Visa TAP.
- STATUS
- Testnet
- CRATE
- tenzro-payments
- STABILITY
- Beta
- REFERENCE
- Visa TAP
Model
TAP credentials authorize an agent to spend on a cardholder's account within a delegation scope. Issuance and verification flow through Visa's trusted agent registry.
Binding
On verify_credential, the binder enforces DelegationScope + SpendingPolicy. The Visa side sees an opaque agent id; Tenzro sees the underlying TDIP machine DID.
Signatures
A TAP credential carries two signature legs. The HTTP request itself is authenticated by an RFC 9421 HTTP Message Signature, which stays classical Ed25519 for relying-party interop. The Tenzro-native credential additionally carries a hybrid Ed25519 + ML-DSA-65 binding over the credential preimage, so the credential is post-quantum-bound without changing the RFC 9421 wire format.
Receipts
Settled TAP receipts are persisted in CF_SETTLEMENTS with the standard PaymentReceipt shape and a protocol = VisaTap discriminator.