# AFSP: Agentic Financial Services Protocol (full summary for agents) Source: AFSP Specification v0.1, Public Review Draft, published September 28, 2026 by Primitive. Authoritative document: https://agenticfinanceprotocol.org/spec/AFSP-v0.1-Public-Review-Draft.pdf This summary is non-normative. Where it differs from the specification, the specification governs. Cite section numbers from the PDF. ## What AFSP is AFSP is an open industry protocol for the moment an AI agent arrives at a regulated financial institution on behalf of a person. Before the agent reaches the institution's systems, AFSP lets the institution verify who the agent is, who it is acting for, and that the person is present and in control. AFSP governs one question only: should this AI agent session proceed to the open banking API layer? (Section 1.1) AFSP does not govern what happens after that decision. OAuth authorization, identity verification, KYC, credit underwriting and account-opening decisions remain with the receiving financial institution. Version 0.1 covers one use case: agent-assisted opening of a new deposit account. Existing standards (OAuth 2.0, FAPI 2.0, FDX, FIDO) assume a relationship already exists. AFSP governs the pre-credential moment, when an agent asks a bank to begin a relationship for someone the bank has never met. It is designed to complement those standards and Section 1033 of the Dodd-Frank Act, not replace them. ## What AFSP is not (Section 1.4) - Not a model. It delivers attested trust signals; each institution decides whether and how to use them. - Not a fraud score. Signal 5 estimates whether a session is human-operated in a normal manner. - Not a replacement for KYC. The institution keeps full KYC accountability. - The agent does not choose for the consumer. It presents offers ranked by the published FitScore formula; the consumer decides. Principle: the agent presents, the human decides, the bank executes. ## The five trust signals (Section 1.1, Section 3.3) | Signal | Question | What it verifies | Status | |---|---|---|---| | S1 Agent provenance | Who is this agent? | A certified, registered, unmodified build from an accountable operator | Mandatory | | S2 Biometric consent | On whose behalf, and did they authorize it? | A real human, on their enrolled device, explicitly authorized this session | Mandatory | | S3 Federated referral | Has their identity been verified? | A trusted network institution has previously completed KYC on this consumer (attestation only, no raw data) | Optional | | S4 Financial identity | Are they financially real? | Behavioral financial signals consistent with an established profile, derived from Section 1033-permissioned data | Mandatory for marketplace sessions | | S5 Session integrity | Are they present right now? | The session is human-operated within normal behavioral parameters | Conditional | A package missing a valid S1, S2 or S4 is rejected. A missing S3 or S5 is noted in `signals_present` and handled by the institution's own risk framework, not automatic rejection. Under the Non-Decline Principle (Section 1.5), an S5 anomaly SHALL NOT be automatically declined; it is routed to human reauthorization, step-up verification or review. ## The PCAA package (Section 6) PCAA stands for Pre-Credential Agent Attestation. It is a signed JSON object assembled by the AFSP platform containing the five signals. Key properties: - Signed with ECDSA-P256 by the AFSP platform. - Bound to a single receiving institution by an institution-specific nonce, added only when the consumer selects that institution. A package bound to one institution is unusable at another. - Validity window of at most 3600 seconds; nonce expiry at most 1800 seconds after assembly. Each package_id is single-use. - Institutions validate it with requirements VAL-01 to VAL-10 (platform signature, institution binding, validity window, replay check, nonce, agent registry signature, build hash, consumer token signature, scope and tier, S4 and S5 provider signatures). - The package is assembled within 1 second, with signals assembled in parallel (Section 14.2). ## v0.1 components (Section 2) - AFSP-01 Consumer Authorization and Biometric Binding (S1, S2). The biometric never leaves the consumer's device TEE; tokens are signed by a hardware-held key. - AFSP-02 Financial Profile Attestation (S4). A six-stage privacy-preserving pipeline; free-text fields are stripped; differential privacy (epsilon 1.0, k-anonymity k=5); raw data is zeroized within 30 seconds. - AFSP-03 Reverse Inquiry Protocol and Fit-Based Marketplace (S3, S4). Anonymous inquiry; offers ranked by the published FitScore formula; no paid ranking. - AFSP-04 Clearance Return Protocol and Session Token (all signals). The institution returns PROCEED_TO_KYC, REQUEST_ADDITIONAL_VERIFICATION or DECLINE_SESSION; a single-use session token (max 1800 seconds) is minted only on PROCEED_TO_KYC; a tamper-evident audit record is kept for at least seven years. - AFSP-05 Behavioral Session Intelligence Interface (S5). A vendor-agnostic session-initiation score. - AFSP-06 Non-Participant Disclosure Standard. Factual disclosure when a named institution is not in the network, with three consumer routing options. ## v1.0 roadmap components (Section 16), not part of v0.1 - AFSP-07 Agent Provenance and Certification Registry - AFSP-08 Federated Credential Verification - AFSP-09 Pre-Execution Revalidation Protocol - AFSP-10 Behavioral Envelope Engine (moment-level) - AFSP-11 Tamper-Evident Regulatory Audit Log - AFSP-12 Post-Opening Session Continuity ## Authorization tiers and action classes (Section 7.4) Registered action classes: READ, DISCOVER, PRESENT, INITIATE, EXECUTE. - Tier 1 (READ, DISCOVER, PRESENT): information only; no identity disclosed. - Tier 2 (INITIATE): begins account opening at the selected institution; requires biometric reconfirmation plus an Intent Verification Checkpoint (IVC). - Tier 3 (EXECUTE): completes opening and funding; requires biometric reconfirmation, IVC with funding parameters, and PROCEED_TO_KYC clearance. Each tier has its own hardware-held key with a tier-specific Extended Key Usage; verifiers reject out-of-tier signatures (VAL-08a). The IVC (Section 5.8) shows the consumer a plain-language summary generated from structured fields, not from model output, before any Tier 2 or Tier 3 payload is signed. This defends against prompt injection that redirects an action. ## Consumer protections - Default scope: an inquiry goes only to institutions the consumer already banks with. Expanding to all network participants requires a biometric-signed scope expansion token, valid for that session only (Section 9.2). - No personally identifying information is sent in the reverse inquiry. Identity goes to one institution only, after selection and PROCEED_TO_KYC. - The AFSP platform is absent from KYC and does not receive KYC data (Section 10.1). - Consumer disclosure requirements CD-1 to CD-8 (Section 5.9) cover authorization, inquiry scope, ranking and compensation, offer terms, account-opening confirmation, outcomes, data use, and revocation. ## Worked example (Appendix A, non-normative, illustrative values) A consumer, Alice, asks her AI assistant for a high-yield savings account (APY above 4.5%, no monthly fees, minimum balance under $500). 1. Discovery: the assistant checks its AFSP tool registration and the Discovery Declaration of Alice's bank. 2. Authorization: Alice authenticates with Face ID; her device's TEE signs the authorization token. She expands scope with a second Face ID. 3. Attestation: S4 and S5 are assembled in parallel with S1 and S2; the platform assembles and holds the PCAA package. 4. Inquiry: seven institutions receive the anonymous reverse inquiry and respond within 800ms; offers are ranked by FitScore. 5. Selection and clearance: Alice selects Sunrise Digital Bank (5.10% APY), confirms the IVC summary and completes a Face ID step-up. The bound package is delivered, and the bank returns PROCEED_TO_KYC in 180ms. A session token is minted. 6. Account opening: KYC runs in the bank's own interface in about 100 seconds; the account opens and the Return Trip API reports OPENED. Total elapsed time from authorization to account open: 2 minutes, 50 seconds. ## Roles (Section 1.6) - Consumer: the sovereign authority; authorizes each session and makes every consequential decision. - Consumer Layer Operator (CLO): AI platforms, bank-embedded assistants, widgets and core-banking platforms that present sessions and run the consumer's authorization. - Agent operator: develops or operates the AI agent; certifies its build. - Signal providers: certified providers of S4 and S5 attestations. - AFSP platform: assembles PCAA packages, operates the agent certification registry and the initial marketplace. Operated by Primitive in v0.1. - Receiving institutions: banks and credit unions; make every decision on whether a session proceeds, on KYC and on account opening. - AFSP Foundation: independent non-profit, targeted for early 2027; will govern the specification, run the working groups, and administer certification and the participation registry. ## Governance, licensing and IP (Sections 17.1, 17.5) - AFSP is open governance, not open source. The specification is public and free to read, reproduce and comment on. - Primitive (CiDR Technologies, Inc. D/B/A Primitive) is the founding author and interim protocol administrator. It holds provisional patent applications on the underlying mechanisms and commits to license essential claims on fair, reasonable and non-discriminatory (FRAND) terms, with terms published before v1.0. - Institutions sign a Network Participation Agreement with the Foundation (certification) and, for platform services, a Platform Access Agreement with Primitive. Institutions may use AFSP in their own branded channels without routing to any marketplace. - Participation levels (Section 14.1): Level 1 Founding Endorser (letter plus working-group commitment, no implementation required), Level 2 Certified Implementation Partner, Level 3 Active Network Participant. ## Status and timeline - v0.1 Public Review Draft: published September 28, 2026. - Public comment closes November 16, 2026. Founding Endorsers will be announced before then. - Working groups begin November 2026. - First proofs of concept targeted for Q1 2027. - AFSP Foundation targeted for early 2027. - Not yet included in v0.1: the protocol binding (transport, endpoints, message formats), a reference implementation and conformance tests. Open items are listed in Section 18. ## How to engage - Read: https://agenticfinanceprotocol.org/spec/AFSP-v0.1-Public-Review-Draft.pdf - Comment publicly: https://github.com/primitive-os/AFSP/issues/new?template=spec-comment.yml - Propose an extension: https://github.com/primitive-os/AFSP/issues/new?template=extension-proposal.yml - Confidential comments, endorsement or working groups: afsp@primitive.com