MANDATE Credential Broker

MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.

Sollte ich dies verwenden

Qualität und Sicherheit

B
Qualität der Beschreibung
95%
Vollständigkeit des Schemas
44%
Qualität der Benennung
50%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (12)

  • LOWTool 'mandate.discover' description lacks action verbin mandate.discover
  • LOWTool 'mandate.discover' doesn't follow camelCase/snake_casein mandate.discover
  • LOWTool 'mandate.mint' doesn't follow camelCase/snake_casein mandate.mint
  • LOWTool 'mandate.delegate' doesn't follow camelCase/snake_casein mandate.delegate
  • LOWTool 'mandate.authorize-action' doesn't follow camelCase/snake_casein mandate.authorize-action
  • LOWTool 'mandate.verify-proof' doesn't follow camelCase/snake_casein mandate.verify-proof
  • LOWTool 'mandate.revoke' doesn't follow camelCase/snake_casein mandate.revoke
  • LOWTool 'broker.register-credential' doesn't follow camelCase/snake_casein broker.register-credential
  • LOWTool 'broker.request-access' doesn't follow camelCase/snake_casein broker.request-access
  • LOWTool 'broker.use' doesn't follow camelCase/snake_casein broker.use

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~676Tokens (Tool-Definitionen)
~326 BTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (0.53% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "mandate": {
      "url": "https://mandate.nanocorp.app/mcp"
    }
  }
}

Remote-Endpunkte

https://mandate.nanocorp.app/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (11)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
⚪mandate.discover

Returns this self-describing tool manifest.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪mandate.mint

Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "organization_id",
    "agent_id",
    "grantor_principal_id",
    "budget_currency",
    "budget_total",
    "per_action_limit",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.delegate

Creates a child mandate only when it is a no-escalation subset of the parent mandate.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "parent_mandate_id",
    "delegator_agent_id",
    "delegate_agent_id",
    "budget_total",
    "per_action_limit",
    "starts_at",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.authorize-action

Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "acting_agent_id",
    "action_type",
    "amount_minor",
    "counterparty"
  ]
}
⚪mandate.verify-proof

Records a proof payload hash and appends proof evidence to the hash-chained ledger.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "organization_id",
    "subject_type",
    "subject_id",
    "proof_type",
    "payload"
  ]
}
⚪mandate.revoke

Revokes a mandate subtree and records the revocation to the hash-chained ledger.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "revoked_by_principal_id",
    "reason"
  ]
}
⚪broker.register-credential(vault_handle, metadata)

Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "vault_handle": {
      "type": "string",
      "description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
    },
    "metadata": {
      "type": "object"
    }
  },
  "required": [
    "organization_id",
    "registered_by_agent_id",
    "label",
    "credential_type",
    "vault_handle",
    "allowed_action_type"
  ]
}
⚪broker.request-access

Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "credential_id",
    "acting_agent_id",
    "mandate_id",
    "action"
  ]
}
⚪broker.use

Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "grant_token",
    "acting_agent_id"
  ]
}
⚪broker.revoke-grant

Revokes a broker grant by id and records the revocation to the ledger.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "revoked_by_agent_id",
    "reason"
  ]
}
⚪broker.introspect-grant

Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.

Eingabe-Schema

{
  "type": "object",
  "required": [
    "grant_token"
  ]
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet11 Tools
verifiziertVersion nicht aufgezeichnet11 Tools