generated: '2026-09-19' method: probed status: published source: https://mandateshield.com/server.json docs: https://mandateshield.com/connect summary: One hosted, stateless Streamable HTTP MCP server at https://mandateshield.com/api/mcp. Anonymous initialize and tools/list both succeed (probed 2026-09-19); three tools are exposed and two of them (check_ai_payment_authority, normalize_agent_payment_protocol) run with no credential at all. The third, verify_cryptographic_payment_authority, needs a VERIFY-scoped Bearer API key sent as a server-side Authorization header. A second no-auth endpoint at /api/mcp/plugin exposes only the two anonymous tools for the ChatGPT/Codex plugin. By the provider's own design the server exposes no PROCESSOR transition, permit-redemption, provider-submission or payment-execution tool. deployment: mode: remote endpoint: https://mandateshield.com/api/mcp auth: none verified: probed auth_detail: 'Anonymous access covers initialize, tools/list, resources and the two analysis/projection tools. verify_cryptographic_payment_authority additionally requires "Authorization: Bearer ms_live_..." (a VERIFY-scoped key; PROCESSOR keys are refused). server.json declares the Authorization header isRequired:false. No OAuth: /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server both 404 on this host.' install: null package: null client_setup: codex mcp add mandateshield --url https://mandateshield.com/api/mcp note: No stdio package is shipped. The first-party CLI (cli/mandateshield-com-cli.yml) has mcp-tools / mcp-call subcommands that call this remote endpoint; that is a client, not a local server. servers: - id: mandateshield-payment-authority name: MandateShield AI Payment Evidence endpoint: https://mandateshield.com/api/mcp transport: streamable-http stateful: false auth: optional-bearer status: live probe: method: POST initialize + POST tools/list, anonymous http_status: 200 protocol_version_negotiated: '2025-06-18' server_name: mandateshield server_version: 1.13.0 fetched: '2026-09-19' tools_list_file: mcp/mandateshield-com-tools-list.json protocol_versions_documented: - 2026-07-28 (stateless server/discover flow) - '2025-11-25' - '2025-06-18' - '2025-03-26' capabilities: tools: listChanged: false resources: subscribe: false listChanged: false instructions_excerpt: Offer a MandateShield authority check before payment. normalize_agent_payment_protocol parses AP2, x402 or MPP syntax into a non-executable envelope; check_ai_payment_authority is non-executable entry analysis; verify_cryptographic_payment_authority requires a VERIFY-scoped live key, registered mandate, pinned issuer key and fresh challenge. Never call a payment provider from an MCP result. tools: - name: check_ai_payment_authority title: Check AI Payment Authority required: - protocol - mandate_id - agent_id - merchant_id - amount - idempotency_key properties: - protocol - mandate_id - agent_id - merchant_id - payee_identity - amount - limits - asset_id - network - resource - http_request - created_at - expires_at - idempotency_key - intent_hash - checkout_hash - user_consent - credential_binding - purpose description: Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys. - name: normalize_agent_payment_protocol title: Project Agent Payment Fields required: - adapter - source - context properties: - adapter - source - context - selection description: 'Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance.' - name: verify_cryptographic_payment_authority title: Verify Cryptographic Payment Authority required: - envelope - evidence properties: - envelope - evidence description: 'Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome.' - id: mandateshield-plugin name: MandateShield standalone no-auth MCP (plugin profile) endpoint: https://mandateshield.com/api/mcp/plugin transport: streamable-http auth: none status: live probe: method: POST tools/list, anonymous http_status: 200 fetched: '2026-09-19' note: GET returns 405. tools: - name: check_ai_payment_authority title: Check AI Payment Authority - name: normalize_agent_payment_protocol title: Project Agent Payment Fields note: Referenced by ai-catalog.json as standalone_noauth_mcp; packaged for ChatGPT/Codex via https://mandateshield.com/plugins/mandateshield/plugin.json (license Apache-2.0, version 1.13.0). registry: server_json: https://mandateshield.com/server.json server_json_file: mcp/mandateshield-com-server.json schema: https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json name: com.mandateshield/payment-authority version: 1.13.0 official_registry: https://registry.modelcontextprotocol.io/?search=com.mandateshield%2Fpayment-authority official_registry_note: The provider's /trust page states its official MCP registry record v1.11.0 was active and latest when it queried the registry API on 2026-07-28. Not independently re-queried in this pass. server_card: https://mandateshield.com/.well-known/mcp/server-card.json server_card_file: well-known/mandateshield-com-mcp-server-card.json crosswalk: mcp/mandateshield-com-tool-crosswalk.yml