This specification standardizes an API to allow merchants (i.e. web sites selling physical or digital goods) to utilize one or more payment methods with minimal integration. User agents (e.g., browsers) facilitate the payment flow between merchant and user.

    I find this worrisome, since we still see nearly-daily browser hijacking exploits. It sounds like a cliche, but I have to clear out 3rd party “toolbar extensions” and “search enhancers” from my mother-in-law’s laptop about once a month.

    The idea that any of them could drive a payment API is troubling.