mcp server
MandateShield AI Payment Evidence
Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.
Description as published by the maintainer. Source
- version 1.13.0
- active
- document understanding
active — Registry entry last updated 2026-07-28. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
3 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
check_ai_payment_authority(amount, limits, network, purpose, agent_id, asset_id, protocol, resource, created_at, expires_at, mandate_id, intent_hash, merchant_id, http_request, user_consent, checkout_hash, payee_identity, idempotency_key, credential_binding)- Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys. Required: protocol, mandate_id, agent_id, merchant_id, amount, idempotency_key.
normalize_agent_payment_protocol(source, adapter, context, selection)- Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance. Required: adapter, source, context.
verify_cryptographic_payment_authority(envelope, evidence)- Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome. Required: envelope, evidence.
Last successful function declaration observed on . Source: https://mandateshield.com/api/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mandateshield.com/api/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| Latest published version | 1.13.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-07-28 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| First listed in the MCP Registry | 2026-07-28 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| mcp tools declared | 3 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mandateshield.com | |
| mcp endpoint status | ok | The server listed 3 functions when asked. | as of probe | mandateshield.com |
Where to get it
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json