • An Agentcard client_id and client_secret from the Agentcard dashboard, in AGENTCARD_CLIENT_ID and AGENTCARD_CLIENT_SECRET.
  • A user with a stored Vault card, and their user_id in AGENTCARD_USER_ID. See Adding a card.
  • Your own app function to deliver an approval link privately to that user.
Start with Agentcard sandbox credentials and its demo store. Validate the intended merchant and payment processor before using real cards.

Attach Vault before shopping

Install the Node packages alongside your app:
Create a standalone Browser Use browser, connect over its cdpUrl, and attach Agentcard before the agent reaches the payment form. Browser Use supports multiple CDP connections to the same browser.
syncRegistry() loads Agentcard’s supported payment recognizers. Keep this Node process and its Playwright connection running throughout shopping and approval. This example attaches to one page: use that same tab for checkout. If your agent opens another tab, attach Agentcard to it and await attachment before allowing checkout there. Send onApprovalUrl links through your own authenticated app or private user channel. Keep approval links, real card details, client secrets, and CDP URLs out of logs and agent task text. Only the cardholder should open the approval link.

Connect the open-source Python agent

Install the separate open-source library with pip install browser-use. Pass the session.cdpUrl above to your Python process securely as BROWSER_USE_CDP_URL. Configure llm as in the open-source quickstart.
Give the agent a placeholder from Stripe’s published test cards, a future expiry, and a test CVC. Tell it to use the attached tab, click Pay once, and wait for the cardholder’s approval and the merchant’s confirmation without submitting again. Never put the real card or approval link in task.

Confirm the order and stop the browser

User approval is not proof that the merchant created an order. Verify the merchant’s confirmation page or API and follow Agentcard’s purchase reconciliation guide. If the result is pending or unknown, preserve the browser for follow-up and reconcile before retrying payment. keep_alive=True leaves the browser available after the Python agent finishes. Once the order is confirmed and no follow-up is needed, stop the owned browser from your Node app:
Stop the browser on setup failure or abandonment too, once you have established that no payment or user action is pending. Closing the Playwright connection alone does not stop billing for the cloud browser.

Hosted agents and full guide

For Browser Use hosted agents, see Agentcard’s Browser Use integration guide. A hosted run starts executing when created. Attach Vault before the shopping task begins, and account for session expiry or browser replacement. Observing a dispatch event and then cancelling is not a synchronous gate before the agent’s first action. The Vault quickstart covers card enrollment, approval, and the complete purchase flow.