MANDATE Credential Broker
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
¿Debería usar esto?
Calidad y seguridad
Hallazgos (12)
- LOWen mandate.discover
- LOWen mandate.discover
- LOWen mandate.mint
- LOWen mandate.delegate
- LOWen mandate.authorize-action
- LOWen mandate.verify-proof
- LOWen mandate.revoke
- LOWen broker.register-credential
- LOWen broker.request-access
- LOWen broker.use
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"mandate": {
"url": "https://mandate.nanocorp.app/mcp"
}
}
}Puntos de conexión remotos
https://mandate.nanocorp.app/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (11)
⚪mandate.discover
Returns this self-describing tool manifest.
Esquema de entrada
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪mandate.mint
Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.
Esquema de entrada
{
"type": "object",
"required": [
"organization_id",
"agent_id",
"grantor_principal_id",
"budget_currency",
"budget_total",
"per_action_limit",
"expires_at",
"scopes"
]
}⚪mandate.delegate
Creates a child mandate only when it is a no-escalation subset of the parent mandate.
Esquema de entrada
{
"type": "object",
"required": [
"parent_mandate_id",
"delegator_agent_id",
"delegate_agent_id",
"budget_total",
"per_action_limit",
"starts_at",
"expires_at",
"scopes"
]
}⚪mandate.authorize-action
Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.
Esquema de entrada
{
"type": "object",
"required": [
"acting_agent_id",
"action_type",
"amount_minor",
"counterparty"
]
}⚪mandate.verify-proof
Records a proof payload hash and appends proof evidence to the hash-chained ledger.
Esquema de entrada
{
"type": "object",
"required": [
"organization_id",
"subject_type",
"subject_id",
"proof_type",
"payload"
]
}⚪mandate.revoke
Revokes a mandate subtree and records the revocation to the hash-chained ledger.
Esquema de entrada
{
"type": "object",
"required": [
"revoked_by_principal_id",
"reason"
]
}⚪broker.register-credential(vault_handle, metadata)
Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.
Esquema de entrada
{
"type": "object",
"properties": {
"vault_handle": {
"type": "string",
"description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
},
"metadata": {
"type": "object"
}
},
"required": [
"organization_id",
"registered_by_agent_id",
"label",
"credential_type",
"vault_handle",
"allowed_action_type"
]
}⚪broker.request-access
Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.
Esquema de entrada
{
"type": "object",
"required": [
"credential_id",
"acting_agent_id",
"mandate_id",
"action"
]
}⚪broker.use
Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.
Esquema de entrada
{
"type": "object",
"required": [
"grant_token",
"acting_agent_id"
]
}⚪broker.revoke-grant
Revokes a broker grant by id and records the revocation to the ledger.
Esquema de entrada
{
"type": "object",
"required": [
"revoked_by_agent_id",
"reason"
]
}⚪broker.introspect-grant
Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.
Esquema de entrada
{
"type": "object",
"required": [
"grant_token"
]
}Comunidad
Evidencia