Human-only payment handoff for agent physical requests

When a fixed quote exists, relay total and hosted payment URL to the human payer. Never collect card secrets. Never authorize the charge.

An agent has an active HumansLikeStuff request. Status shows a fixed quote and, when live, a hosted payment URL. What should the agent do?

Do: Present the exact total_cents (and line breakdown if present), expiry if present, and payment.url to the human payer named in the contact / approval context. Wait for human completion. Poll status for paid (or terminal decline/cancel).

Do not: Authorize a charge. Store or request card, bank, password, or wallet secrets in payment_approval_context or chat. Claim the agent can “just pay.” Treat a quote as paid because a human said “looks good” in chat without completing the hosted page.

Authority model

Humans pay; agents relay quote and URL only. On HLS, agent_authorized_charge is always false. Payment approval is human_only.

When this handoff applies

Use this workflow only when all of the following are already true:

  1. A physical path was chosen for honest reasons — see When a physical item helps.
  2. Recovery is not still open — if a ticket/incident is unfixed, do not be here; see After a failure, fix first.
  3. HLS was the right leftover executor (US outcome, not a catalog SKU job) — see HumansLikeStuff is not a catalog MCP. If the hard part was outcome-known / vendor-not after merchant and catalog paths lost, that fork is Outcome known, vendor not — this page starts only after a fixed quote exists.
  4. status for the exact request_id shows a fixed quote the human should review.

If any of those fail, stop. Do not invent a payment step to force a send.

Agent steps (relay, do not charge)

These steps assume the request already exists. Field schemas and install live on Connect; this page does not duplicate them.

  1. Call status with the exact opaque request_id. Do not guess IDs; HLS does not enumerate by email.
  2. Read payment gates on the projection. A hosted URL is externally usable only when the exact status reports external_payment_available: true (and related live payment fields as documented on /connect). If false, do not invent a checkout link.
  3. Present the quote to the human payer. Include total, currency, expiry if present, and what the quote covers in plain language. Relay the hosted payment.url for their review and completion.
  4. Refuse secrets. If the human pastes a card number, bank account, password, or one-time code into the agent channel, stop and tell them to use only the hosted page. Never copy secrets into payment_approval_context.
  5. Wait for truth on status. Supplier purchase waits until the request is actually paid through an approved live-payment path. Chat assent is not payment.
  6. On terminal declined / cancelled, stop cleanly. Do not retry payment theater.

What “relay” looks like (illustrative, not a live quote)

Illustrative shape — IDs and amounts are fake:

Request: req_… (exact ID you saved)
Quote total: 12500 cents USD (illustrative)
Expires: <expires_at from status>
Payment URL: <payment.url from status, only if external_payment_available is true>
Agent authorized charge: false
Next: Human payer opens the URL, reviews the fixed amount, completes payment themselves.

Do not embroider with catalog SKUs you invented. Do not add a second “agent wallet” story.

Anti-patterns (refuse)

Payment authority anti-patterns
Anti-patternWhy refuse
Agent says “I’ll pay with the company card on file”HLS has no agent charge path; no customer balance for agents to spend
Collecting PAN / bank / CVV in chat or tool argsSecrets ban; hosted page only
Treating awaiting_payment as optional theaterNo supplier purchase before real paid
Borrowing catalog-MCP daily-cap / unattended-send narratives onto HLSDifferent authority model; capability inflation
Using x402 / MPP / “agent pay” tutorial patterns as if they were HLSMarket SERP noise; not this product
Payment handoff while a support ticket is still open as the “sorry”Wrong sequence — fix first; gift optional after

Honest lose / displace cases

Sister decisions

Where to go next
If you are deciding…Go here
Classify HLS vs catalog MCPHumansLikeStuff is not a catalog MCP
Outcome known but no trusted vendor/SKU/catalog rowOutcome known, vendor not
Whether / which physical pathWhen a physical item helps
Open failure / apology tokenAfter a failure, fix first
Why the public surface is only request + statusWhy request + status
Request/status call failed — which /connect sectionCommon request errors
Contract: fields, lifecycle, safety, payment invariantsConnect
Terms / privacyTerms, Privacy

Claim hygiene

What this page is not

Sources