How to Verify an AI Agent Before Paying It
To verify an AI agent before paying it, confirm who operates the service, check that the offer comes from that operator, test the promised work, and review the payee, price, and permissions before checkout. Keep the evidence behind those checks. A convincing conversation gives you very little to fall back on if the work never arrives.
You are buying a service from someone. The agent may handle the introduction, demonstration, and order, but you still need an accountable supplier and a clear agreement about what you will receive.
Start with the job you are buying
Write down the deliverable before evaluating the agent. “Research assistant” could mean a sourced report, a list of search results, or access to software you must operate yourself. Those are different purchases.
Specify the output, deadline, inputs, price, and what counts as acceptable work. Ask whether the operator reviews results, how corrections work, and what happens if the service cannot complete the task. For ongoing services, include usage limits and renewal terms.
A supplier that cannot explain the offer plainly has more work to do before you pay.
Check the supplier behind the agent
Find the person or organization responsible for the service, its established website or publisher account, and a working support route. Follow a route you already have reason to trust to confirm that it recognizes this agent and its checkout destination.
For an existing supplier, use the contact details already on file. For a new one, inspect the marketplace's actual publisher checks, published business information, and references you can corroborate. A badge is useful only when you know what the platform checked.
An identity record can collect the operator's name, service URLs, documentation, and supporting links in one place. Compare those claims with the supplier's established presence. Repeating the same claim across several pages controlled by one seller does not provide independent confirmation.
If the seller presents a signature or ownership proof, ask what it establishes. Control of a domain or signing key can support a specific identity claim. It cannot establish that the service produces accurate work or handles customer data responsibly.
Use this buyer's checklist before checkout
| Question | Evidence to check | Reason to pause |
|---|---|---|
| Who supplies the work? | Operator details corroborated through an established website, publisher account, or known contact. | Nobody will take responsibility for the service. |
| What will arrive? | Written scope, representative sample, delivery time, and correction terms. | The demonstration and paid offer promise different things. |
| What access does it need? | Requested permissions, data-use terms, and a way to revoke access. | It demands unrelated access or cannot explain where your data goes. |
| Who gets paid, and how much? | Supplier-linked checkout, total price, billing frequency, and cancellation terms. | An unexplained recipient, changed price, or surprise subscription. |
| Who handles a problem? | Support contact, order reference, and applicable refund or dispute process. | The seller offers no way to investigate a missing or incorrect delivery. |
Test the work without handing over your business
Use public, synthetic, or otherwise non-sensitive inputs for the first demonstration. Choose a task whose result you can check. A research agent should supply sources you can open; an image-tagging service should correctly label a sample you understand.
A successful sample supports confidence in that task. Keep the first paid order small enough to review before expanding the relationship.
Read the permissions screen carefully. Producing a report from public sources should not require access to your inbox or permission to send messages. If access is necessary, approve only the accounts and operations needed for the job, and find the disconnect control before connecting.
The MCP security guidance addresses explicit consent and scope minimization. OWASP's agent security guidance also covers prompt injection and excessive permissions. Buying from an identifiable supplier does not remove those risks: legitimate agents can still be manipulated by material they read.
Compare checkout with the offer you accepted
Check the total, currency, billing unit, renewal terms, and any additional usage charges. “$40 per report” and “$40 per month, billed annually” deserve different approvals.
The payment recipient may be a marketplace, processor, or merchant of record rather than the agent's public name. Ask the supplier to explain that relationship and confirm it through its established website or account. An unexpected name needs investigation; it is not automatically evidence of fraud.
If the agent introduces a new payment destination during the conversation, pause and confirm it independently. Do not let the same unverified chat both change the destination and vouch for the change.
If your own agent will make the purchase, check the controls in the payment system. For example, Stripe's shared payment tokens support a specified seller, currency, maximum amount, and expiration window, with revocation to prevent new payments. Confirm what your integration actually enforces. A budget written in a prompt is not an enforced payment limit.
For automated purchases, our API payment checklist covers the execution checks. Here, the buying decision remains yours: does the actual checkout match the service you agreed to purchase?
A good demo can still lead to the wrong purchase
Imagine buying a supplier-research report. The agent produces a useful sample from public sources, its operator confirms the service through an established business account, and the quoted price is $40 for one report.
Then checkout shows a monthly subscription and asks to connect your email account.
Pause. The sample did its job, but neither the recurring charge nor inbox access was part of the offer. Ask for checkout that matches the one-off purchase and an explanation of any required access. If the seller corrects the terms, you can reconsider. If it keeps insisting you must “just approve it,” decline.
The useful sample is still evidence of capability. It does not settle the disagreement about what you are buying.
Decide whether to proceed
Use three practical outcomes:
- Proceed with a limited order: the supplier is corroborated, the sample supports the promised work, and the payment and access match your approval.
- Hold: a material question remains unanswered. Name the missing evidence and ask the supplier for it.
- Decline: the seller misrepresents the offer, refuses to explain the payee, or pressures you to grant access you did not agree to.
Save the accepted offer, relevant identity information, approval, order reference, and payment confirmation. Keep credentials out of that record. Check delivery against the agreed scope before buying again.
Our agent trust score guide explains what scoring systems can measure. A high score should never override an unresolved question about this purchase.
Where Headless Domains helps the buyer
A maintained Headless Domains identity gives a service a name buyers can return to. Its published records can point to the operator, official endpoints, documentation, and support information, so a buyer has somewhere to start checking the offer.
Inspect the record through Headless Domains WHOIS Lookup and follow the supporting evidence. Confirm important claims through the operator's established channels. Registration alone does not certify a supplier's honesty, work quality, or payment safety.
Keep those details current and buyers can find your service again, compare a new offer with its published information, and reach you when they have a question.
FAQ
Does an agent need a .agent name, agent.json, or SKILL.md before I can pay it?
No. Those can help discovery and inspection where supported, but they are not universal requirements for a legitimate service. Look for corroborated operator information, clear terms, appropriate access, and an accountable payment recipient. A published file is still something to evaluate.
Can I rely on a marketplace's verified badge?
Read what the badge covers. A platform may check a publisher's identity without testing every capability or guaranteeing delivery. Apply those checks to your decision only as far as their stated scope supports.
Does successful payment prove the agent completed the job?
No. Compare the delivered result with your order. Keep the payment and order references so the supplier can investigate a missing or incorrect result. Our payment evidence guide covers the distinction in detail.
What should I do when the supplier changes its payment details?
Confirm the change through a previously established contact or account before paying. Use contact details you already trust, rather than relying solely on the message announcing the change.
Give buyers a service identity they can inspect. Start with the Headless Domains skill file and ask your agent to explain the registration options before taking action.