openapi: 3.2.0 info: title: MandateShield Payment Authority Receipts API version: 3.4.0 description: Fail-closed authority verification, provider-bound execution permits and provider-outcome reconciliation that is caller-report-independent for autonomous AI-agent purchases. termsOfService: https://mandateshield.com/terms contact: name: Gökhan Vodinali · MandateShield operator url: https://mandateshield.com/legal email: support@hemelion.com servers: - url: https://mandateshield.com tags: - name: Receipts description: Public-key signed-receipt verification and privacy-safe issuance lookup. paths: /api/v2/receipts/verify: post: operationId: verifyDecisionReceipt tags: - Receipts summary: Verify a portable MandateShield decision receipt description: Verifies ES256 signature, receipt profile, temporal validity and claim structure. A valid signature is not execution readiness. enforcement_ready additionally requires supplied and matching expected_envelope and expected_audience values plus a matching public transparency record. requestBody: required: true content: application/json: schema: type: object additionalProperties: false required: - compact properties: compact: type: string maxLength: 20000 expected_envelope: {} expected_audience: type: string minLength: 1 expected_decision: {} responses: '200': description: Receipt signature and structure are valid content: application/json: schema: $ref: '#/components/schemas/ReceiptVerification' '400': description: Receipt is absent, malformed, expired or invalid content: application/json: schema: $ref: '#/components/schemas/Error' /api/v2/transparency/{receiptId}: get: operationId: getReceiptTransparency tags: - Receipts summary: Retrieve a privacy-safe retained receipt issuance record parameters: - in: path name: receiptId required: true schema: type: string pattern: ^msr_[a-f0-9]{32}$ responses: '200': description: Receipt issuance record content: application/mandateshield-transparency-record+json: schema: $ref: '#/components/schemas/TransparencyRecord' '400': $ref: '#/components/responses/BadRequest' '404': description: No transparency record exists for this receipt content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: Error: type: object required: - error properties: error: type: string code: type: string enforcement_authorized: type: boolean TransparencyRecord: type: object additionalProperties: false required: - receipt_id - receipt_hash - input_digest - decision_digest - decision - protocol - key_id - issued_at properties: receipt_id: type: string pattern: ^msr_[a-f0-9]{32}$ receipt_hash: type: string pattern: ^sha256:[a-f0-9]{64}$ input_digest: type: string pattern: ^sha256:[a-f0-9]{64}$ decision_digest: type: string pattern: ^sha256:[a-f0-9]{64}$ decision: type: string enum: - ALLOW - REVIEW - BLOCK - UNKNOWN protocol: type: string key_id: type: string issued_at: type: string format: date-time ReceiptVerification: type: object required: - valid - expired - protected_header - claims - transparency - private_audit_recorded - execution_context - enforcement_ready properties: valid: const: true expired: const: false transparency_uri: type: - string - 'null' protected_header: type: object claims: type: object transparency: type: object required: - recorded - matched - uri properties: recorded: type: boolean matched: type: boolean uri: type: - string - 'null' execution_context: type: object required: - input_matched - audience_matched - authorization_unexpired - authorization_state_active properties: input_matched: type: boolean audience_matched: type: boolean authorization_unexpired: type: boolean description: True only while the receipt's short signed execution window remains open. authorization_state_active: type: boolean description: True only while the account, API key, registered mandate version and pinned authority key remain active. private_audit_recorded: type: boolean description: True when the private execution-audit row for this receipt is still retained. enforcement_ready: type: boolean description: True only when signed execution authority is unexpired and active, the expected envelope and audience match, and the retained public transparency and private execution-audit records match. responses: BadRequest: description: Invalid JSON, shape or parameter content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: hostingSession: type: apiKey in: header name: OAI-Authenticated-User-Email description: Hosting-injected authenticated account-owner identity. The hosting boundary validates the user session and injects this assertion; callers cannot authenticate by supplying this header directly. State-changing control-plane requests additionally require the trusted same-origin check documented by the operation. bearerAuth: type: http scheme: bearer bearerFormat: ms_test_… or ms_live_… description: Keep API keys server-side and isolate them by purpose. VERIFY keys can issue challenges and strict decisions. Paid live PROCESSOR keys are bound to one processor_audience and can call only the execution-transition boundary. x-mandateshield-release: product_version: 1.13.0 openapi_version: 3.4.0 standard_version: 2.4.0 released_at: '2026-07-28T14:25:22.000Z' generated_at: '2026-07-28T14:25:22.000Z' status: current latest_pointer: https://mandateshield.com/current-release.json superseded_by: null canonical_versioned_documents: openapi: https://mandateshield.com/openapi/3.4.0.json llms: https://mandateshield.com/llms/1.13.0.txt llms_full: https://mandateshield.com/llms-full/1.13.0.txt discovery: https://mandateshield.com/discovery/1.13.0.json