generated: '2026-09-19' method: searched source: https://mandateshield.com/reason-codes.json docs: https://mandateshield.com/standard verbatim_file: errors/mandateshield-com-reason-codes.json description: The stable reason-code registry of the Mandate Execution Boundary specification v2.4.0. These are decision finding codes (returned in findings[] on ALLOW/REVIEW/BLOCK decisions and as code on some HTTP errors), each with the meaning and the remediation action the provider publishes. Captured verbatim; this is the non-payments sibling of a decline-code table. specification: Mandate Execution Boundary version: 2.4.0 canonical: https://mandateshield.com/standard code_count: 91 envelope: field: findings[].code sibling_fields: - findings[].message - findings[].severity (low|medium|high observed) observed: POST /api/v1/preflight with {} on 2026-09-19 returned BLOCK with UNSUPPORTED_PROTOCOL, MISSING_MANDATE_ID, MISSING_AGENT_ID, MISSING_MERCHANT, INVALID_AMOUNT, INVALID_CURRENCY, MISSING_SPEND_CAP, NO_CURRENCY_SCOPE, NO_MERCHANT_SCOPE, MISSING_EXPIRY, CONSENT_NOT_PROVEN, REPLAY_GUARD_MISSING ... codes: - code: UNSUPPORTED_PROTOCOL meaning: The declared source protocol is not supported. action: Normalize the request to a supported protocol or CUSTOM. - code: UNSUPPORTED_CONSTRAINT_FIELD meaning: A strict production envelope contains fields the active verifier does not evaluate. action: Remove the field or adopt a versioned adapter that explicitly evaluates it. - code: HTTP_REQUEST_BINDING_INVALID meaning: The signed x402 HTTP action projection is malformed, non-canonical or not bound to the paid resource. action: Bind the exact canonical HTTPS URL, supported uppercase method, SHA-256 body/header digests and ERROR redirect policy. - code: MISSING_MANDATE_ID meaning: No stable identifier links the purchase to user authority. action: Provide the identifier of the approved mandate. - code: MISSING_AGENT_ID meaning: The acting agent cannot be identified. action: Bind the request to a stable agent identity. - code: MISSING_MERCHANT meaning: The final seller or payee is absent. action: Resolve the final merchant before authorization. - code: PAYEE_IDENTITY_INVALID meaning: The versioned payee identity has an invalid provider binding or verification-evidence shape. action: Use the canonical payee-identity v1 schema and independently verify the referenced trust evidence. - code: PAYEE_IDENTITY_MISMATCH meaning: The canonical payee identity does not match the envelope merchant. action: Block execution and bind the exact provider payee to the approved merchant. - code: INVALID_AMOUNT meaning: The proposed amount is missing, zero, negative or malformed. action: Provide a positive transaction value. - code: INVALID_CURRENCY meaning: The transaction currency is not a three-letter code. action: Provide an ISO 4217 currency code. - code: INVALID_ATOMIC_AMOUNT meaning: The atomic-asset amount or decimal exponent is missing or malformed. action: Provide a positive canonical integer string and asset_decimals from 0 through 30. - code: MISSING_ATOMIC_SPEND_CAP meaning: The registered atomic-asset authority has no exact unit ceiling. action: Register max_atomic_units and the exact asset_decimals value. - code: ATOMIC_DECIMALS_MISMATCH meaning: The proposed asset exponent differs from the registered mandate. action: Block execution and use the registered asset definition. - code: ATOMIC_SPEND_CAP_EXCEEDED meaning: The proposed atomic-unit amount is above the registered ceiling. action: Block execution or register a new mandate version. - code: ASSET_BINDING_MISSING meaning: The atomic payment does not identify its exact asset. action: Bind an explicit asset identifier into the signed envelope. - code: NO_ASSET_SCOPE meaning: The registered atomic mandate has no asset allowlist. action: Register an exact asset identifier. - code: ASSET_OUT_OF_SCOPE meaning: The proposed asset differs from the registered asset. action: Block execution or register a new mandate version. - code: NETWORK_BINDING_MISSING meaning: The atomic payment does not identify its network or chain. action: Bind an explicit network identifier into the signed envelope. - code: NO_NETWORK_SCOPE meaning: The registered atomic mandate has no network allowlist. action: Register an exact network identifier. - code: NETWORK_OUT_OF_SCOPE meaning: The proposed network differs from the registered network. action: Block execution or register a new mandate version. - code: RESOURCE_BINDING_MISSING meaning: The atomic payment does not identify the paid resource. action: Bind the exact resource identifier into the signed envelope. - code: NO_RESOURCE_SCOPE meaning: The registered atomic mandate has no resource allowlist. action: Register one or more exact resource identifiers. - code: RESOURCE_OUT_OF_SCOPE meaning: The paid resource is outside the registered scope. action: Block execution or register a new mandate version. - code: MISSING_SPEND_CAP meaning: The authority has no usable maximum amount. action: Register an explicit positive ceiling in integer minor units. - code: SPEND_CAP_EXCEEDED meaning: The final amount is above the registered maximum. action: Block execution or obtain a new mandate version. - code: NO_CURRENCY_SCOPE meaning: The mandate does not constrain transaction currency. action: Register one or more approved currencies. - code: CURRENCY_OUT_OF_SCOPE meaning: The final currency is outside the approved set. action: Block execution or obtain a new mandate version. - code: NO_MERCHANT_SCOPE meaning: The mandate does not constrain the final merchant. action: Register one or more approved merchant identifiers. - code: MERCHANT_OUT_OF_SCOPE meaning: The final seller differs from the approved merchant scope. action: Block execution or obtain a new mandate version. - code: MISSING_EXPIRY meaning: The authority has no defined expiration. action: Register a finite authorization deadline. - code: MANDATE_EXPIRED meaning: The registered authority is no longer valid. action: Block execution and obtain fresh authority. - code: LONG_EXPIRY_WINDOW meaning: The authority window is longer than the analysis profile recommends. action: Require REVIEW or shorten the mandate window. - code: CONSENT_NOT_PROVEN meaning: Explicit user consent is absent. action: Block execution until consent is recorded in a registered mandate. - code: REPLAY_GUARD_MISSING meaning: No unique payment-attempt identifier was supplied. action: Provide a stable idempotency key. - code: REPLAY_GUARD_INVALID meaning: The payment-attempt identifier is too long or contains unsafe characters. action: Use a unique 1–256 character ASCII identifier. - code: REPLAY_DETECTED meaning: The account already consumed this payment-attempt identifier. action: Block the duplicate and use the original receipt. - code: CONCURRENT_REPLAY_DETECTED meaning: Another request is consuming the same payment attempt. action: Block the concurrent duplicate and await the original result. - code: REPLAY_RECORD_UNAVAILABLE meaning: The payment attempt was finalized, but its exact response-recovery record is unavailable. action: Do not execute. Reconcile the original order and payment state before creating a new attempt. - code: PERSISTENCE_UNAVAILABLE meaning: The verifier could not durably commit the decision and replay boundary. action: Do not execute and retry only with the same idempotency key. - code: INTENT_HASH_MISSING meaning: The final purchase lacks an explicit intent digest. action: Bind the approved intent digest to the envelope. - code: IDENTITY_BINDING_MISSING meaning: The agent, merchant or credential chain is not bound. action: Provide protocol-native identity binding evidence. - code: CREATION_TIME_MISSING meaning: The purchase envelope has no unambiguous creation time. action: Add an ISO 8601 creation timestamp. - code: CREATION_TIME_IN_FUTURE meaning: The purchase timestamp exceeds the accepted clock skew. action: Block execution and verify the source clock. - code: STALE_PURCHASE_CONTEXT meaning: The purchase context is more than 24 hours old. action: Require REVIEW and refresh the final purchase facts. - code: AMOUNT_PRECISION_INVALID meaning: The amount cannot be represented in the currency's integer minor units. action: Block execution and provide an exact representable amount. - code: PROMPT_INJECTION_SIGNAL meaning: Heuristic text patterns suggest an attempted policy override. action: Require REVIEW; do not treat the heuristic as proof of compromise. - code: REGISTERED_MANDATE_REQUIRED meaning: No active account-registered mandate matches the production request. action: Register an immutable mandate version before live verification. - code: CRYPTOGRAPHIC_EVIDENCE_REQUIRED meaning: The strict profile received no signed authority evidence. action: Provide compact JWS, AP2 SD-JWT or TAP-style signed evidence. - code: CRYPTOGRAPHIC_EVIDENCE_MALFORMED meaning: The signed authority evidence is structurally incomplete. action: Correct its format, serialization and public verification key. - code: PROTOCOL_EVIDENCE_FORMAT_MISMATCH meaning: The evidence format does not match the declared protocol's strict profile. action: Use AP2 SD-JWT, TAP HTTP message signatures, or JWS for the declared JWS profile. - code: CRYPTOGRAPHIC_KEY_UNSAFE meaning: The public key type, curve or size is unsupported or unsafe. action: Use a supported P-256 or appropriately sized RSA public key. - code: CRYPTOGRAPHIC_SIGNATURE_INVALID meaning: The authority signature cannot be verified by the supplied public key. action: Block execution and obtain fresh evidence from the authority issuer. - code: CRYPTOGRAPHIC_EVIDENCE_EXPIRED meaning: The signed authority evidence has expired. action: Block execution and obtain freshly issued evidence. - code: CRYPTOGRAPHIC_EVIDENCE_NOT_YET_VALID meaning: The signed authority evidence is not yet valid. action: Block execution and verify clock and nbf claims. - code: CRYPTOGRAPHIC_EVIDENCE_FUTURE_IAT meaning: The signed authority evidence was issued in the future. action: Block execution and verify the issuer clock. - code: PRODUCTION_EVIDENCE_FRESHNESS_REQUIRED meaning: Live evidence lacks valid signed iat/exp or exceeds the 24-hour window. action: Obtain short-lived evidence with valid signed iat and exp. - code: CRYPTOGRAPHIC_AUDIENCE_MISMATCH meaning: The signed authority targets a different expected relying party. action: Block relay and obtain evidence for the current relying party. - code: CRYPTOGRAPHIC_NONCE_MISMATCH meaning: The signed nonce differs from the caller's additional expected nonce. action: Block verification and sign the correct challenge. - code: VERIFICATION_CHALLENGE_INVALID meaning: The signed server challenge is absent, expired, consumed or bound elsewhere. action: Request and sign a fresh one-time challenge. - code: VERIFICATION_KEY_THUMBPRINT_MISSING meaning: The verification key has no usable RFC 7638 thumbprint. action: Provide a well-formed supported public JWK. - code: UNTRUSTED_VERIFICATION_KEY meaning: The verification key is not actively pinned to this account and protocol. action: Pin the authority issuer's public JWK in the account control plane. - code: TRUSTED_ISSUER_MISMATCH meaning: The signed issuer differs from the issuer registered with the key pin. action: Block execution and obtain evidence from the registered issuer. - code: TRUSTED_AUDIENCE_MISMATCH meaning: The signed audience omits the relying party registered with the key pin. action: Block execution and obtain evidence for the registered audience. - code: SIGNED_INPUT_BINDING_MISSING meaning: The signed claims omit the canonical purchase digest. action: Sign the exact canonical envelope digest. - code: SIGNED_INPUT_BINDING_MISMATCH meaning: The signed purchase digest differs from the evaluated envelope. action: Block execution because the signed purchase was altered or substituted. - code: SD_JWT_HASH_ALGORITHM_UNSUPPORTED meaning: The SD-JWT uses an unsupported disclosure hash algorithm. action: Use sha-256 for selective-disclosure digests. - code: SD_JWT_DISCLOSURE_UNBOUND meaning: An SD-JWT disclosure is not committed by the issuer signature. action: Block execution and remove or correctly bind the disclosure. - code: SD_JWT_DISCLOSURE_DUPLICATE meaning: The same SD-JWT disclosure appears more than once. action: Block execution and issue a canonical non-duplicated credential. - code: SD_JWT_CLAIM_COLLISION meaning: A disclosure attempts to overwrite another signed or disclosed claim. action: Block execution and issue non-colliding claims. - code: SD_JWT_KEY_BINDING_REQUIRED meaning: The AP2 presentation omits its holder key-binding JWT. action: Present SD-JWT+KB with a holder proof bound by sd_hash. - code: SD_JWT_HOLDER_KEY_INVALID meaning: The issuer-signed holder confirmation key is absent or unsafe. action: Issue the credential with a supported public cnf.jwk holder key. - code: SD_JWT_KEY_BINDING_INVALID meaning: The holder proof is invalid or does not bind this SD-JWT presentation. action: Verify the holder key, audience, nonce, iat and sd_hash before retrying. - code: AP2_PAYMENT_AMOUNT_MISMATCH meaning: The signed AP2 payment mandate binds another amount or currency. action: Block execution and create authority for the final amount. - code: AP2_PAYMENT_AMOUNT_MISSING meaning: The closed AP2 payment mandate does not disclose a final amount. action: Fail closed and provide the complete closed payment mandate. - code: AP2_PAYEE_MISMATCH meaning: The signed AP2 mandate names another payee. action: Block merchant substitution and obtain new authority. - code: AP2_PAYEE_MISSING meaning: The closed AP2 payment mandate does not disclose its payee. action: Fail closed and provide the complete closed payment mandate. - code: AP2_MANDATE_TYPE_INVALID meaning: The evidence is not a supported closed AP2 payment mandate. action: Provide a mandate.payment.1 credential at execution time. - code: AP2_TRANSACTION_BINDING_MISSING meaning: The AP2 mandate or purchase envelope omits the final checkout hash. action: Bind transaction_id to the exact checkout token hash. - code: AP2_TRANSACTION_BINDING_MISMATCH meaning: The AP2 transaction_id names another checkout. action: Block checkout substitution and obtain a new closed mandate. - code: AP2_PAYMENT_INSTRUMENT_MISSING meaning: The AP2 mandate does not identify its payment instrument. action: Include non-secret payment instrument id and type references. - code: TAP_SIGNATURE_INPUT_MALFORMED meaning: The TAP signature input omits required components or parameters. action: Provide covered components, times, nonce, key ID and signature. - code: TAP_VERIFICATION_KEY_MISMATCH meaning: The TAP public key algorithm or declared usage does not permit this signature. action: Block execution and use a compatible verification key intended for signatures. - code: TAP_SIGNATURE_FRESHNESS_INVALID meaning: The TAP signature is stale, future-dated or valid for more than 15 minutes. action: Block execution and require a fresh message signature. - code: TAP_REQUIRED_COMPONENT_NOT_SIGNED meaning: The TAP signature omits a required request component. action: Sign @method, @authority, @path and content-digest. - code: TAP_METHOD_MISMATCH meaning: The signed TAP method is not POST. action: Block execution and sign the actual request method. - code: TAP_PATH_INVALID meaning: The signed TAP request path is not an absolute path. action: Block execution and sign the canonical absolute request path. - code: TAP_AUTHORITY_MISMATCH meaning: The TAP signature is bound to another merchant authority. action: Block relay to the current merchant. - code: TAP_CONTENT_DIGEST_MISMATCH meaning: The TAP content-digest does not bind the exact canonical envelope. action: Block execution and sign the final purchase body. - code: TAP_SIGNATURE_INVALID meaning: The TAP message signature cannot be verified. action: Block execution and obtain a valid signature from the pinned issuer. - code: EXECUTION_AUTHORITY_NOT_ESTABLISHED meaning: Policy passed but the result lacks live account-pinned execution authority. action: Do not execute; use live v2 with registered policy, pinned trust and a fresh challenge. - code: COMMUNITY_THREAT_SIGNAL meaning: A privacy-thresholded merchant fingerprint has independent cross-account reports. action: Require REVIEW and independent merchant verification; never auto-block from this signal alone.