Runtime as featured inForbesRead the article

integrations

AI Agents for Marqeta Card Program Operations

How card program teams use AI agents on Marqeta: dispute case prep, JIT Funding and authorization investigations, card lifecycle requests, KYC follow-up, and DiVA report checks, with approvals.

Gus Trigos
Co-founder and CEO, Runtime
Updated October 8, 2026 · 8 min read

AI agents can take the investigation work on a Marqeta card program: preparing dispute cases, explaining declined or stood-in authorizations, handling card lifecycle requests, chasing KYC follow-ups, and checking DiVA reports against your ledger. They read through Marqeta's Core API, webhooks, DiVA, and open-source MCP server, then hand a person a drafted action to approve. Runtime is the AI agent harness for payment and fintech teams, and it is where those agents run with guardrails and a full record.

Running a card program on Marqeta means the processor handles authorization and settlement at scale, while your team handles everything around it: the cardholder who says a charge isn't theirs, the gateway that timed out, the settlement file that doesn't tie to the ledger. This is a guide to handing that work to agents without handing over the controls.

The ops work on Marqeta that agents can take

QueueWhat the agent doesWhat stays human
Disputes and chargebacksPulls the transaction, clearing records, and cardholder history; checks the case state and network deadline; drafts the case and evidence listDeciding to file, submitting the chargeback, accepting a loss
Declined and stood-in authorizationsExplains why an authorization declined, timed out at the 3-second JIT limit, or was approved by Commando Mode or network stand-inChanging gateway logic, authorization controls, or velocity limits
Card lifecycleReads card state and transition history, drafts suspend, reactivate, or replace requests with the reasonTerminating a card, unsuspending after fraud
Digital wallet tokensTraces token provisioning and token state for a cardholder complaintSuspending or terminating a token
KYC follow-upReads KYC results and codes (for example OFAC or SSN issues), assembles what the reviewer needsAny override, which Marqeta requires written approval and CIP authority for
Settlement and funding reconCompares DiVA settlement, funding, and authorization views to your ledger and bank activityBooking adjustments, moving program funds

How agents connect to Marqeta

Core API. Cards, users, transactions, card transitions, KYC, authorization controls, and dispute cases are all API resources. Marqeta uses HTTP Basic auth with an application token plus an access token, and offers a public sandbox anyone can sign up for and a private sandbox with more simulation for customers.

Webhooks. Marqeta sends events for transactions, card transitions, user and business transitions, chargeback transitions, digital wallet token transitions, 3DS, Commando Mode, and (since February 2026) dispute case transitions. Events can arrive out of order or more than once, so an agent that reacts to them should dedupe on the event token and order by created time.

DiVA reports. The DiVA API serves authorization, settlement, clearing, decline, chargeback, card, balance, and JIT gateway latency views as JSON or CSV. It syncs three times a day, so it is the right source for daily reconciliation, not for real-time triage.

MCP server. Marqeta publishes an open-source Agentic AI MCP Server, currently in beta. It runs locally and exposes tools for card products, card transitions, cards, disputes, transactions, users, and velocity controls. Its read-only scope limits it to GET calls, and its README recommends read-only scope, human confirmation for every action, and least-privilege service accounts. It does not cover KYC, webhooks, or DiVA.

Browser. For work that lives only in the Marqeta Dashboard or the newer Disputes portal, an agent can use a browser session with a dedicated, role-limited login.

Least privilege. Give each agent its own credential. Marqeta's Self-Service Credentials API (limited release) creates admin access tokens with required roles (read, write, pci, program-manager) and an expiry of 1 to 365 days. Start on read. Add write only for a workflow that has an approval step in front of it, and keep pci off unless the job truly needs card data.

Workflow: dispute case preparation

Marqeta disputes run through dispute cases that move from OPEN to READY to CHARGEBACK_INITIATED and on through representment and arbitration, with network-specific deadlines. The slow part is assembling evidence before the window closes.

A cardholder disputed a $412.80 charge on card ending 4471. Pull the authorization and clearing records, the cardholder's last 90 days of transactions at this merchant, and any prior disputes. Check the case state and how many days remain in the current network window. Draft the dispute reason and an evidence list in our template. Don't create or submit the case; post the draft in #disputes for review.

The reviewer sees the evidence, the deadline, and the draft in one place, and decides whether to file.

Workflow: authorization decline investigation

When a cardholder says their card was declined, the answer can sit in several places: your JIT gateway response, an authorization control, a velocity limit, a 3-second timeout, or a stand-in by Commando Mode or the network.

Card ending 9032 was declined at a grocery store yesterday around 6 pm Eastern. Find the authorization, our gateway's response and latency, and any authorization control or velocity limit that applied. Tell me whether this was our decision, a timeout, or a stand-in, and draft a reply to the cardholder in plain language. Flag it if our gateway has timed out more than usual this week.

Workflow: daily settlement check

Using yesterday's DiVA settlement and program funding views, compare network settlement totals to our ledger and to the funding account activity. List every difference over $1 with the transactions behind it and a likely cause. Don't book anything; open one ticket per unexplained difference.

Guardrails

  • Read-only first. New agents get a read-role token or the MCP server's read-only scope.
  • Approvals before anything changes. Filing a chargeback, terminating a card or token, changing authorization controls, and moving funds wait for a named approver.
  • No card numbers in prompts or logs. Keep the pci role off by default and strip PANs from what the agent sees.
  • Respect Marqeta's own controls. KYC overrides follow Marqeta's written approval process, and dispute deadlines come from the case, not from the agent's guess.
  • Record every run. Keep the trigger, each API call, the evidence, the approval, and the result.

Where Runtime enters the picture

Marqeta runs the card program. It doesn't run your team's investigations across the systems around it. A single disputed transaction touches support (the ticket), card ops (the dispute case), finance (the provisional credit and the recon line), and risk (whether the card should stay active). Today each team opens Marqeta, the ledger, and the help desk separately. Runtime is the AI agent harness for payment and fintech teams: one agent works the case across Marqeta, your ledger, and your help desk, and every team sees the same record. Runtime has no official Marqeta integration or partnership; agents use Marqeta's public APIs, MCP server, and dashboard with credentials you control.

  • No single vendor to depend on. Agent computers run in your AWS, GCP, or Azure account or fully self-hosted, on the sandbox provider you choose, with Claude, GPT, Gemini, or open-weight models and harness routing across Claude Code, Codex, and OpenCode, with fallbacks when a provider goes down.
  • Guardrails you set. Agents start read-only, chargebacks and card terminations wait for approval, access follows roles, credentials are masked, card numbers and SSNs are stripped, and every run is recorded for your sponsor bank or auditor.
  • Built for teams. Card ops, support, finance, risk, and compliance share agents, templates, and one memory, so a dispute and the ticket behind it are worked once.
  • An engineer, not an account executive. A forward-deployed AI engineer who built payment infrastructure at Hulu's payments team at Disney, Finix, Modern Treasury, and BlackRock maps your Marqeta queues and builds the first agents with your team.
New agent

Create a banking ops agent that handles RFIs, hold-harmless requests, and returns of funds from our partner bank, verifies against our ledger, and drafts replies for my approval.

Describe the agent you want
Agent ready

bank-ops-agent

Tools picked from your prompt

EmailLedgerSFTPMastercard
Anyone on the team describes the work in plain English and attaches the SOP. Runtime builds the agent and gives it its own computer.

A realistic timeline

StageTime
First read-only agent against the Marqeta sandboxMinutes on Runtime; days if you build the infrastructure yourself
Dispute prep agent on production data, read-onlyOne to two weeks, mostly agreeing on the evidence template
Decline investigation answering support ticketsTwo to three weeks, including the reply review loop
Daily DiVA settlement checkTwo to four weeks, depending on ledger access
Write actions behind approvalsAfter the read-only versions have earned the team's trust

Frequently asked questions

Can AI agents work with Marqeta?

Yes. Marqeta exposes its Core API, webhooks, and the DiVA reporting API, and publishes an open-source MCP server in beta. An agent with a scoped credential can read cards, transactions, dispute cases, KYC results, and reports, then prepare work for a person to approve. Runtime is the AI agent harness for payment and fintech teams that runs those agents with approvals and an audit trail.

Does Marqeta have an MCP server?

Yes. Marqeta documents an Agentic AI MCP Server in beta, published as open source on GitHub. It runs locally, covers card products, card transitions, cards, disputes, transactions, users, and velocity controls, and supports a read-only scope that limits it to GET calls. It does not cover KYC, webhooks, or DiVA reports.

What Marqeta work should stay human?

Filing a chargeback, terminating a card, overriding a KYC result, changing authorization controls, and anything that moves funds. Agents should gather evidence and draft the action; an authorized person approves. Marqeta itself requires written approval and CIP authority for a manual KYC override.

How should an agent authenticate to Marqeta?

Use a dedicated credential with the least access the workflow needs. Marqeta's Self-Service Credentials API, in limited release, lets you create admin access tokens with roles such as read, write, pci, and program-manager and an expiry between 1 and 365 days. Start agents on a read-only token, and avoid the pci role unless the workflow truly needs card data.

Where does Runtime fit next to Marqeta?

Marqeta is the issuing processor and system of record for your card program. Runtime is where your ops team builds and runs the agents that work Marqeta queues alongside your ledger, help desk, and bank files, with read-only defaults, approvals before money moves, and a recorded run for every case. Runtime does not have a native Marqeta integration; agents use Marqeta's public APIs, MCP server, and dashboard.

Put an agent on your Marqeta queues

Start with one queue, like dispute prep or decline investigations. Runtime runs the agent read-only, in your cloud, with approvals before anything changes. Spin one up yourself, or talk with the founders about your program.