{"document_version":"1.0.0","profile":"MANDATESHIELD_PAYEE_IDENTITY_V1","status":"vendor-published-integration-contract","certification":false,"independent_attestation":false,"schema":"https://mandateshield.com/schemas/payee-identity-v1.json","specification":"https://mandateshield.com/specifications/payee-identity/v1","assurance_boundary":{"canonical_shape_validated":true,"exact_source_binding_validated_by_protocol_adapter":true,"external_evidence_independently_verified_by_normalizer":false,"source_protocol_credential_verified_by_normalizer":false,"provider_settlement_verified_by_model":false,"enforcement_authorized_by_model":false,"execution_requirement":"The identity must be inside the signed final envelope. A trusted gateway adapter must match its configured provider identity and obtain a fresh consume-once provider permit."},"profiles":[{"provider":"X402","canonical_binding":["network","pay_to"],"verification_method":"TRUSTED_MERCHANT_MAPPING","source_match":"network and pay_to must exactly match the selected PAYMENT-REQUIRED accepts entry","external_responsibility":"Use the optional first-party customer-side x402 Gate or another trusted integration to verify merchant mapping, the EIP-3009 signature, a latest-block unused-nonce anchor and canonical settlement. The hosted normalizer does not perform those checks."},{"provider":"MPP","canonical_binding":["service_origin","method"],"verification_method":"TLS_SERVICE_ORIGIN","source_match":"service_origin must exactly match the trusted resource origin and method must exactly match the Payment challenge","external_responsibility":"Independently verify the same-origin evidence, method credential, challenge store and settlement."},{"provider":"STRIPE","canonical_binding":["connected_account_id","merchant_account_id"],"verification_method":"STRIPE_ACCOUNT_CONFIGURATION","source_match":"both account identifiers and the evidence URN must match the customer-side adapter configuration","external_responsibility":"Keep Stripe credentials in the trusted gateway and verify the exact provider response."},{"provider":"CUSTOM","canonical_binding":["service_origin","provider_id"],"verification_method":"HTTPS_WELL_KNOWN","source_match":"provider_id must match the configured gateway adapter and evidence must be the exact same-origin /.well-known/mandateshield-payee.json URL","external_responsibility":"Fetch, authenticate, validate and freshness-check the domain-control document in the trusted integration."}],"limitations":["A caller-supplied merchant_id is never sufficient for these adapter profiles.","An evidence_ref is a signed reference, not proof that MandateShield fetched or independently validated the referenced evidence.","Field projection does not establish complete x402, MPP, Stripe or custom-provider conformance.","The model does not contain payment credentials and does not execute or settle payment."]}