UCP Identity Linking

Identity linking connects a user to a merchant account so agents can act on their behalf. Treat it as a high-trust flow.

Figure: Identity linking handshake.

Diagram of user consent and token exchange for identity linking.

When You Need It

  • The merchant requires an existing account for checkout.
  • Order history or loyalty status affects pricing.

Minimal Linking Flow

  1. User Consent: explicit approval before linking.
  2. Token Exchange: short-lived auth token converted to a stable link.
  3. Revocation: user can unlink at any time.

Security Baselines

  • Scope tokens to the minimum set of actions.
  • Store only a stable account reference, not raw credentials.
  • Log link and unlink events for audit.

Related