The best platform for handling AI agent traffic in customer support depends on the job: Lorikeet is built to serve and resolve agent conversations inside support, Cloudflare, HUMAN Security and Akamai verify and control agents at the edge, Stripe and Shopify handle agentic checkout, and Intercom Fin and Salesforce Agentforce expose their AI agents to other agents through APIs and protocols. Most support teams will end up running one tool from two or three of those groups, because no single vendor does all of it.
The operational problem is simple to describe and awkward to fix. Personal AI agents now research, compare, buy, cancel and contact support for the people who use them. They show up on your website, in your chat widget, in your inbox and on the phone. Your stack was built to tell humans from bots, and these agents are neither: they are software acting for a real customer. Treat them as bots and you block customers. Treat them as humans and you get polling storms, duplicate tickets and agents pushing past policies they were never told about.
The volume is not hypothetical. Akamai reports that nearly half (47.9%) of all AI bot traffic across its network from July to December 2025 was in the commerce vertical. If you want the concept first, start with our explainer on B2A (business to agent). This piece is the vendor view: which tools do which part of the job, and where each one stops.
Key takeaways
Split the problem by job. Verifying agents, serving agent questions, resolving agent requests and taking agent payments are four different jobs, and vendors specialize in one or two.
Edge tools decide who gets in, support tools decide what happens next. Bot and agent management can tell you an agent is signed and allowed. It cannot answer a billing question or process a cancellation under your policies.
An agent should get the customer's authority and no more. Whatever you buy, check that agents hit the same identity checks, guardrails and action policies a human customer would.
Machine traffic needs machine rules. Rate limits, a clear check-back instruction and deduplication stop one polling agent from opening fifty tickets.
Most AI support platforms do not have a public, agent-facing front door yet. Several expose APIs or protocol support for developers, which is useful, but different from letting any customer's agent ask a question.
Regulated businesses should weight identity and audit heavily. In fintech, healthtech and insurance, what an unverified agent may be told matters more than how fast it gets told.
What to look for in a platform for AI agent traffic
Before comparing vendors, get the evaluation lens right. These are the five criteria we used, and the ones we would use if we were buying.
Identity. Can the platform tell a verified agent acting for a real customer from a scraper or a bot farm? At the edge, that means cryptographic agent verification. Inside support, it means the agent must pass the same customer identity checks a person would before anything account-specific happens.
Actions. Can an agent get something done, such as a booking, a refund, a plan change or a purchase, or only read public information? And are actions limited to what the customer themselves could do?
Rate limits and polling behavior. Agents poll. The Resy case covered in our blocking vs serving piece is the canonical example. A good platform caps volume, tells the agent when to check back and does not open a new ticket for every retry.
Ticketing and visibility. Do agent conversations land somewhere your team can see, sort and learn from, or do they vanish into edge logs?
Regulated fit. For fintech, healthtech and insurance, check how the platform handles verification before disclosure, audit trails and escalation to humans. Validate contractual and technical scope with each vendor directly.
Quick comparison: 8 platforms for AI agent traffic
# | Platform | Primary job | Best for | Agent-facing channel | Pricing |
|---|---|---|---|---|---|
1 | Lorikeet | Serve and resolve agent conversations inside support | Regulated, complex support teams that want agents answered by the same concierge as customers | Yes: public HTTP endpoint for any agent, plus WebMCP tools for supporting browsers | Public plans from $2,100/mo, paid annually |
2 | Intercom Fin | AI support agent with a developer API | Teams already on Fin that want their own product agent to call Fin | Fin Agent API with a workspace API key | $0.99 per outcome plus seats |
3 | Salesforce Agentforce | AI agent platform with agent interoperability | Salesforce shops building multi-agent workflows | A2A Inbound and Hosted MCP Server described in Salesforce's interoperability guide | $2 per conversation or Flex Credits |
4 | Cloudflare | Bot management and AI crawler control | Deciding which crawlers and signed agents reach your site | No (controls access, does not answer) | AI Crawl Control starts free; Bot Management via sales |
5 | HUMAN Security | Agent verification and governance | Setting per-agent rules on login, account and checkout flows | No (governs agents, does not answer) | Contact sales |
6 | Akamai | Bot and agent control at the edge | Large enterprises that want agent identity tied to a human user | No (verifies and enforces, does not answer) | Contact sales |
7 | Stripe | Agentic payments and checkout | Selling products through AI agents | Yes, for commerce: catalog feeds and agent checkout | Contact Stripe; agent-builder side in preview |
8 | Shopify | Agentic commerce for merchants | Shopify merchants whose buyers use shopping agents | Yes, for commerce: UCP and Catalog MCP | Shopify plan pricing; agent docs list no separate fee |
How these platforms were selected
We started from the jobs a support leader actually has to cover when agents show up: letting good agents in, keeping bad ones out, answering and resolving what agents ask, and taking payment when an agent buys. We then looked for vendors whose own public sites describe a capability aimed at AI agents, not a generic chatbot or a generic bot blocker.
Every non-Lorikeet capability below is linked to the vendor's own page or docs as it read on 29 September 2026. Where a vendor's docs did not state a release status, we say so rather than guessing. We also looked at Decagon and Sierra, both established AI support platforms. Decagon's site describes AI agents across voice, chat and email built on Agent Operating Procedures, and Sierra's site lists deployment across chat, SMS, WhatsApp, email, voice and ChatGPT. Neither site, at write time, documented a public channel for customers' own agents to reach the business, so they are not in this list. That may change quickly, so check with them directly. For a head-to-head on the support platform side, see Lorikeet vs Decagon.
Lorikeet is our product, so read the ranking with that in mind. We placed it first for one job only: serving and resolving agent conversations inside support. It does not do bot management and it does not process payments, and we say so in its entry.
What is this category?
Call it B2A infrastructure: the tools a business uses to deal with personal AI agents acting for its customers. It is a young category, and right now it is really four categories that happen to touch the same traffic.
The first is edge control. Bot management vendors have spent a decade separating humans from automated traffic. They are now adding ways to recognize agents that sign their requests cryptographically, so a site can let a known shopping or assistant agent through while blocking scrapers. This is where Cloudflare, HUMAN Security and Akamai sit.
The second is agentic commerce. Payment and commerce platforms are publishing protocols and APIs so agents can read a catalog, build a cart and pay with a token the customer controls. Stripe and Shopify lead here.
The third is AI support platforms opening up to other agents. Some now let external agents call their AI agent programmatically, through an API, MCP or Google's Agent2Agent protocol. Intercom Fin and Salesforce Agentforce document this. It is typically a developer integration, set up per partner or per product, rather than a public door any customer's agent can walk through.
The fourth is serving agents as a customer channel: giving any customer's agent a sanctioned place to ask questions and get things done, with the same answers, policies and identity checks a human gets, and with every conversation visible to the support team. This is the job Lorikeet built B2A for. The three technical ways to open that door are compared in WebMCP vs public endpoint vs llms.txt.
1) Lorikeet
Best for: Serving and resolving agent conversations inside customer support, especially in fintech, healthtech and insurance.
Fit: Agents get the customer's authority and no more: the same guardrails, identity verification and action policies as a person. Buyers should validate scope for their own regulatory context.
Pricing: Public plans on the pricing page: Start at $2,100/mo and Scale at $5,100/mo, both paid annually, plus custom Signature pricing. A free trial is available.
Lorikeet is an AI customer support platform for complex and regulated businesses, with an AI concierge that works across chat, email and voice. In September 2026 it launched B2A, which gives personal AI agents a sanctioned front door to that same concierge. The idea is deliberately plain: agents are a new channel for existing customers, so they should reach the same knowledge, workflows, actions and guardrails that serve those customers, rather than a separate bot FAQ that drifts out of date.
There are two ways in and one concierge behind them. Agents in browsers that support WebMCP, a proposed web standard, can call tools registered on the business's website. Every other agent calls a public endpoint over plain HTTP, in the form GET https://api.lorikeetcx.ai/v1/ask/<public key>?q=..., and gets plain JSON back, including instructions for asking follow-up questions in the same conversation. You can try it yourself: lorikeetcx.ai runs its own public endpoint, and its footer tells agents how to use it. The site also publishes an llms.txt with sections for asking the support agent and booking a demo.
The design choices are about machine traffic. An agent asks, then checks back for the answer. Rate limits cap volume, and a retry does not open a second ticket. That is the difference between an agent that polls politely and an agent that gets its customer banned, which is the pattern that gets real customers flagged as spam.
Governance is the part that matters for regulated teams. Endpoint conversations are anonymous by default. Anything account-specific goes through the same identity verification skills and policies the concierge applies on every other channel, so an agent sees only what a customer would see and can do only what a customer could do. There is no separate agent identity protocol to trust.
Every agent conversation lands in Lorikeet as a normal ticket, sorted by topic, so the support team can see what agents are asking for. Setup takes four steps: create an account, let Coach help build and test a concierge for your website, turn on the agent-facing endpoint, and paste the snippet Coach gives you into your site. No backend work is required, because the concierge answers from your existing knowledge.
Key features
Public HTTP endpoint any agent can call, returning plain JSON with follow-up instructions
WebMCP tools on your website for browsers and agents that support the proposal
Same concierge, knowledge, workflows and actions as your human customer channels
Rate limits, check-back instructions and no duplicate tickets on retry
Identity verification and action policies applied before anything account-specific
Agent conversations logged as normal tickets, sorted by topic
Why it made the list
It is the only product in this list whose job is to answer and resolve what customers' agents ask, inside support, under support's policies. A conversation that starts with a question can end in a booking, a sale or a resolution, because the agent is talking to the concierge that already does those things for people.
The honest limits: B2A launched in September 2026, so it is weeks old, not years. WebMCP only works where browsers and agents support the proposal, so most agents today will use the plain endpoint. And Lorikeet does not do bot management or payments. If you need to block scrapers at the edge or take agentic payments, pair it with a vendor from further down this list.
Carmoola, a car finance lender, put the customer case this way. Amy Rushby, Co-Founder and Director of Product and Operations: "Carmoola is car finance your way. You know your budget before you shop, and you manage everything in the app with no paperwork and no sales calls. More people now want their own AI agent to do that shopping and managing for them. If that's how a customer wants to do it, it should be just as fast, fair and simple as the app. That's why we're preparing for business to agent now with Lorikeet."
2) Intercom Fin
Best for: Teams already running Fin that want their own product agent, or an orchestrating agent they build, to call Fin programmatically.
Fit: Access is by workspace API key, so it suits known, developer-built integrations. Validate how customer identity is handled for your use case.
Pricing: Public pricing lists Fin at $0.99 per outcome, with seats from $29 to $132 per month. Fin Agent API conversations are billed on outcomes like any other Fin conversation.
Intercom's Fin is one of the most widely used AI support agents. The relevant piece for agent traffic is the Fin Agent API. Intercom's developer docs say "You call Fin from your own agent", with Fin reporting status and responses back through webhooks or Server-Sent Events. You can use Fin as a contained tool inside your own orchestration, or hand a whole conversation turn to Fin.
Key features
Programmatic access to Fin from another agent
Events delivered via webhooks or Server-Sent Events
Use Fin as a tool, or hand over full conversation turns
Outcome-based billing, at most once per conversation
Why it made the list
It is a clear, documented way for another agent to reach a support AI agent, from a major support vendor. That makes it a strong option if the agent you care about is one you or a partner build.
The distinction to understand: requests need a workspace-scoped API key, which the docs say should be kept secure. That fits a developer integration. It is a different shape from a public door that any customer's personal agent can find and use without a key issued by you. If your problem is Instinct or ChatGPT agents showing up unannounced, ask Intercom how they would handle that case.
3) Salesforce Agentforce
Best for: Salesforce customers building multi-agent systems where outside agents call into Agentforce.
Fit: Salesforce's guide describes the capability but does not state a release status for inbound agent access. Confirm availability and licensing before planning around it.
Pricing: Public pricing lists $2 per conversation for customer-facing agents, or Flex Credits at $500 per 100,000 credits.
Agentforce is Salesforce's AI agent platform. Its interoperability guide describes two ways in for outside agents. "A2A Inbound allows external third-party agents to natively call upon the specialized skills and data of an Agentforce agent," using the Agent2Agent protocol. And "Salesforce's Hosted MCP Server allows Agentforce capabilities to be exposed to external hosts through a standardized MCP interface."
Key features
A2A Inbound for third-party agents calling Agentforce agents
Hosted MCP Server exposing Agentforce capabilities to external hosts
Outbound A2A for Agentforce agents calling other agents
Runs on Salesforce data, flows and permissions
Consumption or per-user pricing options
Why it made the list
Salesforce is investing in agent-to-agent interoperability, and if your customer data already lives in Salesforce, having outside agents call into Agentforce keeps that data where it is.
The caveats: the guide does not say whether A2A Inbound is generally available, and A2A is aimed at agents that speak the protocol, typically other enterprise agents. Most consumer personal agents today read websites and call plain HTTP. Plan for both.
4) Cloudflare
Best for: Deciding which AI crawlers and signed agents can reach your site, and blocking the rest.
Fit: Edge control, not support. It decides access; it does not answer questions or resolve requests.
Pricing: AI Crawl Control offers "Start for free". Acting on signed agents as a group in security rules is an Enterprise feature; contact sales.
Cloudflare sits in front of a large share of the web, which gives it a wide view of automated traffic. For agents, two things matter. AI Crawl Control lets you see which AI crawlers hit your site and block, allow or, in private beta, charge them. And Cloudflare now recognizes signed agents, which it describes as "agents that are generally directed by an end user instead of a single company or entity", verified using Web Bot Auth, where "HTTP message signatures allow bots to authenticate themselves". Its docs now place signed agents inside the Verified category.
Key features
AI Crawl Control: monitor, allow or block AI crawlers
Pay per crawl, in private beta
Signed agent recognition via Web Bot Auth
Verified bot directory with published criteria
Security rules that act on signed agents as a group (Enterprise)
Why it made the list
If you only do one edge change, make it this one: stop blanket-blocking signed agents that act for real users. Cloudflare's distinction between end-user-directed agents and crawlers is the same distinction support teams need.
It does not handle what happens after the agent gets through. An allowed agent still hits a login wall, a chat widget built for humans or a form. Pair it with something that serves the agent.
5) HUMAN Security
Best for: Per-agent governance over sensitive flows such as login, account updates and checkout.
Fit: Governs what consumer agents can do on your applications. It does not answer or resolve support requests.
Pricing: Contact sales.
HUMAN's AgenticTrust is aimed squarely at consumer agents. HUMAN says it "provides granular visibility and governance over consumer AI agents that act on behalf of your users", verifies agents "using cryptographic digital signatures that cannot be spoofed" and lets you "deny or allow browsing, login, or checkout according to your business policies and objectives."
Key features
Cryptographic verification of agents
User and session insights into what agents do, from discovery to checkout
Granular per-agent policies on browsing, login and checkout
Protection for high-impact actions such as account updates
Fraud, scraping and fake-account defense across humans, bots and agents
Why it made the list
Its policy model is the closest thing at the edge to "the customer's authority and no more": one agent may browse but not check out, another may do both. That is the right shape of control.
It governs your web application, not your support queue. When an allowed agent asks why a fee was charged or wants to change a plan, something else has to answer.
6) Akamai
Best for: Large enterprises that want agent identity linked to the human behind it, enforced at the edge.
Fit: Edge verification and enforcement. It does not answer or resolve support requests.
Pricing: Contact sales.
In June 2026 Akamai announced an agentic security framework for its Bot & Agent Control solutions. It covers verified agent identity, including work with Visa's Trusted Agent Protocol and a "Know Your Agent" framework with Skyfire and Experian, plus user-centric authentication through Auth0 and Ping Identity, adaptive trust analysis, edge enforcement, content monetization and traffic visibility. Akamai's framing is that a business needs to know who is behind an agent and what it is trying to do, as well as which agent it is.
Key features
Agent identity verification with Visa's Trusted Agent Protocol
Know Your Agent framework with Skyfire and Experian
User authentication integrations with Auth0 and Ping Identity
Edge-based, real-time enforcement
Pay-per-request monetization with TollBit and Skyfire
Why it made the list
Linking an agent to an authorized human is the question every support team eventually asks, and Akamai is building for it at network scale.
Like the other edge vendors, it stops at the door. Verification tells you who is asking; it does not answer the question.
7) Stripe
Best for: Businesses that want AI agents to buy their products and pay with customer-controlled credentials.
Fit: Payments and checkout. It is not a support channel.
Pricing: Contact Stripe. The docs we read list no agent-specific fees, and the agent-builder side is in private preview.
Stripe's agentic commerce docs cover both sides. Sellers use the Agentic Commerce Suite to share product, price and availability with agents and accept agentic payments across protocols including ACP and UCP. Stripe says the suite is available in the US, Canada and select European countries. Businesses selling APIs or services can also accept machine payments.
Key features
Catalog, inventory and pricing feeds for agents
Agent checkout through ACP or UCP
Shared Payment Tokens for agent-initiated payments
Machine payments for APIs and services
Orders tagged with the originating agent in the Dashboard
Why it made the list
When an agent's job is to buy, you want the purchase to happen through payment rails built for it, not through an agent driving a checkout page meant for humans.
It covers the transaction. Questions before the sale and problems after it still come to support.
8) Shopify
Best for: Shopify merchants whose buyers use shopping agents.
Fit: Commerce: discovery, carts, checkout and order status. Not a support platform for non-commerce questions.
Pricing: Shopify's plan pricing is public; its agent docs list no separate fee.
Shopify's agent docs describe how AI agents use the Universal Commerce Protocol (UCP) to search the Catalog, build carts, convert carts into checkouts and monitor orders. Agents present profiles for capability negotiation and operate under trust-based rate limits, and trusted agents can complete purchases.
Key features
Catalog search across Shopify listings and individual storefronts
Cart building and checkout through UCP
Agent profiles and trust-based rate limits
Order lifecycle monitoring, including refunds, returns and cancellations
Real-time order status on demand
Why it made the list
Order status is one of the most common support questions, and Shopify lets agents check it directly. Trust-based rate limits are also a good model for anyone building an agent-facing surface.
Its scope is commerce on Shopify. Policy questions, disputes and anything outside the order still need a support channel.
How to choose
Work through these in order. Most teams stop after three.
Stop banning your own customers. If your bot rules block every automated request, start at the edge. Cloudflare, HUMAN Security or Akamai can let verified agents through while you keep blocking scrapers. See blocking vs serving AI agents for the decision itself.
Give agents a sanctioned place to ask. Once agents get in, they need somewhere to go that returns accurate answers without scraping your help center. That is a support-side job. Our agent-ready website checklist covers the full list of steps.
Apply the customer's authority and no more. Before an agent can see an account or take an action, it should pass the same identity checks a customer would. If your platform treats agents as a separate, looser channel, fix that first.
Add rate limits and check-back. Pick a platform that caps volume and tells the agent when to return, so polling does not become spam or duplicate tickets.
Add payments if agents buy. If agents purchase from you, add Stripe or Shopify's agent rails.
Make it visible. Whatever you choose, make sure agent conversations show up where your support team works, sorted so you can see what agents want.
Detailed feature matrix, with honest gaps
Capability | Lorikeet | Intercom Fin | Agentforce | Cloudflare | HUMAN | Akamai | Stripe | Shopify |
|---|---|---|---|---|---|---|---|---|
Answers support questions from any customer's agent | Yes, public endpoint | Via Fin Agent API with your API key | Via A2A Inbound or MCP; status not stated | No | No | No | No | Order status only |
Takes actions for the customer | Yes, under the same action policies as customers | Yes, Fin procedures | Yes, Agentforce actions | No | No | No | Payments | Carts, checkout |
Cryptographic agent verification | No; uses customer identity verification instead | Not documented | Not documented | Yes, Web Bot Auth | Yes | Yes, with partners | Not its role | Agent profiles |
Customer identity checks before account data | Yes, same as other channels | Validate with vendor | Validate with vendor | No | No | User authentication via Auth0 and Ping Identity | Payment credentials | Validate with vendor |
Rate limits and check-back for agents | Yes | Not documented | Not documented | Edge rules | Edge policies | Edge enforcement | Not documented | Trust-based rate limits |
Agent conversations as tickets | Yes, sorted by topic | Fin conversations | Salesforce records | No | No | No | No | No |
WebMCP tools on your site | Yes, for supporting browsers | Not documented | Not documented | No | No | No | No | No |
Bot management and scraper blocking | No | No | No | Yes | Yes | Yes | No | No |
Agentic payments | No | No | No | Pay per crawl (beta) | No | Monetization partners | Yes | Yes |
Voice, chat and email on the same brain | Yes | Validate with vendor | Validate with vendor | No | No | No | No | No |
"Not documented" means we could not find it on the vendor's public pages at write time. It does not mean the capability is absent. Ask.
Why Lorikeet for agent traffic in support
The argument for Lorikeet is narrow on purpose. Edge vendors decide who gets in. Commerce vendors take the money. Someone still has to answer what the agent asked, under your policies, and resolve it. Lorikeet does that with the same concierge that already serves your customers on chat, email and voice, so there is one set of answers, one set of guardrails and one ticket queue.
That matters most in regulated industries. A fintech or health business cannot let an agent see what the customer could not, and cannot let an agent act where the customer would need to verify first. Lorikeet applies the same identity verification and action policies on the agent channel as everywhere else, so there is no new rulebook to audit.
The concierge itself has a production record outside B2A. Hnry went live in mid-May 2026 and handled 17,000+ conversations in its first month. That is proof of the concierge, not of B2A, which launched on 17 September 2026. For the full concept and the market context, read what B2A is, or see the launch announcement linked above.
If agents are already showing up in your queue, we should talk. Get a demo and we will show you the endpoint answering a live agent, or start a free trial and turn it on yourself.







