MANDATE Credential Broker

MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.

Should I use this

Quality & Safety

B
Description quality
95%
Schema completeness
44%
Naming quality
50%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (12)

  • LOWTool 'mandate.discover' description lacks action verbin mandate.discover
  • LOWTool 'mandate.discover' doesn't follow camelCase/snake_casein mandate.discover
  • LOWTool 'mandate.mint' doesn't follow camelCase/snake_casein mandate.mint
  • LOWTool 'mandate.delegate' doesn't follow camelCase/snake_casein mandate.delegate
  • LOWTool 'mandate.authorize-action' doesn't follow camelCase/snake_casein mandate.authorize-action
  • LOWTool 'mandate.verify-proof' doesn't follow camelCase/snake_casein mandate.verify-proof
  • LOWTool 'mandate.revoke' doesn't follow camelCase/snake_casein mandate.revoke
  • LOWTool 'broker.register-credential' doesn't follow camelCase/snake_casein broker.register-credential
  • LOWTool 'broker.request-access' doesn't follow camelCase/snake_casein broker.request-access
  • LOWTool 'broker.use' doesn't follow camelCase/snake_casein broker.use

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~676Tokens (tool definitions)
~326 BTypical response size
Moderate attention impact (0.53% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "mandate": {
      "url": "https://mandate.nanocorp.app/mcp"
    }
  }
}

Remote endpoints

https://mandate.nanocorp.app/mcpstreamable-http

What it can do

Tool inventory

Tools (11)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪mandate.discover

Returns this self-describing tool manifest.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪mandate.mint

Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.

Input Schema

{
  "type": "object",
  "required": [
    "organization_id",
    "agent_id",
    "grantor_principal_id",
    "budget_currency",
    "budget_total",
    "per_action_limit",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.delegate

Creates a child mandate only when it is a no-escalation subset of the parent mandate.

Input Schema

{
  "type": "object",
  "required": [
    "parent_mandate_id",
    "delegator_agent_id",
    "delegate_agent_id",
    "budget_total",
    "per_action_limit",
    "starts_at",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.authorize-action

Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.

Input Schema

{
  "type": "object",
  "required": [
    "acting_agent_id",
    "action_type",
    "amount_minor",
    "counterparty"
  ]
}
⚪mandate.verify-proof

Records a proof payload hash and appends proof evidence to the hash-chained ledger.

Input Schema

{
  "type": "object",
  "required": [
    "organization_id",
    "subject_type",
    "subject_id",
    "proof_type",
    "payload"
  ]
}
⚪mandate.revoke

Revokes a mandate subtree and records the revocation to the hash-chained ledger.

Input Schema

{
  "type": "object",
  "required": [
    "revoked_by_principal_id",
    "reason"
  ]
}
⚪broker.register-credential(vault_handle, metadata)

Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.

Input Schema

{
  "type": "object",
  "properties": {
    "vault_handle": {
      "type": "string",
      "description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
    },
    "metadata": {
      "type": "object"
    }
  },
  "required": [
    "organization_id",
    "registered_by_agent_id",
    "label",
    "credential_type",
    "vault_handle",
    "allowed_action_type"
  ]
}
⚪broker.request-access

Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.

Input Schema

{
  "type": "object",
  "required": [
    "credential_id",
    "acting_agent_id",
    "mandate_id",
    "action"
  ]
}
⚪broker.use

Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.

Input Schema

{
  "type": "object",
  "required": [
    "grant_token",
    "acting_agent_id"
  ]
}
⚪broker.revoke-grant

Revokes a broker grant by id and records the revocation to the ledger.

Input Schema

{
  "type": "object",
  "required": [
    "revoked_by_agent_id",
    "reason"
  ]
}
⚪broker.introspect-grant

Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.

Input Schema

{
  "type": "object",
  "required": [
    "grant_token"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded11 tools
verifiedversion not recorded11 tools