# Giving AI a Credit Card Is Still Painful

## Executive summary

This video demonstrates the process of having an AI agent execute a real-world transaction—purchasing a course using a specialized 'agent card' from Mercury. The discussion highlights the security features of agent cards, such as scoped permissions and the ability for the agent to retrieve credentials via the Mercury API CLI. However, the demonstration repeatedly shows significant friction and failure points (e.g., invalid coupon codes, required billing addresses, and multiple authorization requests), concluding that the process is currently not a seamless or efficient user experience.

## Key takeaways

- Agent Card Functionality: Mercury agent cards are designed to be handled by AI agents for online purchases. They provide scoped permissions, meaning the agent can spend within a set limit but cannot create new cards or raise its own limits.
- Security Mechanism: The agent can retrieve card credentials (number, expiration date, security code) through the Mercury API CLI, which is presented as a more controlled method than simply providing raw card data.
- Friction in Execution: The attempt to purchase the course repeatedly fails due to technical hurdles, including incorrect coupon code formats, the requirement for a billing address (which defeats the purpose of the agent card), and multiple authorization requests, confirming that the current implementation is 'painful' and not seamless.

## Technical details

- Financial Automation & Security: The demonstration uses Mercury agent cards, which function like 'API keys with scoped permissions,' limiting the agent's blast radius. The process involves using the Mercury API CLI to authorize purchases, which is a key security feature.
- LLM Interaction and Workflow: The speaker prompts the AI agent to perform a multi-step task: researching the course, applying a coupon code ('Hamel Test'), and completing the purchase, simulating a complex, real-world workflow.
- Payment Processing: The transaction utilizes Stripe for payment processing, and the agent's actions are monitored, showing the successful $5 charge after overcoming multiple rejection points.

## Practical implications

- For build engineers, the video serves as a cautionary example of integrating AI agents into high-stakes, regulated systems (like finance). The friction points observed (address requirements, multiple approvals) highlight the need for robust, multi-layered error handling and explicit authorization flows.
- The concept of 'scoped permissions' is critical for designing secure automation, ensuring that even if an agent is compromised or misdirected, its actions are limited to a defined 'blast radius.'
- The difficulty in completing the purchase suggests that current agent-to-financial-service integrations require significant work to achieve a truly seamless user experience.

## Topics

AI Agents, LLM Integration, Financial Technology (FinTech), API Security, Automation Workflow, AI Evals October 2026 cohort, Isaac Flath Course

Source: https://www.youtube.com/watch?v=64iUD6g9dS0
