HappycapyGuide

This article contains affiliate links. We may earn a commission at no extra cost to you if you sign up through our links.

Agentic Commerce

Sam Altman's World Launches AgentKit: Iris Scans Are Now 'Power of Attorney' for AI Shopping Agents

March 30, 2026  ·  Happycapy Guide

TL;DR
On March 17, 2026, World — Sam Altman's identity company that scans your iris to prove you are human — launched AgentKit. It is a developer tool that lets merchants cryptographically verify that the AI agent placing an order is acting on behalf of a real, verified human. Built on World ID and Coinbase's x402 payment protocol, it solves the core trust problem of agentic commerce: when a bot buys something, how does the seller know a real person authorized it?
1 iris
scan needed to create a World ID credential
x402
Coinbase + Cloudflare protocol for automated agent payments
3
major platforms building agentic commerce (Amazon, Mastercard, Google)
Mar 17
AgentKit beta launch date — 2 weeks ago

The Problem AgentKit Is Solving

AI shopping agents are already a reality. Amazon Rufus suggests and re-orders products autonomously. ChatGPT's Operator browses e-commerce sites and adds items to carts. Visa's Trusted Agent Protocol lets AI initiate payments with stored credentials. Google and Mastercard are building their own agentic checkout flows.

But every merchant enabling these systems faces the same question: when an AI agent places an order, is a real human behind it — or is it one of the millions of bots that now make up 50% of internet traffic? (HUMAN Security's March 26 report found AI bot traffic grew 7,851% in 2025 alone.)

Without an answer, merchants risk:

World's AgentKit is the first production tool designed to solve this problem at the infrastructure level rather than with band-aid CAPTCHA or IP-blocking measures.

How AgentKit Works

The system has three components that work together:

1. World ID — The Iris Credential

World ID is generated by scanning a user's iris with World's Orb device — a silver sphere about the size of a bowling ball that uses near-infrared imaging to capture the unique pattern of your iris. The scan is converted into an encrypted digital code. World does not store the raw image; it stores only the encrypted mathematical representation. The resulting credential is a zero-knowledge proof that you are a unique human — verifiable without revealing who you are or any other personal data.

2. x402 Protocol — The Payment Layer

The x402 protocol, developed by Coinbase and Cloudflare, uses HTTP status code 402 (“Payment Required”) as a machine-readable signal for automated micropayments. When an AI agent hits a 402 response, it knows it needs to initiate a payment before the request will be fulfilled — no human needs to open a wallet or click a “pay” button. This is the plumbing that allows AI agents to transact programmatically across the web.

3. AgentKit — The Trust Bridge

AgentKit connects World ID to x402. When a merchant using AgentKit receives an agent-initiated transaction, it can request a World ID proof alongside the payment. If the agent can produce it, the merchant knows: (a) a real human exists behind this agent, (b) that human has explicitly delegated authority to this agent, and (c) no other agent is using the same human's identity. TFH CPO Tiago Sada describes it as giving the agent “power of attorney” — the agent acts, but a verified human is legally and cryptographically accountable.

User scans iris → World IDUser authorizes agentAgent shops with x402Merchant verifies World ID proofOrder confirmed
Try Happycapy — your AI agent for agentic commerce, from $17/mo

Why This Matters Beyond Shopping

AgentKit is being positioned as a shopping tool, but the underlying infrastructure — a cryptographic proof that a specific human authorized a specific agent action — has much broader implications:

Agentic Commerce: Who Is Building What

CompanyAgentic Commerce FeatureIdentity VerificationStatus
World (Sam Altman)AgentKit — iris-based human verification for agent purchasesWorld ID (iris scan)Beta — March 17, 2026
VisaTrusted Agent Protocol — AI initiates payments with stored card credentialsAccount-level onlyLive
AmazonRufus AI — autonomous product suggestions and reordersAmazon accountLive
MastercardAgent Pay — programmable card rails for AI checkoutCard network identityPiloting
GoogleGemini Shopping — agent-driven product search and checkoutGoogle accountLive
HappycapyBrowser skills for research and shopping workflowsAccount-linkedLive — Pro plan
The criticism: World has faced significant scrutiny over its iris-scanning model, with privacy advocates raising concerns about biometric data collection, Orb device deployment in lower-income countries, and the risks of a single company controlling a global biometric identity database. AgentKit inherits these concerns. The tradeoff World is proposing is explicit: give us your iris scan once, and your AI agents earn trust on the internet. Whether that exchange is worth it will be a central debate of the agentic commerce era.

Frequently Asked Questions

What is World AgentKit?

AgentKit is a beta developer tool launched by World on March 17, 2026. It combines World ID — a biometric credential from scanning a user's iris with World's Orb device — with the x402 protocol, an open standard for automated micropayments from Coinbase and Cloudflare. The result lets websites cryptographically verify that an AI agent placing an order is acting on behalf of a real, verified human.

What is the x402 protocol?

x402 is an open standard for automated micropayments built by Coinbase and Cloudflare. It uses HTTP status code 402 (“Payment Required”) as a machine-readable signal that enables AI agents to initiate payments programmatically without human intervention at checkout. World's AgentKit extends x402 with identity verification alongside payment.

Do I need to scan my iris to use AI shopping agents?

Only if a specific merchant requires World ID verification through AgentKit. As of March 2026, AgentKit is in beta and merchant adoption is not yet widespread. For most AI agent tools today — including Happycapy — you can use agentic shopping and browsing features without an iris scan. AgentKit is an optional trust layer designed for high-stakes or high-volume transactions where merchants want to enforce per-human limits and prevent bot fraud.

What is the Sybil problem in AI agents?

The Sybil problem is the ability of one bad actor to create many fake identities that all appear to be distinct individuals. In agentic commerce, a scalper could deploy thousands of bots — each with a different wallet — to buy limited-stock items before real humans can. World's AgentKit solves this by linking each agent back to a single iris scan, making it impossible for one person to create multiple verified human identities.

Happycapy Pro — Claude-powered agents you control, from $17/mo
Sources
SharePost on XLinkedIn
Was this helpful?
Comments

Comments are coming soon.