openapi: 3.2.0 info: title: MandateShield Payment Authority Public sandbox API version: 3.4.0 description: Fail-closed authority verification, provider-bound execution permits and provider-outcome reconciliation that is caller-report-independent for autonomous AI-agent purchases. termsOfService: https://mandateshield.com/terms contact: name: Gökhan Vodinali · MandateShield operator url: https://mandateshield.com/legal email: support@hemelion.com servers: - url: https://mandateshield.com tags: - name: Public sandbox description: Zero-account, test-only and request-local lifecycle simulation. It uses ephemeral keys, contacts no external provider or independent organization, retains no lifecycle state and moves no money. externalDocs: url: https://mandateshield.com/specifications/strict-lifecycle-sandbox/v1 paths: /api/v2/sandbox/lifecycle: post: operationId: runStrictLifecycleSandbox tags: - Public sandbox summary: Run one isolated strict-lifecycle simulation description: Zero-account demonstration that accepts no Authorization credential and exercises the real cryptographic and lifecycle validators with fresh ephemeral keys. The request-local simulation covers challenge, strict authority, atomic reservation, provider-bound permit issuance, one successful claim, replay rejection, simulated provider evidence, COMMIT and signed execution-receipt verification. It is always test_only=true, money_moved=false and production_accepted=false. It retains no lifecycle state, accepts no user-supplied outbound URL, contacts no external provider or independent organization, and does not prove production conformance, third-party validation, audit or certification. security: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StrictLifecycleSandboxRequest' example: {} responses: '200': description: Completed request-local test-only lifecycle simulation content: application/json: schema: $ref: '#/components/schemas/StrictLifecycleSandboxResult' '400': $ref: '#/components/responses/BadRequest' '413': $ref: '#/components/responses/TooLarge' '415': description: Request is not application/json content: application/json: schema: $ref: '#/components/schemas/Error' '429': description: Public sandbox rate limit exceeded content: application/json: schema: $ref: '#/components/schemas/Error' '503': description: The isolated lifecycle simulation failed closed content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: Error: type: object required: - error properties: error: type: string code: type: string enforcement_authorized: type: boolean StrictLifecycleSandboxResult: type: object additionalProperties: false required: - mode - profile - test_only - money_moved - production_accepted - run_id - provider - isolation - summary - assurance_boundary - steps - public_keys - artifacts - verification - timestamps properties: mode: const: strict-lifecycle-sandbox/test-only profile: const: MANDATESHIELD_STRICT_LIFECYCLE_SANDBOX_V1 test_only: const: true money_moved: const: false production_accepted: const: false run_id: type: string minLength: 1 provider: type: object additionalProperties: true required: - id - environment - simulated - external_provider - independent_organization - outbound_calls - money_moved properties: id: const: MANDATESHIELD_SANDBOX_PROVIDER_V1 environment: const: test simulated: const: true external_provider: const: false independent_organization: const: false outbound_calls: const: 0 money_moved: const: false isolation: type: object additionalProperties: true required: - request_local - persistent_lifecycle_state - lifecycle_state_retained_after_response - production_credentials_used - user_supplied_outbound_urls_accepted - abuse_counter_persistence_only properties: request_local: const: true persistent_lifecycle_state: const: false lifecycle_state_retained_after_response: const: false production_credentials_used: const: false user_supplied_outbound_urls_accepted: const: false abuse_counter_persistence_only: const: true summary: type: object additionalProperties: true required: - decision - final_state - permit_one_use_enforced - permit_replay_blocked - third_party_evidence - independent_organization - money_moved properties: decision: const: ALLOW final_state: const: COMMITTED permit_one_use_enforced: const: true permit_replay_blocked: const: true third_party_evidence: const: false independent_organization: const: false money_moved: const: false assurance_boundary: type: object additionalProperties: false required: - separate_cryptographic_roles_verified - external_provider_contacted - independent_organization_involved - external_provider_outcome_verified - production_strong_evidence_proven - third_party_audit_or_certification - production_conformance_proven properties: separate_cryptographic_roles_verified: const: true external_provider_contacted: const: false independent_organization_involved: const: false external_provider_outcome_verified: const: false production_strong_evidence_proven: const: false third_party_audit_or_certification: const: false production_conformance_proven: const: false steps: type: array minItems: 1 items: type: object additionalProperties: true required: - sequence - id - title - status - detail properties: sequence: type: integer minimum: 1 id: type: string title: type: string status: type: string enum: - COMPLETED - VERIFIED - RECORDED detail: type: string public_keys: type: object additionalProperties: true artifacts: type: object additionalProperties: true verification: type: object additionalProperties: true timestamps: type: object additionalProperties: false required: - started_at - completed_at properties: started_at: type: string format: date-time completed_at: type: string format: date-time StrictLifecycleSandboxRequest: type: object additionalProperties: false maxProperties: 1 properties: scenario: const: SUCCESS responses: TooLarge: description: Request exceeds the endpoint size limit content: application/json: schema: $ref: '#/components/schemas/Error' BadRequest: description: Invalid JSON, shape or parameter content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: hostingSession: type: apiKey in: header name: OAI-Authenticated-User-Email description: Hosting-injected authenticated account-owner identity. The hosting boundary validates the user session and injects this assertion; callers cannot authenticate by supplying this header directly. State-changing control-plane requests additionally require the trusted same-origin check documented by the operation. bearerAuth: type: http scheme: bearer bearerFormat: ms_test_… or ms_live_… description: Keep API keys server-side and isolate them by purpose. VERIFY keys can issue challenges and strict decisions. Paid live PROCESSOR keys are bound to one processor_audience and can call only the execution-transition boundary. x-mandateshield-release: product_version: 1.13.0 openapi_version: 3.4.0 standard_version: 2.4.0 released_at: '2026-07-28T14:25:22.000Z' generated_at: '2026-07-28T14:25:22.000Z' status: current latest_pointer: https://mandateshield.com/current-release.json superseded_by: null canonical_versioned_documents: openapi: https://mandateshield.com/openapi/3.4.0.json llms: https://mandateshield.com/llms/1.13.0.txt llms_full: https://mandateshield.com/llms-full/1.13.0.txt discovery: https://mandateshield.com/discovery/1.13.0.json