MANDATE Credential Broker
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (12)
- LOWin mandate.discover
- LOWin mandate.discover
- LOWin mandate.mint
- LOWin mandate.delegate
- LOWin mandate.authorize-action
- LOWin mandate.verify-proof
- LOWin mandate.revoke
- LOWin broker.register-credential
- LOWin broker.request-access
- LOWin broker.use
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"mandate": {
"url": "https://mandate.nanocorp.app/mcp"
}
}
}Remote-Endpunkte
https://mandate.nanocorp.app/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (11)
⚪mandate.discover
Returns this self-describing tool manifest.
Eingabe-Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪mandate.mint
Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.
Eingabe-Schema
{
"type": "object",
"required": [
"organization_id",
"agent_id",
"grantor_principal_id",
"budget_currency",
"budget_total",
"per_action_limit",
"expires_at",
"scopes"
]
}⚪mandate.delegate
Creates a child mandate only when it is a no-escalation subset of the parent mandate.
Eingabe-Schema
{
"type": "object",
"required": [
"parent_mandate_id",
"delegator_agent_id",
"delegate_agent_id",
"budget_total",
"per_action_limit",
"starts_at",
"expires_at",
"scopes"
]
}⚪mandate.authorize-action
Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.
Eingabe-Schema
{
"type": "object",
"required": [
"acting_agent_id",
"action_type",
"amount_minor",
"counterparty"
]
}⚪mandate.verify-proof
Records a proof payload hash and appends proof evidence to the hash-chained ledger.
Eingabe-Schema
{
"type": "object",
"required": [
"organization_id",
"subject_type",
"subject_id",
"proof_type",
"payload"
]
}⚪mandate.revoke
Revokes a mandate subtree and records the revocation to the hash-chained ledger.
Eingabe-Schema
{
"type": "object",
"required": [
"revoked_by_principal_id",
"reason"
]
}⚪broker.register-credential(vault_handle, metadata)
Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.
Eingabe-Schema
{
"type": "object",
"properties": {
"vault_handle": {
"type": "string",
"description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
},
"metadata": {
"type": "object"
}
},
"required": [
"organization_id",
"registered_by_agent_id",
"label",
"credential_type",
"vault_handle",
"allowed_action_type"
]
}⚪broker.request-access
Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.
Eingabe-Schema
{
"type": "object",
"required": [
"credential_id",
"acting_agent_id",
"mandate_id",
"action"
]
}⚪broker.use
Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.
Eingabe-Schema
{
"type": "object",
"required": [
"grant_token",
"acting_agent_id"
]
}⚪broker.revoke-grant
Revokes a broker grant by id and records the revocation to the ledger.
Eingabe-Schema
{
"type": "object",
"required": [
"revoked_by_agent_id",
"reason"
]
}⚪broker.introspect-grant
Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.
Eingabe-Schema
{
"type": "object",
"required": [
"grant_token"
]
}Community
Nachweis