Baselayer raises $35M to verify AI agents at checkout
Baselayer's $35M Series A funds Know Your Agent — cryptographic identity for the bots hitting your checkout. What agentic commerce breaks, and the cheap fix.
Every agentic commerce pitch assumes the agent at your checkout is who it says it is. Nobody built the part that checks. On September 22, Baselayer announced a $35 million Series A led by M13 and launched an Agentic Identity Suite built around a "Know Your Agent" check. If you run a store that is about to start taking orders from shopping agents, this is the gap in your stack that nobody has been naming out loud.
What actually happened
M13 led the round, with Torch Capital, Picus Ventures, Afore Capital and Socure's Matt Thompson participating. Crunchbase News reported it brings total funding to roughly $40 million since the company started in 2023. Baselayer already sells business identity and fraud data to financial institutions — the company claims 2,300+ of them, about one in five in the US, and says it has helped prevent over $1 billion in fraud losses.
The new product answers three questions, cryptographically, before a transaction clears:
- Which agent is this?
- Who does it represent?
- Is it authorized to transact on that party's behalf?
Baselayer is building it as an interoperable layer rather than a walled garden — the launch names work with FIS, Prove, Socure and others, plus participation in the FIDO Alliance and the x402 Identity Working Group. Co-founders Jonathan Awad (CEO) and Timothy Hyde (CTO) are pitching it as a shared fraud consortium for autonomous buyers.
Why agent identity matters for your business
Here is the operator problem, stripped of the funding announcement.
Your fraud stack scores humans. Device fingerprint, mouse movement, typing cadence, velocity checks, IP reputation. An agent fails most of those signals by design — it's headless, it's fast, it comes from a datacenter IP, and it doesn't move a mouse. So your rules engine does one of two dumb things: it blocks legitimate agent orders, or you loosen the rules and blind yourself to the real fraud.
"It's from OpenAI" is not authorization. Knowing which vendor's agent runtime made the call tells you nothing about whether the human behind it authorized this purchase, at this amount, from you. That is the actual question, and it is the one Know Your Agent is aimed at. Note that an authorization layer only works if both sides implement it — which is why the standards-body participation matters more than the product screenshot.
You can do the cheap version this quarter. You do not need a $35 million round to stop guessing. Three moves, in order:
- Log it. Add a field on every order recording whether it arrived through an agent path, and which one. If you cannot answer "how many agent orders did we take last month," every decision after this is a guess.
- Segment your risk rules. Agent-path orders get their own thresholds — amount caps, new-address holds, a separate chargeback report. Don't score them against human heuristics.
- Write down the authorization you actually require. For most small merchants that's a real payment credential with a real 3DS-style challenge behind it, not a bot's assertion. Make it explicit so you notice when a new checkout integration quietly removes it.
The honest caveat: the customer counts and the $1 billion figure are the company's own numbers in its funding release, not audited. Treat them as scale signals, not facts.
Key takeaways
- Baselayer raised $35M Series A on September 22, led by M13; total funding around $40M since 2023
- The Agentic Identity Suite answers three things cryptographically: which agent, who it represents, whether it may transact
- Company-reported scale: 2,300+ financial institution customers, $1B+ in fraud losses prevented — unaudited
- Built as an interoperable layer, with FIDO Alliance and x402 Identity Working Group participation
- Standard fraud stacks score human signals agents fail by design — headless, fast, datacenter IP, no mouse
- Knowing an order came from a vendor's agent runtime is not the same as knowing a human authorized it
- Do this quarter: tag agent-path orders in your data, give them separate risk thresholds, and document the authorization you require
If you can't count your agent orders, you can't price the risk on them. Rush Commerce instruments checkout so agent traffic is a tracked segment with its own rules, not an unlabeled spike in your fraud report. See how we wire it up or tell us what your checkout sees today.
Sources: Baselayer via PR Newswire, Crunchbase News.
- #agentic-commerce
- #agent-identity
- #fraud
- #funding
- #checkout
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Shop Pay ships in Muse while Amazon blocks the agent
Shopify opened agentic checkout with Shop Pay to Meta's Muse the same week Amazon blocked it. Two platforms, opposite bets, one decision for merchants.
Read it47% of skincare brands can't prove their claims to agents
A September 16 report says nearly half of 633 skincare brands lack verifiable evidence for their claims. What happens when the shopper is an agent that checks.
Read it