HTTP API
A strict production boundary with registered policy, cumulative budgets and durable reservations.
POST /api/v2/verifyLAST-MILE AUTHORITY BINDING
MandateShield carries supported signed final approval into the exact provider request, reserves budget, requires one fresh online permit claim and signs a terminal outcome checked against configured evidence without trusting the caller.
Per-attempt and cumulative amount, scope and expiry.
Finds an offer and prepares the final purchase facts.
Verifies signed authority and atomically reserves budget headroom.
Binds the provider request and freshly redeems one permit. The exclusive executor makes one idempotent operation; MandateShield then checks the supported outcome without trusting its report.
HTTP API
POST /api/v2/verifyProcessor API
POST /api/v2/execution-authorizationsMCP tool
POST /api/mcpA2A agent
/.well-known/agent-card.jsonOpen contract
/standardAVAILABLE
Deterministically evaluate the exact proposed action. This does not control whether a caller later executes it.
AVAILABLE
Atomically reserve cumulative budget and issue a short execution authorization. A reservation never grants permission to call a provider.
DEPLOYMENT-EARNED
Provider-bound CONSUME prepares one durable submission and signed permit while submission remains forbidden. A separate execution edge must freshly redeem the exact permit online before one operation. Current provider adoption is not claimed.
PROVIDER-SPECIFIC
Treat caller reports as hints, inspect a configured Stripe PaymentIntent or canonical x402 chain outcome without trusting that report, then commit, release or keep authority reserved.
AVAILABLE · FIRST-PARTY
Verify signed receipts, retained key rotation, release hashes and bounded model results. This is not an independent audit.
SUPPORTED EXECUTION BOUNDARY
Credentials stay with the existing provider. MandateShield receives only normalized authority facts and produces a portable signed reservation. A separate PROCESSOR key is bound to the gateway's exact audience and transitions that reservation with an exact provider binding. The transition prepares a durable submission and signs a short permit but does not unlock payment. A separate execution edge must freshly redeem the exact permit and request binding online; only the first non-replayed claim grants MandateShield authority. The customer-side Gate must then perform one idempotent operation through a configured provider adapter and report its observation. MandateShield checks supported configured Stripe or x402 outcomes without trusting that observation before finalizing. The hosted service does not require payment credentials, customers must not submit them, and the hosted service does not submit the payment.
START AT THE EXECUTION POINT