agenttru.st

MandateShield Payment Authority Agent bronze

www.mandateshield.com

Provides strict cryptographic reservation of AI-agent payment authority and a separate non-executable policy-analysis path. This agent interface exposes no PROCESSOR transition, permit redemption or provider-submission action and never executes payment. The separate hosted control plane can retain encrypted restricted provider lookup credentials for independent reconciliation; those credentials are never supplied to the model or agent transport.

https://www.mandateshield.com/.well-known/agent-card.json its card
πŸ‡ΊπŸ‡Έ US Β· Cloudflare, Inc. Checked 10h ago extendedAgentCard, extensions, pushNotifications, streaming

we checked this    the operator says this

Community rating 0 0 up Β· 0 down β€” sign in to vote

Verified by agenttru.st

Everything here is a check agenttru.st performed itself. Assurance, protocol, hosting and freshness are in the card above and are not repeated.

Certificate
Issued by Google Trust Services domain-validated
Valid until 19 Dec 2026.
Control of the hostname was checked; nothing about who operates it.
DANE / TLSA
Not verified (TLSA query returned RCodeNameError)
Discovery
Well-known document
This host also publishes an ARD catalog (/.well-known/ai-catalog.json) declaring 10 resources. The catalog's entries are the publisher's claims, not something agenttru.st verified.
AI-facing documents
Publishes /llms.txt β€” “MandateShield” a curated map of the site's content for language models
Fetched from this host during verification. Neither document is how this agent was discovered.
First seen
22 Sep 2026
View verification details
Assurance
bronze Bronze β€” agent card fetched over HTTPS with a valid certificate
Protocols
A2A verified by handshake or card fetch, not merely advertised
Hosted in
πŸ‡ΊπŸ‡Έ US Β· Cloudflare, Inc. (AS13335)
Last checked
10h ago

What this agent says it can do

Declared in the agent's own card. agenttru.st has not tested whether it completes any of these tasks β€” the operator of www.mandateshield.com controls every word below.

Project Agent Payment Fields

Map documented AP2 terminal closed-payment fields, x402 v2 PAYMENT-REQUIRED fields, or an explicitly profiled MPP Payment charge challenge into a deterministic purchase envelope. X402 and MPP require exact source-bound canonical payee identity rather than merchant_id alone. Evidence references are not independently verified, projection_fields_valid is not full protocol conformance, and the bridge is never executable.

AP2x402 v2MPPpayment protocol adapterpurchase envelope
Examples it gives
  • Normalize this x402 v2 PAYMENT-REQUIRED offer before authority signing.
  • Turn this MPP charge challenge into a deterministic purchase envelope.

Verify Cryptographic Payment Authority

Fail-closed production verification for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 and Visa TAP chain/trust-store processing remains external. A qualifying live ALLOW returns a signed decision receipt plus a short RESERVED authorization. It never executes payment and exposes no PROCESSOR transition, redemption or reporting action. Every account created at or after 2026-07-26T12:01:24.000Z must use an external gateway that CONSUMEs with an exact provider binding; only older accounts retain legacy unbound compatibility. Provider-bound CONSUME creates a ProviderSubmission record and signed permit while submission remains forbidden. An execution service must freshly redeem it online before one operation, then report the stable provider submission and reference. The caller report or webhook is only a hint; configured Stripe API or canonical x402 chain verification must independently confirm a terminal outcome before autonomou

cryptographic authorizationsigned mandateSD-JWTRFC 9421AP2TAPdecision receiptaccount-pinned keyone-time challengecumulative budget reservationprocessor handoffprovider-bound execution permitatomic online redemptionprovider reconciliationindependent provider evidencesigned execution receipt
Examples it gives
  • Verify that this AP2-shaped closed-payment projection binds the final payee and amount.
  • Validate fresh normalized TAP-shaped evidence before allowing checkout.

Analyze AI Payment Policy

Analyze a normalized purchase envelope against supplied policy facts. Returns ALLOW, REVIEW or BLOCK with exact findings, but this v1 result is non-executable and enforcement_authorized is always false.

agentic commerceAI paymentspayment authorizationAP2UCPTAPx402ACP
Examples it gives
  • Check whether this $124.90 rail purchase stays inside a $150 AP2 mandate.
  • Block a checkout when the final merchant differs from the approved seller.

What its catalog declares

From the ARD catalog this host publishes at /.well-known/ai-catalog.json. The operator controls every entry; agenttru.st verified that the catalog exists and parses, and nothing about what the entries say.

MandateShield Agent Payment Authority Plugin

json

Auditable ChatGPT and Codex plugin package for non-executable payment-authority analysis and optional strict signed-authority reservation before buying, subscribing, transferring value, or invoking paid tools. Neither the plugin nor its MCP tools mediate provider egress, redeem permits, submit provider operations, or execute payments.

https://mandateshield.com/plugins/mandateshield/plugin.json

MandateShield AI Payment Authority MCP Server

mcp-server-card

Remote MCP server for non-executable payment-policy analysis, non-executable AP2/x402/MPP field projection, and strict signed-authority reservation before a separate execution-integrity boundary. It does not expose PROCESSOR transitions, execution-permit redemption, provider submission, or payment execution.

https://mandateshield.com/.well-known/mcp/server-card.json

MandateShield PostgreSQL DurableGatewayJournal

javascript

First-party customer-side PostgreSQL implementation of the Gateway v2 durable begin, primary-read and compare-and-set contract. Database credentials and journal rows stay in customer infrastructure. The readiness check does not attest routing, replication or failover, and split-brain writers are unsafe.

https://mandateshield.com/sdk/v1.13.0/mandateshield-postgres-gateway-journal.mjs

MandateShield Payment Authority A2A Agent

a2a-agent-card

A2A agent interface for payment-protocol field projection, policy analysis, and strict signed-authority verification. A qualifying strict result creates only a RESERVED authorization; the interface never executes payment and exposes no PROCESSOR transition, permit-redemption, or provider-submission action.

https://mandateshield.com/.well-known/agent-card.json

MandateShield Strict Lifecycle Sandbox

json

Zero-account POST endpoint that runs one isolated, request-local strict lifecycle with ephemeral authority, provider and artifact keys. It demonstrates challenge, reservation, one fresh permit claim, a separately signed simulated provider assertion, and terminal receipt verification without production credentials, caller-independent provider evidence, external organizations, outbound provider calls or money movement.

https://mandateshield.com/api/v2/sandbox/lifecycle

MandateShield Proof Network

mandateshield-proof-network

Public list of signed externally bound self-reports. MandateShield verifies control of an HTTPS domain or an exact public GitHub repository commit and the integrity of claimant-supplied offline-vector outputs; it does not execute the claimant implementation, count entries as users or installations, independently verify conformance, or issue certification.

https://mandateshield.com/api/v1/proof-network/proofs

And 4 more entries in the catalog, not shown here.

Technical agent card

Copied from the agent's card. The operator controls these values; agenttru.st has not verified them.

Provider
MandateShield β€” what this agent says about itself; other agents claiming the same provider are not thereby related
Protocol
a2a
Version
1.13.0
Auth schemes
bearerAuth
Extensions
https://mandateshield.com/specifications/agent-card-extension/v1
MandateShield payment-authority, activation and execution-boundary discovery.
A2A protocol extensions the card declares. A declared payment extension (AP2, x402) means the operator says the agent can transact, not that agenttru.st has seen it do so.
Card completeness
complete all eight fields required by a2a.proto v1.0
View all card details
Capabilities
extendedAgentCard extensions pushNotifications streaming
Agent card
https://www.mandateshield.com/.well-known/agent-card.json

Operate this agent and would rather not be listed? Request removal.