{"name":"MandateShield Payment Authority Agent","description":"Provides strict cryptographic reservation of AI-agent payment authority and a separate non-executable policy-analysis path. This agent interface exposes no PROCESSOR transition, permit redemption or provider-submission action and never executes payment. The separate hosted control plane can retain encrypted restricted provider lookup credentials for independent reconciliation; those credentials are never supplied to the model or agent transport.","supportedInterfaces":[{"url":"https://mandateshield.com/a2a","protocolBinding":"JSONRPC","protocolVersion":"1.0"},{"url":"https://mandateshield.com/a2a","protocolBinding":"JSONRPC","protocolVersion":"0.3"}],"provider":{"organization":"MandateShield","url":"https://mandateshield.com"},"version":"1.13.0","documentationUrl":"https://mandateshield.com/developers","capabilities":{"streaming":false,"pushNotifications":false,"extendedAgentCard":false,"extensions":[{"uri":"https://mandateshield.com/specifications/agent-card-extension/v1","description":"MandateShield payment-authority, activation and execution-boundary discovery.","params":{"identity":{"canonicalName":"MandateShield","canonicalDomain":"https://mandateshield.com","evaluation":"https://mandateshield.com/.well-known/mandateshield-evaluation.json"},"standardVersion":"2.4.0","paymentAuthorityDiscovery":"https://mandateshield.com/.well-known/agent-payment-authority.json","protocolCompatibility":{"preferredVersion":"1.0","legacyVersion":"0.3","emptyVersionHeaderMeans":"0.3","versionIsolation":"A2A v1 accepts only SendMessage with A2A-Version: 1.0. A2A v0.3 accepts only message/send with A2A-Version: 0.3 or an absent version header. Both profiles expose identical payment-safety boundaries and no PROCESSOR transition."},"challengeEndpoint":"https://mandateshield.com/api/v2/challenges","strictBatchEndpoint":"https://mandateshield.com/api/v2/batch","receiptTransparencyTemplate":"https://mandateshield.com/api/v2/transparency/{receipt_id}","publicActivationContracts":{"zeroAccountSandbox":{"endpoint":"https://mandateshield.com/api/v2/sandbox/lifecycle","specification":"https://mandateshield.com/specifications/strict-lifecycle-sandbox/v1","accountRequired":false,"testOnly":true,"simulated":true,"moneyMoved":false,"externalProviderContacted":false,"independentOrganizationInvolved":false,"productionAccepted":false},"proofNetwork":{"listEndpoint":"https://mandateshield.com/api/v1/proof-network/proofs","challengeEndpoint":"https://mandateshield.com/api/v1/proof-network/challenges","attestationEndpoint":"https://mandateshield.com/api/v1/proof-network/attestations","proofTemplate":"https://mandateshield.com/api/v1/proof-network/proofs/{proof_id}","badgeTemplate":"https://mandateshield.com/api/v1/proof-network/proofs/{proof_id}/badge.svg","specification":"https://mandateshield.com/specifications/proof-attestation/v1","attestationType":"EXTERNALLY_BOUND_SELF_REPORT","subjectBindingVerified":true,"claimantOutputsSelfReported":true,"countsAsUser":false,"countsAsInstallation":false,"independentConformanceClaimed":false,"certification":false,"nonAuthorizing":true},"deploymentActivationProofs":{"launch":"https://mandateshield.com/launch","page":"https://mandateshield.com/deployment-proofs","listEndpoint":"https://mandateshield.com/api/v1/deployment-proofs","proofTemplate":"https://mandateshield.com/api/v1/deployment-proofs/{proof_id}","humanTemplate":"https://mandateshield.com/deployment-proofs/{proof_id}","badgeTemplate":"https://mandateshield.com/api/v1/deployment-proofs/{proof_id}/badge.svg","specification":"https://mandateshield.com/specifications/deployment-activation-proof/v1","runnerReleaseManifest":"https://mandateshield.com/launch/runner-release.json","attestationType":"ACCOUNT_BOUND_SERVER_OBSERVED_ACTIVATION","accountBound":true,"privatePilotCompletionBeforePublication":true,"privateCompletionPublishesRecord":false,"publicationOptional":true,"publicationRequiredForPaidAccess":false,"explicitPublicationDirectionInSignedChallenge":false,"freshExplicitPublicationDirectionAtFinalize":true,"freshPublicationConsentRequiredAtFinalize":true,"publicationConsentRequestField":"publication_consent","publicationConsentRequiredValue":true,"publicRecordRequiresExplicitConsent":true,"publicationConsentVersion":"2026-07-28","subjectControlVerifiedAtBinding":true,"bindingVerifiedAtExposedPerRecord":true,"strictLiveReservationServerObserved":true,"freshCredentialBoundPermitRedemptionObserved":true,"mandateShieldProviderSubmissionObserved":false,"mandateShieldProviderEnforcementObserved":false,"providerEvidenceRecorded":false,"independentTerminalEvidenceVerified":false,"outOfBandActivityObserved":false,"operatorExclusionNoMatchAtEvaluation":true,"eligibilityEvaluatedAtExposedPerRecord":true,"operatorExclusionNoMatchIsIndependentIdentity":false,"countsAsCustomer":false,"countsAsRevenue":false,"deploymentRuntimeInspected":false,"nonBypassabilityVerified":false,"independentOrganizationVerified":false,"audit":false,"certification":false,"securityGuarantee":false,"nonAuthorizing":true}},"executionContract":{"analysisIsExecutable":false,"decision":"ALLOW","enforcementAuthorized":true,"mode":"live","persisted":true,"authorityValid":true,"keyTrust":"ACCOUNT_PINNED","authorizationState":"RESERVED","consumable":true,"processorConsumeRequired":true,"processorTransitionExposedToAgent":false,"processorTransitionEndpoint":"https://mandateshield.com/api/v2/execution-authorizations","recommendedPath":["VERIFY_RESERVE","CONSUME_WITH_PROVIDER_BINDING","ISSUE_SIGNED_EXECUTION_PERMIT","PROVIDER_OR_FACILITATOR_REDEEM","PROVIDER_OPERATION_WITH_SIGNED_IDEMPOTENCY_KEY","REPORT_PROVIDER_SUBMISSION","INDEPENDENT_PROVIDER_OR_CHAIN_VERIFICATION","AUTONOMOUS_COMMIT_OR_RELEASE","SIGNED_EXECUTION_RECEIPT"],"providerBoundConsumeIssuesPermit":true,"providerBoundConsumeSubmissionPermitted":false,"providerBoundConsumeRequiredForNewAccounts":true,"providerBoundConsumeRequiredFromAccountCreatedAt":"2026-07-26T12:01:24.000Z","legacyUnboundConsumeAllowedOnlyForAccountsCreatedBefore":"2026-07-26T12:01:24.000Z","missingAccountCreationTimeFailsClosed":true,"providerRedemptionRequired":true,"permitVerificationEndpoint":"https://mandateshield.com/api/v2/execution-permits/verify","permitRedemptionEndpoint":"https://mandateshield.com/api/v2/execution-permits/redeem","providerSubmissionEndpoint":"https://mandateshield.com/api/v2/provider-submissions","providerSubmissionSchema":"https://mandateshield.com/schemas/provider-submission-v1.json","providerEvidenceSchema":"https://mandateshield.com/schemas/provider-evidence-v1.json","reconciliationRecordSchema":"https://mandateshield.com/schemas/reconciliation-record-v1.json","executionAssuranceLevelSchema":"https://mandateshield.com/schemas/execution-assurance-level-v1.json","permitSpecification":"https://mandateshield.com/specifications/execution-permit/v1","permitSchema":"https://mandateshield.com/schemas/execution-permit-v1.json","permitMaximumLifetime":"PT60S","signatureOnlyVerificationPermitsSubmission":false,"freshRedemptionProviderSubmissionPermitField":"provider_submission_permitted","freshRedemptionRequiredStatus":"CLAIMED","freshRedemptionIdempotentReplay":false,"providerOperationIdempotencySource":"signed permit provider.idempotency_key","executionReceiptVerifyEndpoint":"https://mandateshield.com/api/v2/execution-receipts/verify","executionReceiptSpecification":"https://mandateshield.com/specifications/execution-receipt/v1","executionReceiptSchema":"https://mandateshield.com/schemas/execution-receipt-v1.json","executionReceiptPurpose":"HISTORICAL_EXECUTION_EVIDENCE","executionReceiptAuthorizesExecution":false,"manualProcessorResultEvidenceClass":"CALLER_ASSERTED","manualProcessorResultIndependentVerification":false,"independentProviderEvidenceClasses":["PROVIDER_API_VERIFIED","CHAIN_FINALIZED"],"independentProviderEvidenceCanFinalizeAuthorization":true,"webhookIsTerminalEvidence":false,"providerOrFacilitatorAdoptionClaimed":false,"providerRejectsPermitlessOperationsClaimed":false},"legacyDiscovery":{"url":"https://mandateshield.com/a2a","preferredTransport":"JSONRPC","additionalInterfaces":[{"url":"https://mandateshield.com/a2a","transport":"JSONRPC"}]}}}]},"securitySchemes":{"bearerAuth":{"httpAuthSecurityScheme":{"description":"Server-side VERIFY-scoped MandateShield API key. Never provide a PROCESSOR key to an agent or A2A client.","scheme":"Bearer","bearerFormat":"ms_test_... or ms_live_..."}}},"defaultInputModes":["application/json","text/plain"],"defaultOutputModes":["application/json","text/plain"],"skills":[{"id":"normalize-agent-payment-protocol","name":"Project Agent Payment Fields","description":"Map documented AP2 terminal closed-payment fields, x402 v2 PAYMENT-REQUIRED fields, or an explicitly profiled MPP Payment charge challenge into a deterministic purchase envelope. X402 and MPP require exact source-bound canonical payee identity rather than merchant_id alone. Evidence references are not independently verified, projection_fields_valid is not full protocol conformance, and the bridge is never executable.","tags":["AP2","x402 v2","MPP","payment protocol adapter","purchase envelope"],"examples":["Normalize this x402 v2 PAYMENT-REQUIRED offer before authority signing.","Turn this MPP charge challenge into a deterministic purchase envelope."],"inputModes":["application/json","text/plain"],"outputModes":["application/json","text/plain"]},{"id":"verify-cryptographic-payment-authority","name":"Verify Cryptographic Payment Authority","description":"Fail-closed production verification for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 and Visa TAP chain/trust-store processing remains external. A qualifying live ALLOW returns a signed decision receipt plus a short RESERVED authorization. It never executes payment and exposes no PROCESSOR transition, redemption or reporting action. Every account created at or after 2026-07-26T12:01:24.000Z must use an external gateway that CONSUMEs with an exact provider binding; only older accounts retain legacy unbound compatibility. Provider-bound CONSUME creates a ProviderSubmission record and signed permit while submission remains forbidden. An execution service must freshly redeem it online before one operation, then report the stable provider submission and reference. The caller report or webhook is only a hint; configured Stripe API or canonical x402 chain verification must independently confirm a terminal outcome before autonomous COMMIT or RELEASE. Offline verification never grants, and provider adoption is not claimed.","tags":["cryptographic authorization","signed mandate","SD-JWT","RFC 9421","AP2","TAP","decision receipt","account-pinned key","one-time challenge","cumulative budget reservation","processor handoff","provider-bound execution permit","atomic online redemption","provider reconciliation","independent provider evidence","signed execution receipt"],"examples":["Verify that this AP2-shaped closed-payment projection binds the final payee and amount.","Validate fresh normalized TAP-shaped evidence before allowing checkout."],"inputModes":["application/json"],"outputModes":["application/json"],"securityRequirements":[{"schemes":{"bearerAuth":{"list":["VERIFY"]}}}]},{"id":"check-ai-payment-authority","name":"Analyze AI Payment Policy","description":"Analyze a normalized purchase envelope against supplied policy facts. Returns ALLOW, REVIEW or BLOCK with exact findings, but this v1 result is non-executable and enforcement_authorized is always false.","tags":["agentic commerce","AI payments","payment authorization","AP2","UCP","TAP","x402","ACP"],"examples":["Check whether this $124.90 rail purchase stays inside a $150 AP2 mandate.","Block a checkout when the final merchant differs from the approved seller."],"inputModes":["application/json","text/plain"],"outputModes":["application/json","text/plain"]}],"signatures":[{"protected":"eyJhbGciOiJFUzI1NiIsImprdSI6Imh0dHBzOi8vbWFuZGF0ZXNoaWVsZC5jb20vLndlbGwta25vd24vandrcy5qc29uIiwia2lkIjoibWFuZGF0ZXNoaWVsZC1hZ2VudC1jYXJkLTIwMjYtMDEiLCJ0eXAiOiJKT1NFIn0","signature":"sgglg9zkVvFYUQJ-Q6hpH9z4oOLSZGNx4ws8gnXDiDesqo83Nk5GUn9nltoHM_AKxTsyMeL4RnUIccVfzcBMeQ"}]}