Sunday, August 2, 2026

— A weekly publication —

The Agentic Commerce Report

A weekly read of everything that moved in agentic commerce — protocols, payment rails, retailer pilots, regulation. Summarised, sourced, and stitched to what came before.

OpenID Foundation Opens Self-Certification for Agent Verifiable Credential Profiles

Issue 14February 23 – March 1, 2026Synthesised from 2 sources

Edited by Reviewed against primary sources

The OpenID Foundation opened a self-certification programme for implementers of its agent Verifiable Credential (VC) profiles this week 1, allowing vendors to certify conformance to the identity framework proposed in the October 2025 whitepaper. The certification process covers credential issuance, presentation, and revocation workflows. Certified implementations receive a conformance mark for use in procurement documentation.

The self-certification programme uses a test suite hosted by the OpenID Foundation covering the full credential lifecycle. Implementations that pass all mandatory test vectors receive certification; optional test vectors cover extended features including partial delegation and time-bounded credential scopes.

The VC self-certification programme operationalises the framework first published in the October 2025 whitepaper 2. That document proposed extending OAuth 2.0 for agent delegation; the certification programme provides a testable conformance surface for those extensions in deployed products. The gap between whitepaper and certification programme — five months — reflects a faster-than-typical standards maturation cycle for an identity framework.

Identity is the second lane to record a second event in this tracking period, following Payments. The VC certification provides the first independently verifiable compliance mechanism in the agent identity layer; prior protocol publications from Google, Mastercard, and Visa did not include certification programmes at launch.

Events this issue

2 events
AEO
research

IDC predicts agentic AI will redefine travel and hospitality across the full booking pipeline in 2026

IDC research frames 2026 as the pivotal year for agentic AI in travel and hospitality, with full pipeline deployment from discovery through post-trip loyalty management.

IDC's hospitality forecast establishes a demand-side analyst baseline before the major supply-side launches of Q2 2026. IDC identifies the end-to-end agentic pipeline as the 2026 differentiator: in 2025, AI assisted individual steps (search, recommendation, customer service); in 2026, agents are expected to orchestrate discovery, comparison, booking, payment, itinerary management, and post-trip loyalty redemption in an integrated flow without human handoffs. The hospitality sector's data richness — loyalty profiles, past stays, preference histories, seasonal pricing — provides agentic systems with unusually deep personalisation inputs relative to first-time retail purchases. IDC identifies this as the primary competitive moat for branded hotel chains over OTA intermediaries: a Marriott agent with five years of guest stay data will outperform a generic booking agent, creating an incentive for hotel brands to own agentic relationships rather than cede them to Google or Booking.com.

  1. IDC
Identity
spec

OpenID Foundation opens self-certification for Verifiable Credential specifications

Self-certification launches for OpenID4VP, OpenID4VCI, and HAIP 1.0, enabling wallets and issuers in 38 jurisdictions to validate compliance with the VC credential specs.

Self-certification is the operational step that turns OpenID4VP, OpenID4VCI, and HAIP 1.0 from drafts into testable production specs. The 38-jurisdiction scope is the broadest geographic baseline for any AI agent identity infrastructure in this archive, extending the OpenID Foundation's earlier AI agent identity whitepaper (2025-w41-identity-openid-foundation-ai-whitepaper). Verifiable Credentials provide the wallet-level credential primitive that Mastercard Agentic Tokens (2025-w18-payments-mastercard-agent-pay) and Google's AP2 Mandates (2025-w38-standards-google-ap2-protocol) compose with at the payment layer. The programme precedes the FIDO Alliance's Agentic Auth working group (2026-w18-standards-fido-agentic-working-groups) by two months, with FIDO citing both Google AP2 and Mastercard Verifiable Intent as backing implementations. The Identity lane's two-entry footprint underlines how thinly populated the non-payments identity layer remains.

  1. OpenID Foundation