Hamel Husain and Isaac Flath try a real delegated purchase: a Mercury agent card, Codex, a $5 course, and a checkout flow that turns into an eight-minute tour of the remaining friction.

The setup

  • Mercury’s agent card exposes credentials through its API and CLI so an agent can enter them at checkout.
  • The owner chooses the spending limit and explicitly grants access to that card.
  • The agent cannot create another card, raise its own limit, or reach cards it was not given.
  • Isaac compares the design to an API key with scoped permissions; Hamel caps this card at $100.

The task

  • Find Isaac’s course and Mercury’s agent-card documentation.
  • Apply a coupon that lowers the course price to $5.
  • Use the already authenticated Mercury CLI to retrieve payment details.
  • Confirm before buying and avoid exposing the card on the live stream.

What went wrong

  • Codex tried incorrect versions of the coupon code, then appended text instead of clearing the field.
  • It needed Hamel’s existing signed-in browser profile rather than completing the flow cleanly in its own browser.
  • It stopped before entering full card credentials because authorization to spend $5 was not interpreted as authorization to disclose those credentials to Stripe.
  • Billing-address handling required another manual intervention.
  • The final payment triggered repeated risk denials even after Hamel approved the transaction.

What the friction revealed

  • The guardrails did real work: a compromised or confused agent could not silently reach an unlimited account.
  • But the system distinguished intent, credential disclosure, billing data, and final submission as separate approval boundaries.
  • For a one-off $5 purchase, Hamel could have completed the checkout much faster himself.
  • The workflow becomes more plausible for asynchronous delegation—while walking or driving—where elapsed time matters less than avoiding direct interaction.
  • Repeated low-risk purchases might justify a reusable skill and a preapproved threshold, but “always authorized” would remove the protection the scoped card is meant to provide.

The result

  • After several corrections and approvals, the charge reached Isaac’s Stripe account.
  • The purchase succeeded, but neither participant considered the experience smooth enough for routine use.
  • The experiment is a useful reminder that financial agents need both a small blast radius and a usable authorization model; either one without the other fails.

“We have purchased something with an agent. My first time. … But it was painful.”