ZBS Index What actually exists in applied AI, with the source next to it

mcp server

MandateShield AI Payment Evidence

Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.

Description as published by the maintainer. Source

  • version 1.13.0
  • active
  • document understanding

active — Registry entry last updated 2026-07-28. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.

What this server can do

3 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

check_ai_payment_authority(amount, limits, network, purpose, agent_id, asset_id, protocol, resource, created_at, expires_at, mandate_id, intent_hash, merchant_id, http_request, user_consent, checkout_hash, payee_identity, idempotency_key, credential_binding)
Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys. Required: protocol, mandate_id, agent_id, merchant_id, amount, idempotency_key.
normalize_agent_payment_protocol(source, adapter, context, selection)
Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance. Required: adapter, source, context.
verify_cryptographic_payment_authority(envelope, evidence)
Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome. Required: envelope, evidence.

Last successful function declaration observed on . Source: https://mandateshield.com/api/mcp. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://mandateshield.com/api/mcp.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
Latest published version 1.13.0 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-07-28 When the registry record was last updated by its maintainer. point in time Model Context Protocol
First listed in the MCP Registry 2026-07-28 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
mcp tools declared 3 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe mandateshield.com
mcp endpoint status ok The server listed 3 functions when asked. as of probe mandateshield.com

Where to get it

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Tools declared by the MCP server at https://mandateshield.com/api/mcp — mandateshield.com, observed , trust tier 1.
  2. Official MCP Registry — Model Context Protocol, observed , trust tier 1.