MCP 서버

MANDATE Credential Broker

io.github.projetnanocorp/mandate

이 MCP로 할 수 있는 일

Manages agent mandates, delegated permissions, policy-gated actions, short-lived credential grants, revocation, and audit proofs.

broker.introspect-grant
Introspect credential grant
Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.
입력 스키마
{'type': 'object', 'required': ['grant_token']}
broker.register-credential
Register credential handle
Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.
입력 스키마
{'type': 'object', 'required': ['organization_id', 'registered_by_agent_id', 'label', 'credential_type', 'vault_handle', 'allowed_action_type'], 'properties': {'metadata': {'type': 'object'}, 'vault_handle': {'type': 'string', 'description': 'Opaque vault reference such as vault://provider/path; never a plaintext secret.'}}}
broker.request-access
Request short-lived credential grant
Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.
입력 스키마
{'type': 'object', 'required': ['credential_id', 'acting_agent_id', 'mandate_id', 'action']}
broker.revoke-grant
Revoke credential grant
Revokes a broker grant by id and records the revocation to the ledger.
입력 스키마
{'type': 'object', 'required': ['revoked_by_agent_id', 'reason']}
broker.use
Use credential grant
Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.
입력 스키마
{'type': 'object', 'required': ['grant_token', 'acting_agent_id']}
mandate.authorize-action
Authorize gateway action
Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.
입력 스키마
{'type': 'object', 'required': ['acting_agent_id', 'action_type', 'amount_minor', 'counterparty']}
mandate.delegate
Delegate mandate
Creates a child mandate only when it is a no-escalation subset of the parent mandate.
입력 스키마
{'type': 'object', 'required': ['parent_mandate_id', 'delegator_agent_id', 'delegate_agent_id', 'budget_total', 'per_action_limit', 'starts_at', 'expires_at', 'scopes']}
mandate.discover
Discover MANDATE agent tools
Returns this self-describing tool manifest.
입력 스키마
{'type': 'object', 'properties': {}, 'additionalProperties': False}
mandate.mint
Mint root mandate
Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.
입력 스키마
{'type': 'object', 'required': ['organization_id', 'agent_id', 'grantor_principal_id', 'budget_currency', 'budget_total', 'per_action_limit', 'expires_at', 'scopes']}
mandate.revoke
Revoke mandate
Revokes a mandate subtree and records the revocation to the hash-chained ledger.
입력 스키마
{'type': 'object', 'required': ['revoked_by_principal_id', 'reason']}
mandate.verify-proof
Record or verify proof
Records a proof payload hash and appends proof evidence to the hash-chained ledger.
입력 스키마
{'type': 'object', 'required': ['organization_id', 'subject_type', 'subject_id', 'proof_type', 'payload']}
추가됨
broker.introspect-grant
2026년 9월 17일 12:49 PM
추가됨
broker.revoke-grant
2026년 9월 17일 12:49 PM
추가됨
broker.use
2026년 9월 17일 12:49 PM
추가됨
broker.request-access
2026년 9월 17일 12:49 PM
추가됨
broker.register-credential
2026년 9월 17일 12:49 PM
추가됨
mandate.revoke
2026년 9월 17일 12:49 PM
추가됨
mandate.verify-proof
2026년 9월 17일 12:49 PM
추가됨
mandate.authorize-action
2026년 9월 17일 12:49 PM
추가됨
mandate.delegate
2026년 9월 17일 12:49 PM
추가됨
mandate.mint
2026년 9월 17일 12:49 PM
추가됨
mandate.discover
2026년 9월 17일 12:49 PM