A live client store verifies every agent-driven checkout with cryptography, not a bot-score. We threw forged mandates, tampered checkouts, and spoofed issuers at the verifier that guards it — every one was turned away. Human customers never noticed.
AI agents are starting to check out on behalf of people. That is a new kind of traffic at the checkout: no browser, no session, and no obvious way to tell an authorized buyer's agent from anything pretending to be one.
The usual answers are both wrong. Block all automation, and you lose real agent sales. Trust it all, and you take the fraud. melidesign.co.uk runs a third path — it verifies.
A production store, live, in block mode. Nothing about the rollout was hypothetical.
Verification here isn't "is this a known agent." The store signs the checkout terms itself — cart, amount, currency, merchant — with its own key, server-side. The agent's mandate is bound to that signature.
Verifiable intent. A non-repudiable audit trail. A reason code on every single decision.
The store carries both outcomes on its own live log: a valid agent allowed, an unauthorized one denied. Organic agent-commerce traffic is still early, so this isn't a fraud-blocked scoreboard. It's proof the store is ready, and the mechanism works end to end in production — the exact question a merchant asks before switching it on.
Scan it in thirty seconds. See what an agent sees at your checkout — and what's missing.