{"id":"https://mandateshield.com/evidence/v1/protocol-support.json","canonical":"https://mandateshield.com/evidence/protocol-support-matrix","version":"1.0.0","standard_version":"2.1.0","reviewed_on":"2026-07-24","title":"Agent Payment Protocol Support Matrix","description":"Machine-readable statement of the exact AP2, TAP, UCP, X402, ACP, CUSTOM and MPP integration boundary exposed by MandateShield strict v2.","status":"vendor-published-support-map","certification":false,"deployment_attestation":false,"methodology":{"review_date":"2026-07-24","evidence_policy":"Claims are mapped to public product contracts, current vendor-profile conformance vectors and primary official protocol sources. A vector is cited only when its current canonical ID directly exercises the stated behavior.","classification_rules":{"deterministic":"A normalized fact, cryptographic binding or durable state transition produces a reproducible fail-closed outcome.","advisory":"A contextual or heuristic signal may require REVIEW but is not proof of compromise and cannot create authority.","external":"The control is a required integration responsibility outside the boundary MandateShield can enforce."},"claim_boundary":"This is a vendor-published evidence map, not independent certification, a deployment attestation or proof of payment settlement."},"support_semantics":{"strict_v2_accepts_declared_protocol":"True only when the current strict API accepts the protocol enum with the listed evidence format.","native_protocol_payload_accepted":"True only when an unadapted source-protocol payload is parsed directly. The current normalized API sets this false for every listed protocol.","integrator_normalization":"Where required, the integrator owns parsing the source protocol, mapping every material final-purchase fact and creating the documented evidence projection."},"sources":[{"id":"mandateshield-standard","title":"Mandate Execution Boundary Specification v2.1.0","publisher":"MandateShield","url":"https://mandateshield.com/standard","kind":"product-contract"},{"id":"mandateshield-security","title":"MandateShield security architecture","publisher":"MandateShield","url":"https://mandateshield.com/security","kind":"product-contract"},{"id":"mandateshield-methodology","title":"MandateShield methodology and evidence","publisher":"MandateShield","url":"https://mandateshield.com/methodology","kind":"product-contract"},{"id":"mandateshield-conformance","title":"MandateShield Conformance Profile v1","publisher":"MandateShield","url":"https://mandateshield.com/conformance/v1/vectors.json","kind":"test-profile"},{"id":"mandateshield-openapi","title":"MandateShield OpenAPI contract","publisher":"MandateShield","url":"https://mandateshield.com/openapi.json","kind":"product-contract"},{"id":"ap2","title":"Agent Payments Protocol specification","publisher":"Agent Payments Protocol","url":"https://ap2-protocol.org/ap2/specification/","kind":"official-specification"},{"id":"ucp","title":"Universal Commerce Protocol official specification","publisher":"Universal Commerce Protocol","url":"https://ucp.dev/2026-04-08/specification/overview/","kind":"official-specification"},{"id":"tap","title":"Trusted Agent Protocol specifications","publisher":"Visa","url":"https://developer.visa.com/capabilities/trusted-agent-protocol/trusted-agent-protocol-specifications/","kind":"official-specification"},{"id":"x402","title":"x402 documentation","publisher":"Coinbase Developer Platform","url":"https://docs.cdp.coinbase.com/x402/welcome","kind":"official-specification"},{"id":"acp","title":"Agentic Commerce Protocol documentation","publisher":"Stripe","url":"https://docs.stripe.com/agentic-commerce/protocol","kind":"official-specification"},{"id":"mpp","title":"Machine Payments Protocol","publisher":"Tempo and Stripe","url":"https://mpp.dev/","kind":"official-specification"},{"id":"rfc7515","title":"RFC 7515: JSON Web Signature","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc7515","kind":"official-specification"},{"id":"rfc7638","title":"RFC 7638: JSON Web Key Thumbprint","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc7638","kind":"official-specification"},{"id":"rfc9421","title":"RFC 9421: HTTP Message Signatures","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc9421","kind":"official-specification"},{"id":"rfc9901","title":"RFC 9901: Selective Disclosure for JWTs","publisher":"RFC Editor","url":"https://www.rfc-editor.org/rfc/rfc9901","kind":"official-specification"}],"protocols":[{"id":"ap2","protocol":"AP2","full_name":"Agentic Payment Protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"SUPPORTED_EVIDENCE_PROFILE","accepted_evidence_format":"sd-jwt","normalization_owner":"integrator","what_is_verified":["Closed mandate.payment.1 projection","RFC 9901 key-binding JWT","Payment amount and currency","Payee and transaction binding","Account-pinned issuer trust"],"integrator_responsibilities":["Project the final closed-payment evidence into the documented API evidence object.","Validate the wider checkout_jwt hash and delegate chain.","Operate or rely on the appropriate issuer trust registry."],"limitations":["Open mandates are not accepted by the strict closed-payment profile.","The wider AP2 checkout/delegate chain is not processed natively."],"conformance_vector_ids":["ap2-holder-proof-required"],"source_ids":["ap2","rfc9901","mandateshield-conformance","mandateshield-openapi"]},{"id":"tap","protocol":"TAP","full_name":"Trusted Agent Protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"NORMALIZED_PROJECTION","accepted_evidence_format":"http-message-signature","normalization_owner":"integrator","what_is_verified":["Normalized RFC 9421-style signature projection","Method, authority, path and content-digest coverage","Created, expiry, nonce and signature","Exact purchase-envelope content digest","Account-pinned key trust"],"integrator_responsibilities":["Parse and normalize upstream Visa structured fields.","Apply the appropriate Visa trust-store and participant onboarding rules.","Supply the documented normalized components and signature input."],"limitations":["Raw Visa structured fields are not parsed natively.","MandateShield does not implement the full Visa trust-store profile."],"conformance_vector_ids":["tap-required-component-omitted"],"source_ids":["tap","rfc9421","mandateshield-conformance","mandateshield-openapi"]},{"id":"ucp","protocol":"UCP","full_name":"Universal Commerce Protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"INTEGRATOR_NORMALIZATION_REQUIRED","accepted_evidence_format":"jws","normalization_owner":"integrator","what_is_verified":["Normalized final purchase envelope","Compact JWS signature and exact input digest","Account-pinned issuer, audience and protocol","Registered mandate policy and execution state"],"integrator_responsibilities":["Resolve UCP version, negotiated capabilities and checkout state.","Normalize the final total, merchant and checkout facts.","Create the documented signed JWS projection."],"limitations":["Raw UCP service messages and capability negotiation are not parsed natively.","UCP interoperability does not replace payment-authority or gateway controls."],"conformance_vector_ids":[],"source_ids":["ucp","rfc7515","mandateshield-openapi"]},{"id":"x402","protocol":"X402","full_name":"x402 payment protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"INTEGRATOR_NORMALIZATION_REQUIRED","accepted_evidence_format":"jws","normalization_owner":"integrator","what_is_verified":["Canonical atomic-unit string","Asset decimal exponent","Asset, network, resource and merchant scope","Compact JWS and exact input digest","Registered mandate and replay state"],"integrator_responsibilities":["Parse the selected HTTP 402 payment requirement.","Normalize exact asset, network, resource and payee identifiers.","Construct or submit payment only after the required gateway transition."],"limitations":["HTTP 402 challenges and payment credentials are not parsed natively.","MandateShield does not call an x402 facilitator or execute settlement."],"conformance_vector_ids":["x402-exact-beyond-safe-integer","x402-one-unit-over-cap","x402-resource-substitution"],"source_ids":["x402","rfc7515","mandateshield-conformance","mandateshield-openapi"]},{"id":"acp","protocol":"ACP","full_name":"Agentic Commerce Protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"INTEGRATOR_NORMALIZATION_REQUIRED","accepted_evidence_format":"jws","normalization_owner":"integrator","what_is_verified":["Normalized final checkout facts","Compact JWS and exact input digest","Registered amount, currency and merchant scope","Account-pinned issuer trust and replay state"],"integrator_responsibilities":["Validate and resolve the current ACP checkout session.","Normalize the final cart, total, merchant and fulfillment context.","Keep payment credentials and provider submission in the existing payment stack."],"limitations":["ACP checkout sessions are not parsed natively.","Fulfillment and payment processing remain with the merchant and provider."],"conformance_vector_ids":[],"source_ids":["acp","rfc7515","mandateshield-openapi"]},{"id":"custom","protocol":"CUSTOM","full_name":"Integrator-defined normalized protocol","strict_v2_accepts_declared_protocol":true,"native_protocol_payload_accepted":false,"support_status":"INTEGRATOR_NORMALIZATION_REQUIRED","accepted_evidence_format":"jws","normalization_owner":"integrator","what_is_verified":["Documented normalized purchase-envelope fields","Compact JWS and exact canonical input digest","Account-pinned issuer, audience and CUSTOM protocol","Registered mandate, replay and execution state"],"integrator_responsibilities":["CUSTOM normalization is integrator work.","Map the source protocol into every required normalized field.","Sign the exact final envelope with a registered issuer key.","Maintain source-protocol validation outside MandateShield."],"limitations":["CUSTOM is not a universal parser or automatic adapter.","Source fields omitted during normalization cannot be evaluated or bound."],"conformance_vector_ids":["jws-final-envelope-substitution"],"source_ids":["rfc7515","mandateshield-standard","mandateshield-conformance","mandateshield-openapi"]},{"id":"mpp","protocol":"MPP","full_name":"Machine Payments Protocol","strict_v2_accepts_declared_protocol":false,"native_protocol_payload_accepted":false,"support_status":"NOT_NATIVELY_ACCEPTED","accepted_evidence_format":null,"normalization_owner":"integrator","what_is_verified":[],"integrator_responsibilities":["MPP is not natively accepted as a declared protocol by the current API.","To use MandateShield beside MPP, an integrator must normalize the final MPP payment facts to CUSTOM and supply the documented compact JWS evidence.","Keep MPP challenge, credential and payment execution processing outside MandateShield."],"limitations":["There is no native MPP parser, evidence profile or MPP-specific conformance vector.","A CUSTOM bridge is integrator work and must not be represented as native MPP support."],"conformance_vector_ids":[],"source_ids":["mpp","mandateshield-openapi"]}]}