REPLAY_DETECTEDThe account already consumed this payment-attempt identifier.
OPEN VENDOR SPECIFICATION · V2.4.0
The Mandate Execution Boundary separates policy analysis from a cryptographically trusted reservation that a gateway must consume before one exact provider submission.
decision = ALLOWenforcement_authorized = truemode = livepersisted = trueassurance.authority_valid = trueassurance.key_trust = ACCOUNT_PINNEDexecution_authorization.state = RESERVEDexecution_authorization.consumable = truePORTABLE CONTRACTS
STABLE REASON CODES
REPLAY_DETECTEDThe account already consumed this payment-attempt identifier.
REGISTERED_MANDATE_REQUIREDNo active account-registered mandate matches the production request.
VERIFICATION_CHALLENGE_INVALIDThe signed server challenge is absent, expired, consumed or bound elsewhere.
UNTRUSTED_VERIFICATION_KEYThe verification key is not actively pinned to this account and protocol.
TRUSTED_ISSUER_MISMATCHThe signed issuer differs from the issuer registered with the key pin.
TRUSTED_AUDIENCE_MISMATCHThe signed audience omits the relying party registered with the key pin.
SIGNED_INPUT_BINDING_MISMATCHThe signed purchase digest differs from the evaluated envelope.
EXECUTION_AUTHORITY_NOT_ESTABLISHEDPolicy passed but the result lacks live account-pinned execution authority.
This is an open, vendor-published technical contract and reference implementation. It is not represented as an accredited, regulated or consensus industry standard. Compatibility means implementing the published behavior; it does not imply certification by MandateShield.
REFERENCE IMPLEMENTATION