MCP-Server

MandateShield AI Payment Evidence

com.mandateshield/payment-authority
Payments & Fintech Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Normalizes payment protocol data and checks delegated AI payment authority, including cryptographic evidence verification.

check_ai_payment_authority
Check AI Payment Authority
Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys.
Idempotent
Eingabeschema
{'type': 'object', 'required': ['protocol', 'mandate_id', 'agent_id', 'merchant_id', 'amount', 'idempotency_key'], 'properties': {'amount': {'type': 'object', 'oneOf': [{'required': ['value', 'currency']}, {'required': ['atomic_units', 'asset_decimals']}], 'properties': {'value': {'type': 'number', 'exclusiveMinimum': 0}, 'currency': {'type': 'string', 'pattern': '^[A-Za-z]{3}$', 'description': 'Three-letter ISO currency code.'}, 'minor_units': {'type': 'integer', 'minimum': 1, 'description': "Optional exact integer amount in the currency's minor unit."}, 'atomic_units': {'type': 'string', 'pattern': '^(?:0|[1-9][0-9]{0,77})$', 'description': 'Exact integer atomic-asset amount. This string is authoritative for X402.'}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}}, 'additionalProperties': False}, 'limits': {'type': 'object', 'oneOf': [{'anyOf': [{'required': ['max_amount_minor']}, {'required': ['max_amount']}], 'required': ['currencies', 'merchants']}, {'required': ['max_atomic_units', 'asset_decimals', 'assets', 'networks', 'resources', 'merchants']}], 'properties': {'assets': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'networks': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'merchants': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'resources': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'currencies': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[A-Za-z]{3}$'}, 'minItems': 1}, 'max_amount': {'type': 'number', 'exclusiveMinimum': 0}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}, 'max_amount_minor': {'type': 'integer', 'exclusiveMinimum': 0}, 'max_atomic_units': {'type': 'string', 'pattern': '^[1-9][0-9]{0,77}$'}}, 'description': 'Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate.'}, 'network': {'type': 'string', 'minLength': 1, 'description': 'Exact network or chain identifier; required for atomic X402 payments.'}, 'purpose': {'type': 'string', 'description': 'Non-sensitive plain-language purchase purpose.'}, 'agent_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the acting AI agent.'}, 'asset_id': {'type': 'string', 'minLength': 1, 'description': 'Exact token or asset identifier; required for atomic X402 payments.'}, 'protocol': {'enum': ['AP2', 'TAP', 'UCP', 'X402', 'MPP', 'ACP', 'CUSTOM'], 'type': 'string', 'description': 'Source protocol or CUSTOM for a normalized envelope.'}, 'resource': {'type': 'string', 'minLength': 1, 'description': 'Exact paid resource identifier; required for atomic X402 payments.'}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'expires_at': {'type': 'string', 'format': 'date-time'}, 'mandate_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the user-approved authority.'}, 'intent_hash': {'type': 'string'}, 'merchant_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the final seller or payee.'}, 'http_request': {'type': 'object', 'required': ['profile', 'url', 'method', 'body_sha256', 'headers_sha256', 'redirect_policy'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'method': {'enum': ['GET', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string'}, 'profile': {'const': 'MANDATESHIELD_X402_V2_EXACT_EIP3009_V1'}, 'body_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'headers_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'redirect_policy': {'const': 'ERROR'}}, 'description': 'Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter.', 'additionalProperties': False}, 'user_consent': {'type': 'boolean'}, 'checkout_hash': {'type': 'string', 'minLength': 1, 'description': 'Digest or stable identifier for the exact final checkout.'}, 'payee_identity': {'type': 'object', 'oneOf': [{'properties': {'binding': {'type': 'object', 'required': ['network', 'pay_to'], 'properties': {'pay_to': {'type': 'string', 'maxLength': 500, 'minLength': 1}, 'network': {'type': 'string', 'maxLength': 240, 'minLength': 1}}, 'additionalProperties': False}, 'provider': {'const': 'X402'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TRUSTED_MERCHANT_MAPPING'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'method'], 'properties': {'method': {'type': 'string', 'pattern': '^[a-z]+$'}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'MPP'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TLS_SERVICE_ORIGIN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['connected_account_id', 'merchant_account_id'], 'properties': {'merchant_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}, 'connected_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}, 'provider': {'const': 'STRIPE'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'STRIPE_ACCOUNT_CONFIGURATION'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'pattern': '^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'provider_id'], 'properties': {'provider_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'CUSTOM'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'HTTPS_WELL_KNOWN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'format': 'uri', 'pattern': '^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$'}}, 'additionalProperties': False}}}], 'required': ['profile', 'provider', 'merchant_id', 'binding', 'verification'], 'properties': {'binding': {'type': 'object'}, 'profile': {'const': 'MANDATESHIELD_PAYEE_IDENTITY_V1'}, 'provider': {'enum': ['X402', 'MPP', 'STRIPE', 'CUSTOM'], 'type': 'string'}, 'merchant_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'enum': ['TRUSTED_MERCHANT_MAPPING', 'TLS_SERVICE_ORIGIN', 'STRIPE_ACCOUNT_CONFIGURATION', 'HTTPS_WELL_KNOWN'], 'type': 'string'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}, 'description': 'Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document.', 'additionalProperties': False}, 'idempotency_key': {'type': 'string', 'pattern': '^[A-Za-z0-9._:~-]+$', 'maxLength': 256, 'minLength': 1, 'description': 'Unique identifier for this intended payment attempt.'}, 'credential_binding': {'type': 'string'}}, 'additionalProperties': True}
Ausgabeschema
{'type': 'object', 'required': ['decision', 'score', 'receipt', 'checked_at', 'protocol', 'findings', 'risk', 'recommended_action', 'controls', 'mode', 'persisted', 'enforcement_authorized'], 'properties': {'mode': {'type': 'string'}, 'risk': {'type': 'object', 'required': ['level', 'requested_value', 'mandate_headroom', 'blocked_value', 'primary_reason'], 'properties': {'level': {'enum': ['CLEAR', 'GUARDED', 'ELEVATED', 'CRITICAL'], 'type': 'string'}, 'blocked_value': {'type': 'number', 'minimum': 0}, 'primary_reason': {'type': ['string', 'null']}, 'requested_value': {'type': ['number', 'null']}, 'mandate_headroom': {'type': ['number', 'null']}}}, 'error': {'type': 'string'}, 'score': {'type': 'integer', 'maximum': 100, 'minimum': 0, 'description': 'Deterministic control-coverage indicator, not a calibrated probability of fraud or loss.'}, 'receipt': {'type': 'string'}, 'controls': {'type': 'object', 'required': ['evaluated', 'passed'], 'properties': {'passed': {'type': 'integer', 'minimum': 0}, 'evaluated': {'type': 'integer', 'minimum': 0}}}, 'decision': {'enum': ['ALLOW', 'REVIEW', 'BLOCK'], 'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'message', 'severity'], 'properties': {'code': {'type': 'string'}, 'message': {'type': 'string'}, 'severity': {'enum': ['high', 'medium', 'low'], 'type': 'string'}}}}, 'protocol': {'type': 'string'}, 'persisted': {'type': 'boolean'}, 'checked_at': {'type': 'string', 'format': 'date-time'}, 'recommended_action': {'type': 'string'}, 'enforcement_authorized': {'type': 'boolean', 'description': 'True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call.'}}}
normalize_agent_payment_protocol
Project Agent Payment Fields
Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', 'required': ['adapter', 'source', 'context'], 'properties': {'source': {'description': 'Raw protocol input: AP2 compact SD-JWT, x402 PAYMENT-REQUIRED base64 JSON, MPP WWW-Authenticate Payment challenge, or the documented decoded object.'}, 'adapter': {'enum': ['AP2_CLOSED_PAYMENT_SD_JWT', 'X402_V2_PAYMENT_REQUIRED', 'MPP_HTTP_PAYMENT_CHALLENGE'], 'type': 'string'}, 'context': {'type': 'object', 'required': ['mandate_id', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'asset_id': {'type': 'string', 'maxLength': 500, 'minLength': 1}, 'resource': {'type': 'string', 'maxLength': 2048, 'minLength': 1}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'mandate_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'amount_unit': {'enum': ['MINOR_UNITS', 'ATOMIC_UNITS'], 'type': 'string'}, 'http_method': {'enum': ['GET', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string'}, 'merchant_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'user_consent': {'type': 'boolean'}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}, 'payee_identity': {'type': 'object', 'oneOf': [{'properties': {'binding': {'type': 'object', 'required': ['network', 'pay_to'], 'properties': {'pay_to': {'type': 'string', 'maxLength': 500, 'minLength': 1}, 'network': {'type': 'string', 'maxLength': 240, 'minLength': 1}}, 'additionalProperties': False}, 'provider': {'const': 'X402'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TRUSTED_MERCHANT_MAPPING'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'method'], 'properties': {'method': {'type': 'string', 'pattern': '^[a-z]+$'}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'MPP'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TLS_SERVICE_ORIGIN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['connected_account_id', 'merchant_account_id'], 'properties': {'merchant_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}, 'connected_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}, 'provider': {'const': 'STRIPE'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'STRIPE_ACCOUNT_CONFIGURATION'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'pattern': '^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'provider_id'], 'properties': {'provider_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'CUSTOM'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'HTTPS_WELL_KNOWN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'format': 'uri', 'pattern': '^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$'}}, 'additionalProperties': False}}}], 'required': ['profile', 'provider', 'merchant_id', 'binding', 'verification'], 'properties': {'binding': {'type': 'object'}, 'profile': {'const': 'MANDATESHIELD_PAYEE_IDENTITY_V1'}, 'provider': {'enum': ['X402', 'MPP', 'STRIPE', 'CUSTOM'], 'type': 'string'}, 'merchant_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'enum': ['TRUSTED_MERCHANT_MAPPING', 'TLS_SERVICE_ORIGIN', 'STRIPE_ACCOUNT_CONFIGURATION', 'HTTPS_WELL_KNOWN'], 'type': 'string'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}, 'description': 'Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document.', 'additionalProperties': False}, 'idempotency_key': {'type': 'string', 'maxLength': 256, 'minLength': 1}, 'http_body_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'http_headers_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'mpp_request_profile': {'enum': ['MANDATESHIELD_PORTABLE_CHARGE_V1'], 'type': 'string', 'description': 'Required for MPP because the core protocol delegates request field semantics to method-specific specifications.'}, 'x402_execution_profile': {'enum': ['MANDATESHIELD_X402_V2_EXACT_EIP3009_V1'], 'type': 'string', 'description': 'Opt-in strict first-party x402 execution binding. Requires method and exact request digests.'}}, 'additionalProperties': False}, 'selection': {'type': 'object', 'properties': {'index': {'type': 'integer', 'maximum': 24, 'minimum': 0}}, 'additionalProperties': False}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['adapter', 'adapter_version', 'protocol', 'source_digest', 'envelope_digest', 'envelope', 'assurance', 'next_step', 'warnings'], 'properties': {'adapter': {'type': 'string'}, 'envelope': {'type': 'object', 'required': ['protocol', 'mandate_id', 'agent_id', 'merchant_id', 'amount', 'idempotency_key'], 'properties': {'amount': {'type': 'object', 'oneOf': [{'required': ['value', 'currency']}, {'required': ['atomic_units', 'asset_decimals']}], 'properties': {'value': {'type': 'number', 'exclusiveMinimum': 0}, 'currency': {'type': 'string', 'pattern': '^[A-Za-z]{3}$', 'description': 'Three-letter ISO currency code.'}, 'minor_units': {'type': 'integer', 'minimum': 1, 'description': "Optional exact integer amount in the currency's minor unit."}, 'atomic_units': {'type': 'string', 'pattern': '^(?:0|[1-9][0-9]{0,77})$', 'description': 'Exact integer atomic-asset amount. This string is authoritative for X402.'}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}}, 'additionalProperties': False}, 'limits': {'type': 'object', 'oneOf': [{'anyOf': [{'required': ['max_amount_minor']}, {'required': ['max_amount']}], 'required': ['currencies', 'merchants']}, {'required': ['max_atomic_units', 'asset_decimals', 'assets', 'networks', 'resources', 'merchants']}], 'properties': {'assets': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'networks': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'merchants': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'resources': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'currencies': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[A-Za-z]{3}$'}, 'minItems': 1}, 'max_amount': {'type': 'number', 'exclusiveMinimum': 0}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}, 'max_amount_minor': {'type': 'integer', 'exclusiveMinimum': 0}, 'max_atomic_units': {'type': 'string', 'pattern': '^[1-9][0-9]{0,77}$'}}, 'description': 'Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate.'}, 'network': {'type': 'string', 'minLength': 1, 'description': 'Exact network or chain identifier; required for atomic X402 payments.'}, 'purpose': {'type': 'string', 'description': 'Non-sensitive plain-language purchase purpose.'}, 'agent_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the acting AI agent.'}, 'asset_id': {'type': 'string', 'minLength': 1, 'description': 'Exact token or asset identifier; required for atomic X402 payments.'}, 'protocol': {'enum': ['AP2', 'TAP', 'UCP', 'X402', 'MPP', 'ACP', 'CUSTOM'], 'type': 'string', 'description': 'Source protocol or CUSTOM for a normalized envelope.'}, 'resource': {'type': 'string', 'minLength': 1, 'description': 'Exact paid resource identifier; required for atomic X402 payments.'}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'expires_at': {'type': 'string', 'format': 'date-time'}, 'mandate_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the user-approved authority.'}, 'intent_hash': {'type': 'string'}, 'merchant_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the final seller or payee.'}, 'http_request': {'type': 'object', 'required': ['profile', 'url', 'method', 'body_sha256', 'headers_sha256', 'redirect_policy'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'method': {'enum': ['GET', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string'}, 'profile': {'const': 'MANDATESHIELD_X402_V2_EXACT_EIP3009_V1'}, 'body_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'headers_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'redirect_policy': {'const': 'ERROR'}}, 'description': 'Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter.', 'additionalProperties': False}, 'user_consent': {'type': 'boolean'}, 'checkout_hash': {'type': 'string', 'minLength': 1, 'description': 'Digest or stable identifier for the exact final checkout.'}, 'payee_identity': {'type': 'object', 'oneOf': [{'properties': {'binding': {'type': 'object', 'required': ['network', 'pay_to'], 'properties': {'pay_to': {'type': 'string', 'maxLength': 500, 'minLength': 1}, 'network': {'type': 'string', 'maxLength': 240, 'minLength': 1}}, 'additionalProperties': False}, 'provider': {'const': 'X402'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TRUSTED_MERCHANT_MAPPING'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'method'], 'properties': {'method': {'type': 'string', 'pattern': '^[a-z]+$'}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'MPP'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TLS_SERVICE_ORIGIN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['connected_account_id', 'merchant_account_id'], 'properties': {'merchant_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}, 'connected_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}, 'provider': {'const': 'STRIPE'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'STRIPE_ACCOUNT_CONFIGURATION'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'pattern': '^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'provider_id'], 'properties': {'provider_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'CUSTOM'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'HTTPS_WELL_KNOWN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'format': 'uri', 'pattern': '^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$'}}, 'additionalProperties': False}}}], 'required': ['profile', 'provider', 'merchant_id', 'binding', 'verification'], 'properties': {'binding': {'type': 'object'}, 'profile': {'const': 'MANDATESHIELD_PAYEE_IDENTITY_V1'}, 'provider': {'enum': ['X402', 'MPP', 'STRIPE', 'CUSTOM'], 'type': 'string'}, 'merchant_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'enum': ['TRUSTED_MERCHANT_MAPPING', 'TLS_SERVICE_ORIGIN', 'STRIPE_ACCOUNT_CONFIGURATION', 'HTTPS_WELL_KNOWN'], 'type': 'string'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}, 'description': 'Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document.', 'additionalProperties': False}, 'idempotency_key': {'type': 'string', 'pattern': '^[A-Za-z0-9._:~-]+$', 'maxLength': 256, 'minLength': 1, 'description': 'Unique identifier for this intended payment attempt.'}, 'credential_binding': {'type': 'string'}}, 'additionalProperties': True}, 'protocol': {'enum': ['AP2', 'X402', 'MPP'], 'type': 'string'}, 'warnings': {'type': 'array', 'items': {'type': 'string'}}, 'assurance': {'type': 'object', 'required': ['projection_fields_valid', 'source_signature_verified', 'source_trust_verified', 'delegated_authority_verified', 'payment_credential_verified', 'settlement_verified', 'enforcement_authorized'], 'properties': {'settlement_verified': {'const': False}, 'source_trust_verified': {'const': False}, 'enforcement_authorized': {'const': False}, 'projection_fields_valid': {'const': True}, 'source_signature_verified': {'const': False}, 'payment_credential_verified': {'const': False}, 'delegated_authority_verified': {'const': False}}}, 'next_step': {'type': 'string'}, 'source_digest': {'type': 'string'}, 'adapter_version': {'type': 'string'}, 'envelope_digest': {'type': 'string'}}, 'additionalProperties': True}
verify_cryptographic_payment_authority
Verify Cryptographic Payment Authority
Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome.
Idempotent
Eingabeschema
{'type': 'object', 'required': ['envelope', 'evidence'], 'properties': {'envelope': {'type': 'object', 'required': ['protocol', 'mandate_id', 'agent_id', 'merchant_id', 'amount', 'idempotency_key'], 'properties': {'amount': {'type': 'object', 'oneOf': [{'required': ['value', 'currency']}, {'required': ['atomic_units', 'asset_decimals']}], 'properties': {'value': {'type': 'number', 'exclusiveMinimum': 0}, 'currency': {'type': 'string', 'pattern': '^[A-Za-z]{3}$', 'description': 'Three-letter ISO currency code.'}, 'minor_units': {'type': 'integer', 'minimum': 1, 'description': "Optional exact integer amount in the currency's minor unit."}, 'atomic_units': {'type': 'string', 'pattern': '^(?:0|[1-9][0-9]{0,77})$', 'description': 'Exact integer atomic-asset amount. This string is authoritative for X402.'}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}}, 'additionalProperties': False}, 'limits': {'type': 'object', 'oneOf': [{'anyOf': [{'required': ['max_amount_minor']}, {'required': ['max_amount']}], 'required': ['currencies', 'merchants']}, {'required': ['max_atomic_units', 'asset_decimals', 'assets', 'networks', 'resources', 'merchants']}], 'properties': {'assets': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'networks': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'merchants': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'resources': {'type': 'array', 'items': {'type': 'string', 'minLength': 1}, 'minItems': 1}, 'currencies': {'type': 'array', 'items': {'type': 'string', 'pattern': '^[A-Za-z]{3}$'}, 'minItems': 1}, 'max_amount': {'type': 'number', 'exclusiveMinimum': 0}, 'asset_decimals': {'type': 'integer', 'maximum': 30, 'minimum': 0}, 'max_amount_minor': {'type': 'integer', 'exclusiveMinimum': 0}, 'max_atomic_units': {'type': 'string', 'pattern': '^[1-9][0-9]{0,77}$'}}, 'description': 'Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate.'}, 'network': {'type': 'string', 'minLength': 1, 'description': 'Exact network or chain identifier; required for atomic X402 payments.'}, 'purpose': {'type': 'string', 'description': 'Non-sensitive plain-language purchase purpose.'}, 'agent_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the acting AI agent.'}, 'asset_id': {'type': 'string', 'minLength': 1, 'description': 'Exact token or asset identifier; required for atomic X402 payments.'}, 'protocol': {'enum': ['AP2', 'TAP', 'UCP', 'X402', 'MPP', 'ACP', 'CUSTOM'], 'type': 'string', 'description': 'Source protocol or CUSTOM for a normalized envelope.'}, 'resource': {'type': 'string', 'minLength': 1, 'description': 'Exact paid resource identifier; required for atomic X402 payments.'}, 'created_at': {'type': 'string', 'format': 'date-time'}, 'expires_at': {'type': 'string', 'format': 'date-time'}, 'mandate_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the user-approved authority.'}, 'intent_hash': {'type': 'string'}, 'merchant_id': {'type': 'string', 'minLength': 1, 'description': 'Stable identifier for the final seller or payee.'}, 'http_request': {'type': 'object', 'required': ['profile', 'url', 'method', 'body_sha256', 'headers_sha256', 'redirect_policy'], 'properties': {'url': {'type': 'string', 'format': 'uri'}, 'method': {'enum': ['GET', 'HEAD', 'POST', 'PUT', 'PATCH', 'DELETE'], 'type': 'string'}, 'profile': {'const': 'MANDATESHIELD_X402_V2_EXACT_EIP3009_V1'}, 'body_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'headers_sha256': {'type': 'string', 'pattern': '^sha256:[a-f0-9]{64}$'}, 'redirect_policy': {'const': 'ERROR'}}, 'description': 'Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter.', 'additionalProperties': False}, 'user_consent': {'type': 'boolean'}, 'checkout_hash': {'type': 'string', 'minLength': 1, 'description': 'Digest or stable identifier for the exact final checkout.'}, 'payee_identity': {'type': 'object', 'oneOf': [{'properties': {'binding': {'type': 'object', 'required': ['network', 'pay_to'], 'properties': {'pay_to': {'type': 'string', 'maxLength': 500, 'minLength': 1}, 'network': {'type': 'string', 'maxLength': 240, 'minLength': 1}}, 'additionalProperties': False}, 'provider': {'const': 'X402'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TRUSTED_MERCHANT_MAPPING'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'method'], 'properties': {'method': {'type': 'string', 'pattern': '^[a-z]+$'}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'MPP'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'TLS_SERVICE_ORIGIN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['connected_account_id', 'merchant_account_id'], 'properties': {'merchant_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}, 'connected_account_id': {'type': 'string', 'pattern': '^acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}, 'provider': {'const': 'STRIPE'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'STRIPE_ACCOUNT_CONFIGURATION'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'pattern': '^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$'}}, 'additionalProperties': False}}}, {'properties': {'binding': {'type': 'object', 'required': ['service_origin', 'provider_id'], 'properties': {'provider_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'service_origin': {'type': 'string', 'pattern': '^https://[^/?#]+$'}}, 'additionalProperties': False}, 'provider': {'const': 'CUSTOM'}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'const': 'HTTPS_WELL_KNOWN'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'format': 'uri', 'pattern': '^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$'}}, 'additionalProperties': False}}}], 'required': ['profile', 'provider', 'merchant_id', 'binding', 'verification'], 'properties': {'binding': {'type': 'object'}, 'profile': {'const': 'MANDATESHIELD_PAYEE_IDENTITY_V1'}, 'provider': {'enum': ['X402', 'MPP', 'STRIPE', 'CUSTOM'], 'type': 'string'}, 'merchant_id': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'verification': {'type': 'object', 'required': ['method', 'verifier', 'evidence_ref'], 'properties': {'method': {'enum': ['TRUSTED_MERCHANT_MAPPING', 'TLS_SERVICE_ORIGIN', 'STRIPE_ACCOUNT_CONFIGURATION', 'HTTPS_WELL_KNOWN'], 'type': 'string'}, 'verifier': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'evidence_ref': {'type': 'string', 'maxLength': 2048, 'minLength': 1}}, 'additionalProperties': False}}, 'description': 'Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document.', 'additionalProperties': False}, 'idempotency_key': {'type': 'string', 'pattern': '^[A-Za-z0-9._:~-]+$', 'maxLength': 256, 'minLength': 1, 'description': 'Unique identifier for this intended payment attempt.'}, 'credential_binding': {'type': 'string'}}, 'additionalProperties': True}, 'evidence': {'type': 'object', 'required': ['format', 'public_key'], 'properties': {'format': {'enum': ['jws', 'sd-jwt', 'http-message-signature'], 'type': 'string'}, 'compact': {'type': 'string'}, 'algorithm': {'enum': ['ES256', 'RS256', 'PS256'], 'type': 'string'}, 'signature': {'type': 'string'}, 'components': {'type': 'object'}, 'public_key': {'type': 'object'}, 'expected_nonce': {'type': 'string'}, 'signature_input': {'type': 'object'}, 'expected_audience': {'type': 'string'}, 'expected_authority': {'type': 'string'}}, 'additionalProperties': False}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'required': ['decision', 'score', 'receipt', 'checked_at', 'protocol', 'findings', 'risk', 'recommended_action', 'controls', 'mode', 'persisted', 'enforcement_authorized', 'assurance', 'signed_receipt', 'transparency', 'execution_authorization'], 'properties': {'mode': {'type': 'string'}, 'risk': {'type': 'object', 'required': ['level', 'requested_value', 'mandate_headroom', 'blocked_value', 'primary_reason'], 'properties': {'level': {'enum': ['CLEAR', 'GUARDED', 'ELEVATED', 'CRITICAL'], 'type': 'string'}, 'blocked_value': {'type': 'number', 'minimum': 0}, 'primary_reason': {'type': ['string', 'null']}, 'requested_value': {'type': ['number', 'null']}, 'mandate_headroom': {'type': ['number', 'null']}}}, 'error': {'type': 'string'}, 'score': {'type': 'integer', 'maximum': 100, 'minimum': 0, 'description': 'Deterministic control-coverage indicator, not a calibrated probability of fraud or loss.'}, 'receipt': {'type': 'string'}, 'controls': {'type': 'object', 'required': ['evaluated', 'passed'], 'properties': {'passed': {'type': 'integer', 'minimum': 0}, 'evaluated': {'type': 'integer', 'minimum': 0}}}, 'decision': {'enum': ['ALLOW', 'REVIEW', 'BLOCK'], 'type': 'string'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'message', 'severity'], 'properties': {'code': {'type': 'string'}, 'message': {'type': 'string'}, 'severity': {'enum': ['high', 'medium', 'low'], 'type': 'string'}}}}, 'protocol': {'type': 'string'}, 'assurance': {'type': 'object', 'required': ['status', 'format', 'key_trust', 'signature_valid', 'authority_valid', 'input_digest', 'findings']}, 'persisted': {'type': 'boolean'}, 'checked_at': {'type': 'string', 'format': 'date-time'}, 'transparency': {'type': 'object', 'required': ['status', 'uri'], 'properties': {'uri': {'type': 'string'}, 'status': {'enum': ['RECORDED', 'NOT_RECORDED'], 'type': 'string'}}}, 'signed_receipt': {'type': 'object', 'required': ['format', 'compact', 'receipt_id', 'key_id', 'jwks_uri', 'verify_uri', 'transparency_uri']}, 'recommended_action': {'type': 'string'}, 'enforcement_authorized': {'type': 'boolean', 'description': 'True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call.'}, 'execution_authorization': {'type': 'object', 'required': ['state', 'consumable', 'transition_uri', 'processor_integration_required'], 'properties': {'state': {'enum': ['RESERVED', 'NOT_RESERVED', 'ARCHIVAL_ONLY'], 'type': 'string'}, 'consumable': {'type': 'boolean'}, 'expires_at': {'type': ['string', 'null']}, 'transition_uri': {'type': 'string'}, 'processor_integration_required': {'type': 'boolean', 'const': True}}}}}
Hinzugefügt
verify_cryptographic_payment_authority
17. September 2026 12:36
Hinzugefügt
normalize_agent_payment_protocol
17. September 2026 12:36
Hinzugefügt
check_ai_payment_authority
17. September 2026 12:36