No payment credentials
The API needs authorization context, not card numbers, bank details or private keys. Settlement remains with the merchant's payment provider.
SECURITY ARCHITECTURE
MandateShield treats the payment boundary as a deterministic control point, independent of the model's reasoning.
The API needs authorization context, not card numbers, bank details or private keys. Settlement remains with the merchant's payment provider.
Strict v2 verifies the evidence signature and binds it to the final amount, merchant, audience, nonce or canonical purchase digest before policy checks run.
A durable uniqueness constraint blocks sequential and concurrent reuse of the same idempotency key.
ES256-signed receipts store digests, assurance and the policy outcome—not the full prompt, conversation or payment credential.
THREAT COVERAGE
BLOCKBLOCKBLOCKBLOCKBLOCKBLOCKBLOCKREVIEWBLOCKBLOCKBLOCKA passed policy check is not fraud insurance, legal approval or proof that an AI model is safe. Merchants remain responsible for payment authorization, sanctions screening, consumer law, chargebacks and their own risk controls. MandateShield adds a narrow, auditable control before those systems execute. The AP2 verifier validates the issuer-signed token, disclosed claim digests and payment bindings; a complete delegated multi-agent trust chain still requires the issuer's trust registry. x402 settlement and facilitator verification remain with the x402 payment stack.