The agent can propose.
It cannot authorize.
Trust Middleware turns an AI recommendation into a governed purchase intent. Watch trusted facts, deterministic policy, and human authority decide what reaches PayPal.
Policy holds the authority. AI only supplies the suggestion.
Live evaluation
Demo Airlines · NYC → SFO
One-way economy flight · 18 Jun 2027 · Demo Airlines 407
What the middleware verifies
System invariants
Agent has no payment credentials.
It can only submit a scoped intent.
Context can add friction, never authority.
A hard block stays a hard block.
Approvals are single-use.
They bind to exact facts, policy version, and expiry.
Every proposal gets a verdict.
Inspect the exact input, server-resolved facts, policy result, and payment state for each request.
Purchase intents
Demo Airlines · NYC → SFO
Nothing disappears after the verdict.
Decision inputs, policy versions, human approvals, and PayPal states are recorded as a traceable chain.
Authority has an API boundary.
The agent receives a proposal endpoint. Only an authenticated human can call the approval endpoint. PayPal credentials never cross this surface.
Recommendation is not authorization.
Every request arrives as a governed purchase intent. The middleware resolves facts from registered records, evaluates the active policy version, and returns a decision that downstream payment code cannot override.
POST /v1/purchase-intentsWhy this matters
A manipulated agent may still recommend the $3 fee. It cannot turn that recommendation into an order.