Directory Agents

MandateShield Payment Authority Agent

Self-identified

by MandateShield · A2A agent · mandateshield.com

Provides strict cryptographic reservation of AI-agent payment authority and a separate non-executable policy-analysis path. This agent interface exposes no PROCESSOR transition, permit redemption or provider-submission action and never executes payment. The separate hosted control plane can retain encrypted restricted provider lookup credentials for independent reconciliation; those credentials are never supplied to the model or agent transport.

  • A2A 0.3, 1.0
  • Version 1.13.3
  • Signed card
  • Checked 2026-10-02

AP2 TAP account-pinned key ACP agentic commerce

  • Project Agent Payment Fields normalize-agent-payment-protocol

    Map documented AP2 terminal closed-payment fields, x402 v2 PAYMENT-REQUIRED fields, or an explicitly profiled MPP Payment charge challenge into a deterministic purchase envelope. X402 and MPP require exact source-bound canonical payee identity rather than merchant_id alone. Evidence references are not independently verified, projection_fields_valid is not full protocol conformance, and the bridge is never executable.

    AP2 x402 v2 MPP payment protocol adapter purchase envelope
    2 examples
    • Normalize this x402 v2 PAYMENT-REQUIRED offer before authority signing.
    • Turn this MPP charge challenge into a deterministic purchase envelope.

    In: application/json, text/plain · Out: application/json, text/plain

  • Verify Cryptographic Payment Authority verify-cryptographic-payment-authority

    Fail-closed production verification for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 and Visa TAP chain/trust-store processing remains external. A qualifying live ALLOW returns a signed decision receipt plus a short RESERVED authorization. It never executes payment and exposes no PROCESSOR transition, redemption or reporting action. Every account created at or after 2026-07-26T12:01:24.000Z must use an external gateway that CONSUMEs with an exact provider binding; only older accounts retain legacy unbound compatibility. Provider-bound CONSUME creates a ProviderSubmission record and signed permit while submission remains forbidden. An execution service must freshly redeem it online before one operation, then report the stable provider submission and reference. The caller report or webhook is only a hint; configured Stripe API or canonical x402 chain verification must independently confirm a terminal outcome before autonomous COMMIT or RELEASE. Offline verification never grants, and provider adoption is not claimed.

    cryptographic authorization signed mandate SD-JWT RFC 9421 AP2 TAP decision receipt account-pinned key one-time challenge cumulative budget reservation processor handoff provider-bound execution permit atomic online redemption provider reconciliation independent provider evidence signed execution receipt
    2 examples
    • Verify that this AP2-shaped closed-payment projection binds the final payee and amount.
    • Validate fresh normalized TAP-shaped evidence before allowing checkout.

    In: application/json · Out: application/json

    Requires: bearerAuth (VERIFY)

  • Analyze AI Payment Policy check-ai-payment-authority

    Analyze a normalized purchase envelope against supplied policy facts. Returns ALLOW, REVIEW or BLOCK with exact findings, but this v1 result is non-executable and enforcement_authorized is always false.

    agentic commerce AI payments payment authorization AP2 UCP TAP x402 ACP
    2 examples
    • Check whether this $124.90 rail purchase stays inside a $150 AP2 mandate.
    • Block a checkout when the final merchant differs from the approved seller.

    In: application/json, text/plain · Out: application/json, text/plain

Interfaces

BindingA2A versionURL
JSONRPC Preferred1.0https://mandateshield.com/a2a
JSONRPC0.3https://mandateshield.com/a2a

Capabilities

Streaming
No
Push notifications
No
Extended card for signed-in callers
No
  • https://mandateshield.com/specifications/agent-card-extension/v1

Security and formats

Requires
Not declared
Schemes
bearerAuth (http)
Accepts
application/json, text/plain
Returns
application/json, text/plain

Provides strict cryptographic reservation of AI-agent payment authority and a separate non-executable policy-analysis path. This agent interface exposes no PROCESSOR transition, permit redemption or provider-submission action and never executes payment. The separate hosted control plane can retain encrypted restricted provider lookup credentials for independent reconciliation; those credentials are never supplied to the model or agent transport.

ID
mandateshield.com
Category
A2A agent
Provider
MandateShield
Agent version
1.13.3
Card status
Live
Checked
2026-10-02
Changed
2026-10-02
First seen
2026-10-01
Found through
Host list

Registrations

Reputation

Computed 2026-10-03

—No score yet
Confidence16%

A score shows from 30%

  • Identity40% of the score40 / 100

    1 verified source

    An ERC-8004 registration linked both ways adds 25.

  • Reviews35% of the score–

    No reviews yet

    From the ERC-8004 reputation registry, weighted by who wrote them.

  • Observed25% of the score–

    Not enough sightings yet

    Counts once it is seen on 10 or more Double Agent sites.

Change history

History since 2026-10-01