Hamel Husain and Isaac Flath try a real delegated purchase: a Mercury agent card, Codex, a $5 course, and a checkout flow that turns into an eight-minute tour of the remaining friction.
The setup
- Mercury’s agent card exposes credentials through its API and CLI so an agent can enter them at checkout.
- The owner chooses the spending limit and explicitly grants access to that card.
- The agent cannot create another card, raise its own limit, or reach cards it was not given.
- Isaac compares the design to an API key with scoped permissions; Hamel caps this card at $100.
The task
- Find Isaac’s course and Mercury’s agent-card documentation.
- Apply a coupon that lowers the course price to $5.
- Use the already authenticated Mercury CLI to retrieve payment details.
- Confirm before buying and avoid exposing the card on the live stream.
What went wrong
- Codex tried incorrect versions of the coupon code, then appended text instead of clearing the field.
- It needed Hamel’s existing signed-in browser profile rather than completing the flow cleanly in its own browser.
- It stopped before entering full card credentials because authorization to spend $5 was not interpreted as authorization to disclose those credentials to Stripe.
- Billing-address handling required another manual intervention.
- The final payment triggered repeated risk denials even after Hamel approved the transaction.
What the friction revealed
- The guardrails did real work: a compromised or confused agent could not silently reach an unlimited account.
- But the system distinguished intent, credential disclosure, billing data, and final submission as separate approval boundaries.
- For a one-off $5 purchase, Hamel could have completed the checkout much faster himself.
- The workflow becomes more plausible for asynchronous delegation—while walking or driving—where elapsed time matters less than avoiding direct interaction.
- Repeated low-risk purchases might justify a reusable skill and a preapproved threshold, but “always authorized” would remove the protection the scoped card is meant to provide.
The result
- After several corrections and approvals, the charge reached Isaac’s Stripe account.
- The purchase succeeded, but neither participant considered the experience smooth enough for routine use.
- The experiment is a useful reminder that financial agents need both a small blast radius and a usable authorization model; either one without the other fails.
“We have purchased something with an agent. My first time. … But it was painful.”