Platform
Platform
Drop-In Authentication
Passkeys
Phishing-resistant, FIDO2/WebAuthn
Biometric authentication
Face and device-native biometrics
WhatsApp OTP
Global reach, lower cost than SMS
Email OTP
Universal second factor
App push authentication
Native device push notifications
Palm biometrics
Contactless identity verification
KEY FEATURES
No-code rules engine
Step-up auth, risk policies, alerts
User observability
Audit trails, dynamic linking
Risk-based authentication
Adaptive MFA by context
Session management
Persistent sessions across channels
Digital Credential Verification
Accept and verify digital IDs
Pre-built UI
Fastest deployment path
Digital Credentials Verification
Accept and verify digital IDs
Solutions
Solutions
USE CASE
Account takeover prevention
Stop ATO without adding friction
Go passwordless
Replace passwords with passkeys
Call center authentication
Verify callers without KBA
SMS cost optimization
Cut OTP costs up to 90%
Existing apps
Add auth without re-architecting
Palm biometric payments
Contactless in-store payments
INDUSTRY
Financial services & banking
Secure high-value transactions
Healthcare
Authentication for ePHI access
Marketplaces & loyalty programs
Protect points and member accounts
Telecommunications
Secure subscriber accounts and channels
Government & public sector
Citizen identity and digital credentials
ROLE
Engineering
Fast integration, flexible SDKs
PricingCustomers
Resources
Resources
LEARN
Blog
Guides
Docs
COMPANY
About us
Why Authsignal
Partners
Careers
Security
Contact
INTEGRATIONS
Amazon Cognito
Auth0
Azure AD B2C
Duende IdentityServer
Keycloak
Salesforce
ServiceNow
WSO2 Identity Platform
View all integrations
Docs
Start free trial
Book a demoLogin
AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

Join us today!
Right icon
Blog
/
Current article
Digital Credentials
AI agents

Digital payment credentials: how verifiable trust could reshape payments

Breeze Challen
⬤
September 9, 2026
Share
Digital Payments

Online card authentication has traditionally been designed around a familiar interaction: a customer reaches checkout, presents a payment method and proves they are authorized to use it. That model is starting to stretch.

Payments now move through digital wallets, apps and an expanding range of online experiences. Agentic commerce adds another layer, with AI agents beginning to participate in transactions on behalf of consumers.

Against that backdrop, EMVCo is developing the Digital Payment Credential (DPC). EMVCo is the global technical body that creates and manages the EMV Specifications used to support secure, interoperable card-based payments worldwide. In June 2026, it released a draft Digital Payment Credential Schema Framework for public review.

DPCs point towards a payment model where authentication information can be packaged as verifiable proof and used across different parts of the payment ecosystem.

What is a Digital Payment Credential?

A Digital Payment Credential is a payment card-specific application of a verifiable digital credential (VDC).

Verifiable digital credentials are digital representations of trusted information that can be presented online or in person and verified cryptographically. EMVCo's DPC work applies this model to online card-based payment authentication.

The current work starts with the credential's schema: the data it contains and how that data is structured. That may sound like a narrow technical problem, but standardization matters. If different payment networks, wallets and verification systems represent the same payment information differently, the industry risks recreating the fragmentation that interoperability is meant to solve.

EMVCo is explicitly designing the DPC initiative around a common approach to credential provisioning, request and verification across those environments.

Payment authentication can move with the journey

Payment tokenization and EMV 3-D Secure already play established roles in securing online card payments, and Digital Payment Credentials are being developed alongside them.

DPCs introduce a different architectural possibility. Rather than designing authentication around each individual interface, trusted payment information could be presented and verified as the payment moves between environments.

For businesses designing payment experiences, that creates room to think differently about where authentication belongs.

A journey may start in one channel and finish in another, so authentication cannot stay fixed to a single step or interface. Risk, previous verification and transaction context should influence what happens next. Authentication then becomes an orchestration problem rather than a collection of individual challenges.

Done well, that should also improve the customer journey. Security should feel almost invisible when the available trust signals are sufficient, while stronger verification can appear only when the context or risk actually requires it.

Interoperability will decide how useful DPCs become

A new credential format alone does not simplify a payment experience. Its value comes from different participants being able to issue, request and verify it consistently.

EMVCo intends the DPC framework to address card payment authentication requirements as well as device binding, cross-domain usage and dynamic linking. It is also investigating future functionality for payment initiation.

That becomes more relevant as payments and digital identity begin to use more of the same concepts: wallets, verifiable credentials and cryptographic proof.

For product teams, the opportunity is less about adding another payment method and more about creating payment journeys flexible enough to work with portable forms of trust.

New channels make portable trust more valuable

Agentic commerce makes this direction particularly interesting.

EMVCo's separate Agentic Payments work is examining how card payments should establish consumer intent and delegated authority when an AI agent makes purchases on someone's behalf. Digital Payment Credentials do not solve that problem on their own, but they sit within the same broader move towards interoperable, verifiable payment interactions.

The DPC Schema Framework is still a draft, and the model will continue to develop. but the direction is already useful. Payment experiences are becoming less tied to a single checkout, device or channel, and authentication infrastructure needs to become flexible enough to move with them.

That means recognizing the trust already established, responding to context and risk, and avoiding a new standalone flow every time a new wallet, credential or verification method is introduced.

Businesses that design for this kind of orchestration will be better placed to adopt Digital Payment Credentials and whatever changes come next.

Question icon
Have a question?
Book a demo
NewsletterDemo PasskeysView docs
Digital Credentials
AI agents

You might also like

Digital identity credentials and passkeys: what businesses need to prepare for next
Digital IDs
Passkeys

Digital identity credentials and passkeys: what businesses need to prepare for next

August 28, 2026
Digital identity credentials are going global. Authsignal makes them drop-in.
Digital IDs

Digital identity credentials are going global. Authsignal makes them drop-in.

August 8, 2026
Hong Kong's SFC has told brokers and crypto platforms to drop OTP login
SMS OTP
Passkeys

Hong Kong's SFC has told brokers and crypto platforms to drop OTP login

August 5, 2026

Secure your customers’ accounts today with Authsignal

Passkey demoCreate free account
Authsignal Purple Logo

Authsignal is a drop-in authentication and orchestration layer for consumer-facing businesses. Passkeys, adaptive MFA, and omnichannel verification on top of your existing identity stack. Deployed in weeks, not quarters.

AICPA SOCFido Certified
LinkedInTwitter
Platform
Drop-In Authentication
PasskeysBiometric authenticationWhatsApp OTPEmail OTPApp push authenticationPalm biometricsSMS OTPEmail OTPMagic LinksAuthenticator apps (TOTP)
View all auth methods
KEY FEATURES
No-code rules engineUser observabilityRisk-based authenticationSession managementDigital Credential VerificationPre-built UI
Pricing
Customers
Solutions
USE CASE
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
Palm biometric payments
industry
Financial services
Government & Public Sector
Healthcare
Loyalty Programs & Marketplaces
Telecommunications
ROLE
Engineering
Docs
Compare
Twilio Verify vs AuthsignalAuth0 vs AuthsignalAWS Cognito vs Authsignal + AWS Cognito
Resources
LEARN
BlogGuidesDocs
COMPANY
About usWhy AuthsignalPartnersCareersSecurityContact
Integrations
Amazon Cognito
Auth0
Azure AD B2C
Duende IdentityServer
Keycloak
Salesforce
ServiceNow
WSO2 Identity Platform
View all integrations
United States
+1 214 974-4877
Australia
+61 387 715 810
New Zealand
+64 275 491 983
© 2026 Authsignal - All Rights Reserved
Terms of servicePrivacy policySecuritySystem statusCookies