EMVCo's draft framework uses Verifiable Intent to make a consumer's approval provable. A checkout mandate covers what is bought; a payment mandate covers how it is paid. Open mandates set limits for an agent, closed ones hold final values. Up to three signed layers link the card issuer, the consumer and the agent, and each party sees only what it needs.
A mandate is a structured record of what the consumer approved. VI uses two kinds, each shown to a different party:
The two form a Mandate Pair. They are shown to different parties but share a common reference, so each party can confirm it is looking at the same transaction without seeing the other half.
A mandate is either open or closed, and this maps to the two execution modes.
When the agent pays, verifiers check that the closed mandate falls within the open one.
Open mandates carry constraints. The framework describes two families:
Per-transaction limits can be checked on the spot. A total budget needs a running total, which the framework says is typically kept by the payment system.
VI builds each approval as a chain of up to three signed credentials:
Each layer is tied to the one above, so a credential cannot be lifted out and reused elsewhere.
VI uses selective disclosure: each party receives only the parts relevant to its role. The merchant sees what was bought, not how it was paid. The payment side sees the payment details, not the cart. If a consumer approved several possible merchants, the agent reveals only the one it used.
The framework describes two points where payment is tied to checkout. At approval time, the payment mandate references the checkout mandate the consumer approved. At purchase time, both mandates carry the same reference derived from the merchant-signed cart. If the cart changes after the merchant signed it, the reference no longer matches.