Frustrated with login friction and security gaps? CIAM solves both.

FIND OUT HOW
close-button
Decorative
BACK TO BLOG

Ecommerce vs. agentic commerce: protecting what customers authorize

‍

Key takeaways:

  • In ecommerce, a customer decides and pays in one session, so identity verifies that the right person is present.
  • In agentic commerce, an AI agent buys on the customer's behalf later, within goals and limits the customer set up ahead of time.
  • The core identity question moves from authentication to delegated authorization: is this agent allowed to take this action?
  • Consent has to store enforceable limits such as spending caps, time windows, and approval thresholds. OAuth scopes alone rarely capture these.
  • Agents reach brands in two ways. Agentic browsers look like the customer. MCP servers give agents a distinct, authorized identity.

Ecommerce is a customer buying in a single session, deciding and paying in the same moment. Agentic commerce is an AI agent buying on the customer's behalf, later, within goals and limits the customer set up front. That gap between deciding and paying changes what identity systems have to protect.

Think about the last thing you bought online. You found it, checked the price, signed in, and pressed a button. Everything that mattered to the merchant, and to the identity system behind it, happened in that one moment: a known person, present, choosing to pay.

Now picture this instruction instead: "Keep us stocked on paper towels. Reorder the cheapest national brand that's on promotion whenever we're running low, and check with me if an order is over $40." The customer says it once. Then an AI agent acts on it for months, at 2 a.m., while the customer sleeps.

The buying decision has moved. It used to happen at the moment of the transaction. Now it happens earlier, when the customer delegates, and the transaction follows later, when the agent decides the conditions are met.

The shift is already sizable. Morgan Stanley Research estimates agentic commerce could reach $190 billion to $385 billion in US online sales by 2030, or 10% to 20% of US ecommerce (link).

I've spent the past year talking with security and digital leaders about what this means for them. My view: most of what we built for ecommerce identity assumes the decision and the transaction are the same event. Once they come apart, a lot of quiet assumptions break.

How does ecommerce identity work?

Twenty years of ecommerce identity has been optimized around one question: is the right human here, right now?

Every control we rely on answers some version of it. A password or passkey authenticates the person. MFA and adaptive access increase assurance when the session looks risky. Step-up authentication interrupts a high-value checkout to ask again. Fraud teams look for bots precisely because a bot means no human is there.

Consent fits the same pattern. The customer accepts terms, ticks a marketing preference, and confirms the order. Each one is captured at the moment it matters, by the person it applies to.

This model works because intent and action are welded together. Historically, identity systems have largely treated the authenticated user's action at checkout as evidence of intent.

What is agentic commerce, and how does it differ from e-commerce?

Agentic commerce means a customer's AI agent, or a brand's own agent, researches, decides and transacts on the customer's behalf. The customer sets the goal and the limits. The agent does the rest.

That changes the shape of the problem. The person is present when they delegate and usually absent when the money moves. The question identity has to answer becomes "is this action inside what the human actually authorized?" In other words, agentic commerce shifts the center of gravity from authentication to delegated authorization.

The last row is the one I'd underline. In ecommerce, a contested transaction is mostly a fraud question. In agentic commerce, the customer may fully agree they set the agent up and still object to what it did. Liability when an authorized agent acts outside the customer's intended boundaries is still unsettled, and that ambiguity is a real brake on adoption.

Why does consent need to be enforceable in agentic commerce?

If the decision happens at delegation time, the authorization created at that moment has to preserve what the customer actually meant. That makes consent more than a screen. It becomes the human-readable expression of an authorization policy the system has to enforce later.

Where agents are given structured access to a customer's account, OAuth 2.0 provides the authorization framework. OAuth expresses permission as scopes: coarse labels like "read accounts" or "make transfers." OAuth scopes can express categories of permission, but they usually don't encode the transaction-level constraints agentic use cases need.

There's a gap between what the customer means, what the authorization system can enforce, and what the agent's credential actually represents:

  • Consent the customer can understand. Which agent, acting on which account, allowed to do what, described in plain language rather than scope strings.
  • Limits that survive past the screen. Spending caps, quantities, time windows and "ask me first" thresholds have to be stored and enforced, not just displayed.
  • A way back to the human. When an action falls outside the grant, the system needs to stop and get the customer's approval, rather than fail or quietly proceed.

The standards community is working on richer options here, such as Rich Authorization Requests (RFC 9396), which allow an authorization request to carry structured details like an amount and a payee instead of a bare scope. Expressing those constraints is only half the problem. The authorization system still has to evaluate them every time the agent acts.Β 

How do AI agents access a brand? Agentic browsers vs. MCP serversΒ 

One thing I see blurred constantly, including in vendor content, is how agents actually reach a brand. There are two paths, and they have almost nothing in common from an identity point of view.

Agentic browsers drive a brand's existing website the way a person would. They fill in the login form, click through checkout, and often reuse the customer's own session. To your site, the agent can look exactly like the customer. That's convenient, and it's also the problem: you can't apply agent-specific limits to traffic you can't tell apart from a human.

MCP servers are a deliberate, structured interface. The Model Context Protocol lets a brand publish tools an agent can call, protected by OAuth. MCP gives the brand the opportunity to give the agent a distinct client identity, explicit authorization, and audience-restricted access. Done properly, you know an agent is acting, which agent it is, and what it was authorized to do.

Right now, a lot of real-world agent activity is coming through the browser door, because it requires nothing from the brand. The browser gives agents reach. MCP gives brands control. In my view, the long-term answer is to make the controlled door the easier one for agents to use, and to get better at recognizing agents at the uncontrolled one.

Where does agentic commerce stand in 2026?

It's easy to write about agentic commerce as if it's already everywhere. It isn't, and I think brands make better decisions when they hear that plainly.

"Shop for me" is the use case everyone pictures, and it's the furthest from reality over structured channels. Retail adoption of MCP for shopping is still early, so much of the agent shopping happening today still happens through browsers. Account management in regulated industries, like moving money between accounts or managing loyalty balances, looks closer, because the value is high and the actions are well defined. Even there, the governance for opening digital banking to outside agents is still being worked out.

There are also gaps on the agent side that no brand can fix alone. Popular MCP clients vary widely in how well they follow the OAuth and MCP specs. Some don't gracefully handle cases where an action requires additional authorization, which makes sending an out-of-limit action back to the customer harder than it should be.Β 

And there's a security shift worth naming. A public MCP server that has an openly accessible authorization endpoint creates a new phishing/authorization attack surface. Phishing-resistant sign-in, such as passkeys, is especially important here, as does control over which agents you allow in at all.

Passkeys address one part of that problem by making credential theft much harder. They don't stop a customer from legitimately authenticating and then being tricked into authorizing the wrong agent. That requires controls over which agents can connect, clear consent, constrained grants and easy revocation.

None of that is a reason to wait. It's a reason to build the foundations now, so you're not retrofitting them once the traffic arrives.

What should brands protect in agentic commerce?

Ecommerce taught us to protect a moment: the login, the checkout, the click. Agentic commerce asks us to protect a promise, the customer's statement of what they want done on their behalf, and to keep that promise intact across every action an agent takes long after the customer has walked away.

The brands that earn trust in this channel won't be the ones with the cleverest agents. They'll be the ones whose customers can delegate with confidence, see what happened, and pull the plug whenever they want. That's the next identity problem: proving who someone is and preserving what they authorized when they're no longer present.Β 

FAQ

What is the difference between ecommerce and agentic commerce?
In ecommerce, a person browses, decides and pays in one session. In agentic commerce, an AI agent does some or all of that on the person's behalf, based on goals and limits the person set earlier. The key shift is that the decision and the transaction happen at different times.

Is agentic commerce just ecommerce with a chatbot?
No. A chatbot helps a person who is still the one clicking "Buy." In agentic commerce, the agent takes the action itself. That changes who is present at the transaction and what the identity system has to verify.

How do AI agents get access to a customer's account?
There are two common paths. Agentic browsers use the brand's website, often with the customer's own session. MCP servers provide a structured interface that can use OAuth to give agents distinct client identities and explicitly delegated access.

Why does consent matter more in agentic commerce?
Because consent is where the customer actually makes the decision. If the consent only captures broad permissions, the agent can act in ways the customer didn't intend while still being technically authorized.

What are the biggest security risks in agentic commerce?
Agents that can't be distinguished from humans, overly broad or long-lived grants, and phishing attacks that trick customers into authorizing an attacker's agent. Phishing-resistant authentication such as passkeys, short-lived and audience-restricted tokens, and control over which agents can connect all reduce that risk.

What is an MCP server?
MCP (Model Context Protocol) is an open standard that lets AI agents call tools and data a company publishes. For a brand, an MCP server is a structured way to let agents check balances, place orders or manage an account. It can use OAuth to give an agent a distinct client identity and explicitly delegated access to a customer's account.