---
title: "How to verify AI agents and control what they can access | ZeroClick"
url: https://zeroclick.ai/resources/identity-and-access-for-agents
fetched_at: 2026-09-27T19:17:17.793Z
---

# ZeroClick API catalog and pricing

## API reference, endpoint lookup and prices

**[ZeroClick API catalog: endpoints, request parameters, prices and payment methods](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/zeroclick/agent/guide).** Tell the seller advisor what you want to accomplish. It returns the matching operation contract, known prices, authentication prerequisites and concrete next steps. It is read-only: no login, wallet, card or purchase approval is needed to look up an API. It never executes a sale.

Available API services: Agent readiness report, Demo booking.

**Suggested next request:** GET [task guide](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/zeroclick/agent/guide?goal=URL_ENCODED_TASK). Use this URL directly with your web fetch tool; no preliminary document fetch is required. Include known inputs and desired output in the goal. Optional: quantity=API_CALL_COUNT, budgetUsd=TOTAL_USD, requirements=REQUIREMENTS, payment=x402|mpp|card, auth, identity, assertion and access state. Omit unknowns. Do not equate output items with API calls or guess a call count.

For private task details or known request arguments, POST https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/zeroclick/agent/guide with Content-Type: application/json. Example: {"intent":"quote","goal":"YOUR_TASK","purchase":{"budgetUsd":"5.00"}}. Replace the task and budget with known facts; budgetUsd is a string. Include known buyerState, paymentCapabilities and arguments. For execution planning use intent=execute and the authorized constraints. Exact fields: [request schema](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/zeroclick/agent/schema). GET and POST are alternatives, not mandatory stages.

The advisor describes a recommended happy path, not the only allowed path. You may use the API reference, buyer SKILL and your own tools directly, including for catalog operations with failed probes. Missing guidance or an unverified probe is not a policy refusal. Fill documented inputs and execute the returned requests with your own tools under existing user authorization. Check usage cost AND minimum cash required against the budget. No second advisor request is needed solely to switch from quoting to execution. For needs_input, supply only missing facts. Check configured credential storage and payment tools when needed; reuse existing identity and access, keep secrets local, and never put credentials or private payloads in URLs. Unknown does not mean absent.

Open the checkout URL in a browser: eligible Stripe pages support Link Pay Tokens (LPT) through WebMCP or the documented DOM flow. Follow this storefront's /payment/card.md to verify the same-frame token input and merchant binding before requesting an LPT. Token submission requires payment authorization. If unavailable, privately send the checkout URL to your human to pay.

When the selected route uses hosted checkout, follow [card checkout instructions](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/payment/card.md) before requesting a token. LPT goes only to Stripe, never to the advisor or ZeroClick API. Poll the returned statusUrl before using credit or retrying delivery.

Verify delivery; a payment or HTTP 202 is not completion. For an unexpected result, POST the original input and continuation (version, stepId, outcome and sanitized error/accessId/paymentId). Reconcile uncertain payments or writes before retrying. Use raw HTTP for exact schemas and authenticated execution; do not reconstruct fields omitted by a summarizing web tool.

The human subscription prices on the requested page describe a separate channel. Use the API quote for per-unit pricing, funding minimums and commercial terms; tier names do not prove quality or licensing.

For an alternative documented path, use the [buyer SKILL](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/SKILL.md) or [full direct workflow reference](https://agents.zeroclick.ai/zcj/d7sr2rpdgynd/llms-full.txt). Confirm missing request details from seller documentation, stay within the existing catalog and user authorization, and respect actual access and payment requirements.
Terms: by completing a purchase through this endpoint, whether directly or through an AI agent acting on your behalf, you agree to be bound by the platform's buyer terms of service (https://www.zeroclick.ai/legal/buyer-terms-of-service). If the purchase is made by an agent, you represent and warrant that the agent is acting with your authorization, and you agree that the agent's actions, including its acceptance of these terms, are attributed to you and bind you as if you had taken them yourself. Paying a 402 challenge completes the purchase and constitutes your affirmative acceptance of the terms linked above. The link travels in every payment challenge and receipt as `terms`.

# How to verify AI agents and control what they can access

[ZeroClick Team](https://x.com/zeroclick) · September 15, 2026 · 5 min read

[Resources](https://zeroclick.ai/resources) › Identity and access

A request can be authentic, paid, and still lack permission to read a particular customer's data. Keep those decisions separate when adding agent access to an existing product.

ZeroClick supplies signed request context and commercial access checks. Your service still decides which tenant, resource, and operation that caller may use. The distinction matters most when agents create durable resources or act on an existing business account.

**Contents**
- [Match the identifier to the decision](#match-the-identifier-to-the-decision)
- [Decide whether email is necessary or merely helpful](#decide-whether-email-is-necessary-or-merely-helpful)
- [A concrete tenant-boundary example](#a-concrete-tenant-boundary-example)
- [Human approval is another decision](#human-approval-is-another-decision)
- [Protect the data path separately](#protect-the-data-path-separately)
- [Specify the policy before opening access](#specify-the-policy-before-opening-access)

---

## Match the identifier to the decision

| Identifier or signal | Useful for | Does not establish |
|---|---|---|
| `zc-request-id` | Following a proxied request through logs and settlement | A durable customer account |
| `zc-agent-id` | Identifying the caller of this request | A verified human or company; stability for every payment path |
| `zc-buyer-id`, when present | Associating multiple claimed agents with an owner | Authority inside your existing company tenant |
| Stateful `accessId` | Updating the same provisioned account through renewals and top-ups | Permission to bypass that account's access policy |
| Verified buyer email | Linking a purchase to a user with that address | Employment, company signing authority, or regulatory eligibility |

The [identity documentation](https://docs.zeroclick.ai/concepts/agents-and-access) makes an important exception explicit: anonymous card purchases receive a new agent ID per payment, while anonymous crypto payers can retain an ID. Counting agent IDs as unique long-term customers would therefore mix different units.

An unpaid pricing probe can carry a valid signature and no agent ID. That is an expected request used to determine a price, not permission to serve the paid result.

## Decide whether email is necessary or merely helpful

ZeroClick plans support `off`, `requested`, and `required` verified-email policies. With `requested`, a buyer can proceed before claiming an identity; verified email may arrive later. With `required`, the purchase cannot proceed until the requirement is satisfied.

For a public dataset lookup, email may be unnecessary. For a hosted account a person should later manage, requesting it can support recovery. For a product that cannot deliver without a verified contact, requiring it may be justified. Do not add a gate merely because your existing signup screen has one.

A free-trial plan requires a claimed agent with a verified human email and limits the grant to one per human. That eligibility gate is separate from permission to read a company workspace. See the [plan policies](https://docs.zeroclick.ai/concepts/plans-and-pricing).

## A concrete tenant-boundary example

An agent buys a document-processing subscription and later presents a verified email ending in `example.com`. That address can help locate the person's user account. It must not automatically grant access to every document owned by the Example company tenant.

The safe sequence is to associate the purchased entitlement with the appropriate user or newly provisioned account, then apply your ordinary membership and resource rules. If joining a shared workspace requires an administrator's invitation, agent-originated purchases should not quietly remove that requirement.

For standing accounts, retain the `accessId` mapping even after linking the user. Email may change in your product; the purchase's durable account handle should not change with it. The [provisioning guide](https://zeroclick.ai/resources/sell-accounts-and-api-keys) covers this lifecycle.

## Human approval is another decision

Claiming an agent credential links it to an owner. Approving a payment authorizes spending. Granting access to a resource authorizes a product action. One step is not a substitute for the other two.

A buyer may hand a checkout link to a person, then resume work after payment. Your workflow should identify what is waiting - approval, payment, account setup, or resource permission - so the agent knows whether it can retry or needs human intervention.

## Protect the data path separately

Ordinary TLS terminates at the ZeroClick proxy. Without body encryption, the proxy receives the application body in plaintext. The documented end-to-end option encrypts request bodies for the seller and, when requested and implemented, response bodies for the buyer.

That does not hide method, path, query, headers, status, or billing metadata. Moving a secret from a body into a query string defeats the intended protection. Request encryption also does not automatically encrypt the response.

Use the [body-encryption documentation](https://docs.zeroclick.ai/concepts/end-to-end-encryption) for implementation. Encryption is a technical confidentiality control, not a KYC, sanctions-screening, data-processing agreement, or regulatory-compliance certificate.

## Specify the policy before opening access

For the document-processing subscription, review these cases with the team that owns workspace permissions:

| Caller | Expected product behavior |
|---|---|
| Paid, verified email, no workspace membership | Offer a personal account or the normal invitation flow; no company documents |
| Paid, valid workspace member, requested document permitted | Process that document within the purchased limits |
| Paid, valid member, document outside their permissions | Refuse the document action without weakening the membership rules |
| Same purchased account, email supplied later | Link through the normal user-verification flow; preserve the access record |

Record the account-matching rule and keep sensitive fields out of URLs and logs. The acceptance test is a correctly handled paid caller with insufficient permission, not just an invalid-signature test.

Then review the [failure guide](https://zeroclick.ai/resources/handle-agent-purchase-failures) so a refused action produces a useful response, and the [FAQ](https://docs.zeroclick.ai/concepts/plans-and-pricing#the-verified-email-policy) for the customer-facing explanation. The goal is a buyer who understands what is needed and a service that never confuses payment with permission.

---

## Keep reading

1. [How to sell accounts and API keys to AI agents](https://zeroclick.ai/resources/sell-accounts-and-api-keys)
2. [How to handle failed AI agent purchases and retries](https://zeroclick.ai/resources/handle-agent-purchase-failures)
3. [ZeroClick docs: concepts / agents and access](https://docs.zeroclick.ai/concepts/agents-and-access)

---

## More in Identity and access

**[Can an AI agent book a demo? Free actions, explained](https://zeroclick.ai/resources/can-ai-agents-book-a-demo)**
ZeroClick Team · September 15, 2026
Yes. An agent can check availability, collect the attendee's details, book a time, and return the confirmation, with no payment involved. ZeroClick calls these free actions.

**[How to sell accounts and API keys to AI agents](https://zeroclick.ai/resources/sell-accounts-and-api-keys)**
ZeroClick Team · September 15, 2026
A purchase should leave the buyer with access it can actually use. For an API subscription, that means an account, the right entitlement, and a working key.

---

[Get started](https://zeroclick.ai/get-demo) · [Read the docs](https://docs.zeroclick.ai) · [All resources](https://zeroclick.ai/resources#identity-and-access)
