MandateShield AI Payment Evidence

Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
85%
Qualität der Benennung
80%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (2)

  • LOWTool 'normalize_agent_payment_protocol' name length outside 3-30 rangein normalize_agent_payment_protocol
  • LOWTool 'verify_cryptographic_payment_authority' name length outside 3-30 rangein verify_cryptographic_payment_authority

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~8,310Tokens (Tool-Definitionen)
~32.4 KBTypische Antwortgröße
Erhebliche Auswirkung auf die Aufmerksamkeit (6.49% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "payment-authority": {
      "url": "https://mandateshield.com/api/mcp"
    }
  }
}

Remote-Endpunkte

https://mandateshield.com/api/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (3)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟡check_ai_payment_authority(protocol, mandate_id, agent_id, merchant_id, payee_identity, ...)

Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "protocol": {
      "type": "string",
      "enum": [
        "AP2",
        "TAP",
        "UCP",
        "X402",
        "MPP",
        "ACP",
        "CUSTOM"
      ],
      "description": "Source protocol or CUSTOM for a normalized envelope."
    },
    "mandate_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the user-approved authority."
    },
    "agent_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the acting AI agent."
    },
    "merchant_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the final seller or payee."
    },
    "payee_identity": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "profile",
        "provider",
        "merchant_id",
        "binding",
        "verification"
      ],
      "properties": {
        "profile": {
          "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
        },
        "provider": {
          "type": "string",
          "enum": [
            "X402",
            "MPP",
            "STRIPE",
            "CUSTOM"
          ]
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "binding": {
          "type": "object"
        },
        "verification": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "method",
            "verifier",
            "evidence_ref"
          ],
          "properties": {
            "method": {
              "type": "string",
              "enum": [
                "TRUSTED_MERCHANT_MAPPING",
                "TLS_SERVICE_ORIGIN",
                "STRIPE_ACCOUNT_CONFIGURATION",
                "HTTPS_WELL_KNOWN"
              ]
            },
            "verifier": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "evidence_ref": {
              "type": "string",
              "minLength": 1,
              "maxLength": 2048
            }
          }
        }
      },
      "oneOf": [
        {
          "properties": {
            "provider": {
              "const": "X402"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "network",
                "pay_to"
              ],
              "properties": {
                "network": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "pay_to": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 500
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "TRUSTED_MERCHANT_MAPPING"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "MPP"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "service_origin",
                "method"
              ],
              "properties": {
                "service_origin": {
                  "type": "string",
                  "pattern": "^https://[^/?#]+$"
                },
                "method": {
                  "type": "string",
                  "pattern": "^[a-z]+$"
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "TLS_SERVICE_ORIGIN"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "STRIPE"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "connected_account_id",
                "merchant_account_id"
              ],
              "properties": {
                "connected_account_id": {
                  "type": "string",
                  "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                },
                "merchant_account_id": {
                  "type": "string",
                  "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "STRIPE_ACCOUNT_CONFIGURATION"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "CUSTOM"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "service_origin",
                "provider_id"
              ],
              "properties": {
                "service_origin": {
                  "type": "string",
                  "pattern": "^https://[^/?#]+$"
                },
                "provider_id": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "HTTPS_WELL_KNOWN"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "format": "uri",
                  "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                }
              }
            }
          }
        }
      ],
      "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
    },
    "amount": {
      "type": "object",
      "additionalProperties": false,
      "oneOf": [
        {
          "required": [
            "value",
            "currency"
          ]
        },
        {
          "required": [
            "atomic_units",
            "asset_decimals"
          ]
        }
      ],
      "properties": {
        "value": {
          "type": "number",
          "exclusiveMinimum": 0
        },
        "minor_units": {
          "type": "integer",
          "minimum": 1,
          "description": "Optional exact integer amount in the currency's minor unit."
        },
        "currency": {
          "type": "string",
          "pattern": "^[A-Za-z]{3}$",
          "description": "Three-letter ISO currency code."
        },
        "atomic_units": {
          "type": "string",
          "pattern": "^(?:0|[1-9][0-9]{0,77})$",
          "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        }
      }
    },
    "limits": {
      "type": "object",
      "properties": {
        "max_amount": {
          "type": "number",
          "exclusiveMinimum": 0
        },
        "max_amount_minor": {
          "type": "integer",
          "exclusiveMinimum": 0
        },
        "max_atomic_units": {
          "type": "string",
          "pattern": "^[1-9][0-9]{0,77}$"
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        },
        "currencies": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "pattern": "^[A-Za-z]{3}$"
          }
        },
        "merchants": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "assets": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "networks": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "resources": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        }
      },
      "oneOf": [
        {
          "required": [
            "currencies",
            "merchants"
          ],
          "anyOf": [
            {
              "required": [
                "max_amount_minor"
              ]
            },
            {
              "required": [
                "max_amount"
              ]
            }
          ]
        },
        {
          "required": [
            "max_atomic_units",
            "asset_decimals",
            "assets",
            "networks",
            "resources",
            "merchants"
          ]
        }
      ],
      "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
    },
    "asset_id": {
      "type": "string",
      "minLength": 1,
      "description": "Exact token or asset identifier; required for atomic X402 payments."
    },
    "network": {
      "type": "string",
      "minLength": 1,
      "description": "Exact network or chain identifier; required for atomic X402 payments."
    },
    "resource": {
      "type": "string",
      "minLength": 1,
      "description": "Exact paid resource identifier; required for atomic X402 payments."
    },
    "http_request": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "profile",
        "url",
        "method",
        "body_sha256",
        "headers_sha256",
        "redirect_policy"
      ],
      "properties": {
        "profile": {
          "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
        },
        "url": {
          "type": "string",
          "format": "uri"
        },
        "method": {
          "type": "string",
          "enum": [
            "GET",
            "HEAD",
            "POST",
            "PUT",
            "PATCH",
            "DELETE"
          ]
        },
        "body_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "headers_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "redirect_policy": {
          "const": "ERROR"
        }
      },
      "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
    },
    "created_at": {
      "type": "string",
      "format": "date-time"
    },
    "expires_at": {
      "type": "string",
      "format": "date-time"
    },
    "idempotency_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 256,
      "pattern": "^[A-Za-z0-9._:~-]+$",
      "description": "Unique identifier for this intended payment attempt."
    },
    "intent_hash": {
      "type": "string"
    },
    "checkout_hash": {
      "type": "string",
      "minLength": 1,
      "description": "Digest or stable identifier for the exact final checkout."
    },
    "user_consent": {
      "type": "boolean"
    },
    "credential_binding": {
      "type": "string"
    },
    "purpose": {
      "type": "string",
      "description": "Non-sensitive plain-language purchase purpose."
    }
  },
  "required": [
    "protocol",
    "mandate_id",
    "agent_id",
    "merchant_id",
    "amount",
    "idempotency_key"
  ],
  "additionalProperties": true
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "decision": {
      "type": "string",
      "enum": [
        "ALLOW",
        "REVIEW",
        "BLOCK"
      ]
    },
    "score": {
      "type": "integer",
      "minimum": 0,
      "maximum": 100,
      "description": "Deterministic control-coverage indicator, not a calibrated probability of fraud or loss."
    },
    "receipt": {
      "type": "string"
    },
    "checked_at": {
      "type": "string",
      "format": "date-time"
    },
    "protocol": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "required": [
          "code",
          "message",
          "severity"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "high",
              "medium",
              "low"
            ]
          }
        }
      }
    },
    "risk": {
      "type": "object",
      "required": [
        "level",
        "requested_value",
        "mandate_headroom",
        "blocked_value",
        "primary_reason"
      ],
      "properties": {
        "level": {
          "type": "string",
          "enum": [
            "CLEAR",
            "GUARDED",
            "ELEVATED",
            "CRITICAL"
          ]
        },
        "requested_value": {
          "type": [
            "number",
            "null"
          ]
        },
        "mandate_headroom": {
          "type": [
            "number",
            "null"
          ]
        },
        "blocked_value": {
          "type": "number",
          "minimum": 0
        },
        "primary_reason": {
          "type": [
            "string",
            "null"
          ]
        }
      }
    },
    "recommended_action": {
      "type": "string"
    },
    "controls": {
      "type": "object",
      "required": [
        "evaluated",
        "passed"
      ],
      "properties": {
        "evaluated": {
          "type": "integer",
          "minimum": 0
        },
        "passed": {
          "type": "integer",
          "minimum": 0
        }
      }
    },
    "mode": {
      "type": "string"
    },
    "persisted": {
      "type": "boolean"
    },
    "enforcement_authorized": {
      "type": "boolean",
      "description": "True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call."
    },
    "error": {
      "type": "string"
    }
  },
  "required": [
    "decision",
    "score",
    "receipt",
    "checked_at",
    "protocol",
    "findings",
    "risk",
    "recommended_action",
    "controls",
    "mode",
    "persisted",
    "enforcement_authorized"
  ]
}
🟢normalize_agent_payment_protocol(adapter, source, context, selection)

Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "adapter": {
      "type": "string",
      "enum": [
        "AP2_CLOSED_PAYMENT_SD_JWT",
        "X402_V2_PAYMENT_REQUIRED",
        "MPP_HTTP_PAYMENT_CHALLENGE"
      ]
    },
    "source": {
      "description": "Raw protocol input: AP2 compact SD-JWT, x402 PAYMENT-REQUIRED base64 JSON, MPP WWW-Authenticate Payment challenge, or the documented decoded object."
    },
    "context": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "mandate_id",
        "agent_id"
      ],
      "properties": {
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "maxLength": 2048
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 500
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        },
        "user_consent": {
          "type": "boolean"
        },
        "amount_unit": {
          "type": "string",
          "enum": [
            "MINOR_UNITS",
            "ATOMIC_UNITS"
          ]
        },
        "mpp_request_profile": {
          "type": "string",
          "enum": [
            "MANDATESHIELD_PORTABLE_CHARGE_V1"
          ],
          "description": "Required for MPP because the core protocol delegates request field semantics to method-specific specifications."
        },
        "x402_execution_profile": {
          "type": "string",
          "enum": [
            "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
          ],
          "description": "Opt-in strict first-party x402 execution binding. Requires method and exact request digests."
        },
        "http_method": {
          "type": "string",
          "enum": [
            "GET",
            "HEAD",
            "POST",
            "PUT",
            "PATCH",
            "DELETE"
          ]
        },
        "http_body_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "http_headers_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        }
      }
    },
    "selection": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "index": {
          "type": "integer",
          "minimum": 0,
          "maximum": 24
        }
      }
    }
  },
  "required": [
    "adapter",
    "source",
    "context"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "adapter": {
      "type": "string"
    },
    "adapter_version": {
      "type": "string"
    },
    "protocol": {
      "type": "string",
      "enum": [
        "AP2",
        "X402",
        "MPP"
      ]
    },
    "source_digest": {
      "type": "string"
    },
    "envelope_digest": {
      "type": "string"
    },
    "envelope": {
      "type": "object",
      "additionalProperties": true,
      "required": [
        "protocol",
        "mandate_id",
        "agent_id",
        "merchant_id",
        "amount",
        "idempotency_key"
      ],
      "properties": {
        "protocol": {
          "type": "string",
          "enum": [
            "AP2",
            "TAP",
            "UCP",
            "X402",
            "MPP",
            "ACP",
            "CUSTOM"
          ],
          "description": "Source protocol or CUSTOM for a normalized envelope."
        },
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the user-approved authority."
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the acting AI agent."
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the final seller or payee."
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        },
        "amount": {
          "type": "object",
          "additionalProperties": false,
          "oneOf": [
            {
              "required": [
                "value",
                "currency"
              ]
            },
            {
              "required": [
                "atomic_units",
                "asset_decimals"
              ]
            }
          ],
          "properties": {
            "value": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "minor_units": {
              "type": "integer",
              "minimum": 1,
              "description": "Optional exact integer amount in the currency's minor unit."
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Za-z]{3}$",
              "description": "Three-letter ISO currency code."
            },
            "atomic_units": {
              "type": "string",
              "pattern": "^(?:0|[1-9][0-9]{0,77})$",
              "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            }
          }
        },
        "limits": {
          "type": "object",
          "properties": {
            "max_amount": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "max_amount_minor": {
              "type": "integer",
              "exclusiveMinimum": 0
            },
            "max_atomic_units": {
              "type": "string",
              "pattern": "^[1-9][0-9]{0,77}$"
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            },
            "currencies": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "pattern": "^[A-Za-z]{3}$"
              }
            },
            "merchants": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "assets": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "networks": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "resources": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            }
          },
          "oneOf": [
            {
              "required": [
                "currencies",
                "merchants"
              ],
              "anyOf": [
                {
                  "required": [
                    "max_amount_minor"
                  ]
                },
                {
                  "required": [
                    "max_amount"
                  ]
                }
              ]
            },
            {
              "required": [
                "max_atomic_units",
                "asset_decimals",
                "assets",
                "networks",
                "resources",
                "merchants"
              ]
            }
          ],
          "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "description": "Exact token or asset identifier; required for atomic X402 payments."
        },
        "network": {
          "type": "string",
          "minLength": 1,
          "description": "Exact network or chain identifier; required for atomic X402 payments."
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "description": "Exact paid resource identifier; required for atomic X402 payments."
        },
        "http_request": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "url",
            "method",
            "body_sha256",
            "headers_sha256",
            "redirect_policy"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
            },
            "url": {
              "type": "string",
              "format": "uri"
            },
            "method": {
              "type": "string",
              "enum": [
                "GET",
                "HEAD",
                "POST",
                "PUT",
                "PATCH",
                "DELETE"
              ]
            },
            "body_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "headers_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "redirect_policy": {
              "const": "ERROR"
            }
          },
          "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256,
          "pattern": "^[A-Za-z0-9._:~-]+$",
          "description": "Unique identifier for this intended payment attempt."
        },
        "intent_hash": {
          "type": "string"
        },
        "checkout_hash": {
          "type": "string",
          "minLength": 1,
          "description": "Digest or stable identifier for the exact final checkout."
        },
        "user_consent": {
          "type": "boolean"
        },
        "credential_binding": {
          "type": "string"
        },
        "purpose": {
          "type": "string",
          "description": "Non-sensitive plain-language purchase purpose."
        }
      }
    },
    "assurance": {
      "type": "object",
      "required": [
        "projection_fields_valid",
        "source_signature_verified",
        "source_trust_verified",
        "delegated_authority_verified",
        "payment_credential_verified",
        "settlement_verified",
        "enforcement_authorized"
      ],
      "properties": {
        "projection_fields_valid": {
          "const": true
        },
        "source_signature_verified": {
          "const": false
        },
        "source_trust_verified": {
          "const": false
        },
        "delegated_authority_verified": {
          "const": false
        },
        "payment_credential_verified": {
          "const": false
        },
        "settlement_verified": {
          "const": false
        },
        "enforcement_authorized": {
          "const": false
        }
      }
    },
    "next_step": {
      "type": "string"
    },
    "warnings": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "adapter",
    "adapter_version",
    "protocol",
    "source_digest",
    "envelope_digest",
    "envelope",
    "assurance",
    "next_step",
    "warnings"
  ],
  "additionalProperties": true
}
⚪verify_cryptographic_payment_authority(envelope, evidence)

Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "envelope": {
      "type": "object",
      "additionalProperties": true,
      "required": [
        "protocol",
        "mandate_id",
        "agent_id",
        "merchant_id",
        "amount",
        "idempotency_key"
      ],
      "properties": {
        "protocol": {
          "type": "string",
          "enum": [
            "AP2",
            "TAP",
            "UCP",
            "X402",
            "MPP",
            "ACP",
            "CUSTOM"
          ],
          "description": "Source protocol or CUSTOM for a normalized envelope."
        },
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the user-approved authority."
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the acting AI agent."
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the final seller or payee."
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        },
        "amount": {
          "type": "object",
          "additionalProperties": false,
          "oneOf": [
            {
              "required": [
                "value",
                "currency"
              ]
            },
            {
              "required": [
                "atomic_units",
                "asset_decimals"
              ]
            }
          ],
          "properties": {
            "value": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "minor_units": {
              "type": "integer",
              "minimum": 1,
              "description": "Optional exact integer amount in the currency's minor unit."
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Za-z]{3}$",
              "description": "Three-letter ISO currency code."
            },
            "atomic_units": {
              "type": "string",
              "pattern": "^(?:0|[1-9][0-9]{0,77})$",
              "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            }
          }
        },
        "limits": {
          "type": "object",
          "properties": {
            "max_amount": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "max_amount_minor": {
              "type": "integer",
              "exclusiveMinimum": 0
            },
            "max_atomic_units": {
              "type": "string",
              "pattern": "^[1-9][0-9]{0,77}$"
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            },
            "currencies": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "pattern": "^[A-Za-z]{3}$"
              }
            },
            "merchants": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "assets": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "networks": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "resources": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            }
          },
          "oneOf": [
            {
              "required": [
                "currencies",
                "merchants"
              ],
              "anyOf": [
                {
                  "required": [
                    "max_amount_minor"
                  ]
                },
                {
                  "required": [
                    "max_amount"
                  ]
                }
              ]
            },
            {
              "required": [
                "max_atomic_units",
                "asset_decimals",
                "assets",
                "networks",
                "resources",
                "merchants"
              ]
            }
          ],
          "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "description": "Exact token or asset identifier; required for atomic X402 payments."
        },
        "network": {
          "type": "string",
          "minLength": 1,
          "description": "Exact network or chain identifier; required for atomic X402 payments."
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "description": "Exact paid resource identifier; required for atomic X402 payments."
        },
        "http_request": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "url",
            "method",
            "body_sha256",
            "headers_sha256",
            "redirect_policy"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
            },
            "url": {
              "type": "string",
              "format": "uri"
            },
            "method": {
              "type": "string",
              "enum": [
                "GET",
                "HEAD",
                "POST",
                "PUT",
                "PATCH",
                "DELETE"
              ]
            },
            "body_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "headers_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "redirect_policy": {
              "const": "ERROR"
            }
          },
          "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256,
          "pattern": "^[A-Za-z0-9._:~-]+$",
          "description": "Unique identifier for this intended payment attempt."
        },
        "intent_hash": {
          "type": "string"
        },
        "checkout_hash": {
          "type": "string",
          "minLength": 1,
          "description": "Digest or stable identifier for the exact final checkout."
        },
        "user_consent": {
          "type": "boolean"
        },
        "credential_binding": {
          "type": "string"
        },
        "purpose": {
          "type": "string",
          "description": "Non-sensitive plain-language purchase purpose."
        }
      }
    },
    "evidence": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "format",
        "public_key"
      ],
      "properties": {
        "format": {
          "type": "string",
          "enum": [
            "jws",
            "sd-jwt",
            "http-message-signature"
          ]
        },
        "compact": {
          "type": "string"
        },
        "public_key": {
          "type": "object"
        },
        "expected_audience": {
          "type": "string"
        },
        "expected_nonce": {
          "type": "string"
        },
        "expected_authority": {
          "type": "string"
        },
        "algorithm": {
          "type": "string",
          "enum": [
            "ES256",
            "RS256",
            "PS256"
          ]
        },
        "signature": {
          "type": "string"
        },
        "signature_input": {
          "type": "object"
        },
        "components": {
          "type": "object"
        }
      }
    }
  },
  "required": [
    "envelope",
    "evidence"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "decision": {
      "type": "string",
      "enum": [
        "ALLOW",
        "REVIEW",
        "BLOCK"
      ]
    },
    "score": {
      "type": "integer",
      "minimum": 0,
      "maximum": 100,
      "description": "Deterministic control-coverage indicator, not a calibrated probability of fraud or loss."
    },
    "receipt": {
      "type": "string"
    },
    "checked_at": {
      "type": "string",
      "format": "date-time"
    },
    "protocol": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "required": [
          "code",
          "message",
          "severity"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "high",
              "medium",
              "low"
            ]
          }
        }
      }
    },
    "risk": {
      "type": "object",
      "required": [
        "level",
        "requested_value",
        "mandate_headroom",
        "blocked_value",
        "primary_reason"
      ],
      "properties": {
        "level": {
          "type": "string",
          "enum": [
            "CLEAR",
            "GUARDED",
            "ELEVATED",
            "CRITICAL"
          ]
        },
        "requested_value": {
          "type": [
            "number",
            "null"
          ]
        },
        "mandate_headroom": {
          "type": [
            "number",
            "null"
          ]
        },
        "blocked_value": {
          "type": "number",
          "minimum": 0
        },
        "primary_reason": {
          "type": [
            "string",
            "null"
          ]
        }
      }
    },
    "recommended_action": {
      "type": "string"
    },
    "controls": {
      "type": "object",
      "required": [
        "evaluated",
        "passed"
      ],
      "properties": {
        "evaluated": {
          "type": "integer",
          "minimum": 0
        },
        "passed": {
          "type": "integer",
          "minimum": 0
        }
      }
    },
    "mode": {
      "type": "string"
    },
    "persisted": {
      "type": "boolean"
    },
    "enforcement_authorized": {
      "type": "boolean",
      "description": "True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call."
    },
    "error": {
      "type": "string"
    },
    "assurance": {
      "type": "object",
      "required": [
        "status",
        "format",
        "key_trust",
        "signature_valid",
        "authority_valid",
        "input_digest",
        "findings"
      ]
    },
    "signed_receipt": {
      "type": "object",
      "required": [
        "format",
        "compact",
        "receipt_id",
        "key_id",
        "jwks_uri",
        "verify_uri",
        "transparency_uri"
      ]
    },
    "transparency": {
      "type": "object",
      "required": [
        "status",
        "uri"
      ],
      "properties": {
        "status": {
          "type": "string",
          "enum": [
            "RECORDED",
            "NOT_RECORDED"
          ]
        },
        "uri": {
          "type": "string"
        }
      }
    },
    "execution_authorization": {
      "type": "object",
      "required": [
        "state",
        "consumable",
        "transition_uri",
        "processor_integration_required"
      ],
      "properties": {
        "state": {
          "type": "string",
          "enum": [
            "RESERVED",
            "NOT_RESERVED",
            "ARCHIVAL_ONLY"
          ]
        },
        "consumable": {
          "type": "boolean"
        },
        "transition_uri": {
          "type": "string"
        },
        "expires_at": {
          "type": [
            "string",
            "null"
          ]
        },
        "processor_integration_required": {
          "type": "boolean",
          "const": true
        }
      }
    }
  },
  "required": [
    "decision",
    "score",
    "receipt",
    "checked_at",
    "protocol",
    "findings",
    "risk",
    "recommended_action",
    "controls",
    "mode",
    "persisted",
    "enforcement_authorized",
    "assurance",
    "signed_receipt",
    "transparency",
    "execution_authorization"
  ]
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet3 Tools
verifiziertVersion nicht aufgezeichnet3 Tools