MandateShield AI Payment Evidence

Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
85%
命名の品質
80%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(2)

  • LOWTool 'normalize_agent_payment_protocol' name length outside 3-30 rangenormalize_agent_payment_protocol 内
  • LOWTool 'verify_cryptographic_payment_authority' name length outside 3-30 rangeverify_cryptographic_payment_authority 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~8,310トークン数(ツール定義)
~32.4 KB一般的なレスポンスサイズ
注意への影響は大きい(128k コンテキストの 6.49%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "payment-authority": {
      "url": "https://mandateshield.com/api/mcp"
    }
  }
}

リモートエンドポイント

https://mandateshield.com/api/mcpstreamable-http

できること

ツール一覧

ツール(3)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟡check_ai_payment_authority(protocol, mandate_id, agent_id, merchant_id, payee_identity, ...)

Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys.

入力スキーマ

{
  "type": "object",
  "properties": {
    "protocol": {
      "type": "string",
      "enum": [
        "AP2",
        "TAP",
        "UCP",
        "X402",
        "MPP",
        "ACP",
        "CUSTOM"
      ],
      "description": "Source protocol or CUSTOM for a normalized envelope."
    },
    "mandate_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the user-approved authority."
    },
    "agent_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the acting AI agent."
    },
    "merchant_id": {
      "type": "string",
      "minLength": 1,
      "description": "Stable identifier for the final seller or payee."
    },
    "payee_identity": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "profile",
        "provider",
        "merchant_id",
        "binding",
        "verification"
      ],
      "properties": {
        "profile": {
          "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
        },
        "provider": {
          "type": "string",
          "enum": [
            "X402",
            "MPP",
            "STRIPE",
            "CUSTOM"
          ]
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "binding": {
          "type": "object"
        },
        "verification": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "method",
            "verifier",
            "evidence_ref"
          ],
          "properties": {
            "method": {
              "type": "string",
              "enum": [
                "TRUSTED_MERCHANT_MAPPING",
                "TLS_SERVICE_ORIGIN",
                "STRIPE_ACCOUNT_CONFIGURATION",
                "HTTPS_WELL_KNOWN"
              ]
            },
            "verifier": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "evidence_ref": {
              "type": "string",
              "minLength": 1,
              "maxLength": 2048
            }
          }
        }
      },
      "oneOf": [
        {
          "properties": {
            "provider": {
              "const": "X402"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "network",
                "pay_to"
              ],
              "properties": {
                "network": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "pay_to": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 500
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "TRUSTED_MERCHANT_MAPPING"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "MPP"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "service_origin",
                "method"
              ],
              "properties": {
                "service_origin": {
                  "type": "string",
                  "pattern": "^https://[^/?#]+$"
                },
                "method": {
                  "type": "string",
                  "pattern": "^[a-z]+$"
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "TLS_SERVICE_ORIGIN"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "STRIPE"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "connected_account_id",
                "merchant_account_id"
              ],
              "properties": {
                "connected_account_id": {
                  "type": "string",
                  "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                },
                "merchant_account_id": {
                  "type": "string",
                  "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "STRIPE_ACCOUNT_CONFIGURATION"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                }
              }
            }
          }
        },
        {
          "properties": {
            "provider": {
              "const": "CUSTOM"
            },
            "binding": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "service_origin",
                "provider_id"
              ],
              "properties": {
                "service_origin": {
                  "type": "string",
                  "pattern": "^https://[^/?#]+$"
                },
                "provider_id": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                }
              }
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "const": "HTTPS_WELL_KNOWN"
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "format": "uri",
                  "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                }
              }
            }
          }
        }
      ],
      "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
    },
    "amount": {
      "type": "object",
      "additionalProperties": false,
      "oneOf": [
        {
          "required": [
            "value",
            "currency"
          ]
        },
        {
          "required": [
            "atomic_units",
            "asset_decimals"
          ]
        }
      ],
      "properties": {
        "value": {
          "type": "number",
          "exclusiveMinimum": 0
        },
        "minor_units": {
          "type": "integer",
          "minimum": 1,
          "description": "Optional exact integer amount in the currency's minor unit."
        },
        "currency": {
          "type": "string",
          "pattern": "^[A-Za-z]{3}$",
          "description": "Three-letter ISO currency code."
        },
        "atomic_units": {
          "type": "string",
          "pattern": "^(?:0|[1-9][0-9]{0,77})$",
          "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        }
      }
    },
    "limits": {
      "type": "object",
      "properties": {
        "max_amount": {
          "type": "number",
          "exclusiveMinimum": 0
        },
        "max_amount_minor": {
          "type": "integer",
          "exclusiveMinimum": 0
        },
        "max_atomic_units": {
          "type": "string",
          "pattern": "^[1-9][0-9]{0,77}$"
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        },
        "currencies": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "pattern": "^[A-Za-z]{3}$"
          }
        },
        "merchants": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "assets": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "networks": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        },
        "resources": {
          "type": "array",
          "minItems": 1,
          "items": {
            "type": "string",
            "minLength": 1
          }
        }
      },
      "oneOf": [
        {
          "required": [
            "currencies",
            "merchants"
          ],
          "anyOf": [
            {
              "required": [
                "max_amount_minor"
              ]
            },
            {
              "required": [
                "max_amount"
              ]
            }
          ]
        },
        {
          "required": [
            "max_atomic_units",
            "asset_decimals",
            "assets",
            "networks",
            "resources",
            "merchants"
          ]
        }
      ],
      "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
    },
    "asset_id": {
      "type": "string",
      "minLength": 1,
      "description": "Exact token or asset identifier; required for atomic X402 payments."
    },
    "network": {
      "type": "string",
      "minLength": 1,
      "description": "Exact network or chain identifier; required for atomic X402 payments."
    },
    "resource": {
      "type": "string",
      "minLength": 1,
      "description": "Exact paid resource identifier; required for atomic X402 payments."
    },
    "http_request": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "profile",
        "url",
        "method",
        "body_sha256",
        "headers_sha256",
        "redirect_policy"
      ],
      "properties": {
        "profile": {
          "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
        },
        "url": {
          "type": "string",
          "format": "uri"
        },
        "method": {
          "type": "string",
          "enum": [
            "GET",
            "HEAD",
            "POST",
            "PUT",
            "PATCH",
            "DELETE"
          ]
        },
        "body_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "headers_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "redirect_policy": {
          "const": "ERROR"
        }
      },
      "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
    },
    "created_at": {
      "type": "string",
      "format": "date-time"
    },
    "expires_at": {
      "type": "string",
      "format": "date-time"
    },
    "idempotency_key": {
      "type": "string",
      "minLength": 1,
      "maxLength": 256,
      "pattern": "^[A-Za-z0-9._:~-]+$",
      "description": "Unique identifier for this intended payment attempt."
    },
    "intent_hash": {
      "type": "string"
    },
    "checkout_hash": {
      "type": "string",
      "minLength": 1,
      "description": "Digest or stable identifier for the exact final checkout."
    },
    "user_consent": {
      "type": "boolean"
    },
    "credential_binding": {
      "type": "string"
    },
    "purpose": {
      "type": "string",
      "description": "Non-sensitive plain-language purchase purpose."
    }
  },
  "required": [
    "protocol",
    "mandate_id",
    "agent_id",
    "merchant_id",
    "amount",
    "idempotency_key"
  ],
  "additionalProperties": true
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "decision": {
      "type": "string",
      "enum": [
        "ALLOW",
        "REVIEW",
        "BLOCK"
      ]
    },
    "score": {
      "type": "integer",
      "minimum": 0,
      "maximum": 100,
      "description": "Deterministic control-coverage indicator, not a calibrated probability of fraud or loss."
    },
    "receipt": {
      "type": "string"
    },
    "checked_at": {
      "type": "string",
      "format": "date-time"
    },
    "protocol": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "required": [
          "code",
          "message",
          "severity"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "high",
              "medium",
              "low"
            ]
          }
        }
      }
    },
    "risk": {
      "type": "object",
      "required": [
        "level",
        "requested_value",
        "mandate_headroom",
        "blocked_value",
        "primary_reason"
      ],
      "properties": {
        "level": {
          "type": "string",
          "enum": [
            "CLEAR",
            "GUARDED",
            "ELEVATED",
            "CRITICAL"
          ]
        },
        "requested_value": {
          "type": [
            "number",
            "null"
          ]
        },
        "mandate_headroom": {
          "type": [
            "number",
            "null"
          ]
        },
        "blocked_value": {
          "type": "number",
          "minimum": 0
        },
        "primary_reason": {
          "type": [
            "string",
            "null"
          ]
        }
      }
    },
    "recommended_action": {
      "type": "string"
    },
    "controls": {
      "type": "object",
      "required": [
        "evaluated",
        "passed"
      ],
      "properties": {
        "evaluated": {
          "type": "integer",
          "minimum": 0
        },
        "passed": {
          "type": "integer",
          "minimum": 0
        }
      }
    },
    "mode": {
      "type": "string"
    },
    "persisted": {
      "type": "boolean"
    },
    "enforcement_authorized": {
      "type": "boolean",
      "description": "True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call."
    },
    "error": {
      "type": "string"
    }
  },
  "required": [
    "decision",
    "score",
    "receipt",
    "checked_at",
    "protocol",
    "findings",
    "risk",
    "recommended_action",
    "controls",
    "mode",
    "persisted",
    "enforcement_authorized"
  ]
}
🟢normalize_agent_payment_protocol(adapter, source, context, selection)

Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope. X402 requires source-matched network+payTo identity and MPP requires source-matched HTTPS service-origin+method identity; merchant_id alone is insufficient. Evidence references are not independently verified. projection_fields_valid is not full protocol conformance: this tool never verifies delegated authority or a payment credential and always returns enforcement_authorized=false under assurance.

入力スキーマ

{
  "type": "object",
  "properties": {
    "adapter": {
      "type": "string",
      "enum": [
        "AP2_CLOSED_PAYMENT_SD_JWT",
        "X402_V2_PAYMENT_REQUIRED",
        "MPP_HTTP_PAYMENT_CHALLENGE"
      ]
    },
    "source": {
      "description": "Raw protocol input: AP2 compact SD-JWT, x402 PAYMENT-REQUIRED base64 JSON, MPP WWW-Authenticate Payment challenge, or the documented decoded object."
    },
    "context": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "mandate_id",
        "agent_id"
      ],
      "properties": {
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 240
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "maxLength": 2048
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "maxLength": 500
        },
        "asset_decimals": {
          "type": "integer",
          "minimum": 0,
          "maximum": 30
        },
        "user_consent": {
          "type": "boolean"
        },
        "amount_unit": {
          "type": "string",
          "enum": [
            "MINOR_UNITS",
            "ATOMIC_UNITS"
          ]
        },
        "mpp_request_profile": {
          "type": "string",
          "enum": [
            "MANDATESHIELD_PORTABLE_CHARGE_V1"
          ],
          "description": "Required for MPP because the core protocol delegates request field semantics to method-specific specifications."
        },
        "x402_execution_profile": {
          "type": "string",
          "enum": [
            "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
          ],
          "description": "Opt-in strict first-party x402 execution binding. Requires method and exact request digests."
        },
        "http_method": {
          "type": "string",
          "enum": [
            "GET",
            "HEAD",
            "POST",
            "PUT",
            "PATCH",
            "DELETE"
          ]
        },
        "http_body_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "http_headers_sha256": {
          "type": "string",
          "pattern": "^sha256:[a-f0-9]{64}$"
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        }
      }
    },
    "selection": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "index": {
          "type": "integer",
          "minimum": 0,
          "maximum": 24
        }
      }
    }
  },
  "required": [
    "adapter",
    "source",
    "context"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "adapter": {
      "type": "string"
    },
    "adapter_version": {
      "type": "string"
    },
    "protocol": {
      "type": "string",
      "enum": [
        "AP2",
        "X402",
        "MPP"
      ]
    },
    "source_digest": {
      "type": "string"
    },
    "envelope_digest": {
      "type": "string"
    },
    "envelope": {
      "type": "object",
      "additionalProperties": true,
      "required": [
        "protocol",
        "mandate_id",
        "agent_id",
        "merchant_id",
        "amount",
        "idempotency_key"
      ],
      "properties": {
        "protocol": {
          "type": "string",
          "enum": [
            "AP2",
            "TAP",
            "UCP",
            "X402",
            "MPP",
            "ACP",
            "CUSTOM"
          ],
          "description": "Source protocol or CUSTOM for a normalized envelope."
        },
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the user-approved authority."
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the acting AI agent."
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the final seller or payee."
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        },
        "amount": {
          "type": "object",
          "additionalProperties": false,
          "oneOf": [
            {
              "required": [
                "value",
                "currency"
              ]
            },
            {
              "required": [
                "atomic_units",
                "asset_decimals"
              ]
            }
          ],
          "properties": {
            "value": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "minor_units": {
              "type": "integer",
              "minimum": 1,
              "description": "Optional exact integer amount in the currency's minor unit."
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Za-z]{3}$",
              "description": "Three-letter ISO currency code."
            },
            "atomic_units": {
              "type": "string",
              "pattern": "^(?:0|[1-9][0-9]{0,77})$",
              "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            }
          }
        },
        "limits": {
          "type": "object",
          "properties": {
            "max_amount": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "max_amount_minor": {
              "type": "integer",
              "exclusiveMinimum": 0
            },
            "max_atomic_units": {
              "type": "string",
              "pattern": "^[1-9][0-9]{0,77}$"
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            },
            "currencies": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "pattern": "^[A-Za-z]{3}$"
              }
            },
            "merchants": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "assets": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "networks": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "resources": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            }
          },
          "oneOf": [
            {
              "required": [
                "currencies",
                "merchants"
              ],
              "anyOf": [
                {
                  "required": [
                    "max_amount_minor"
                  ]
                },
                {
                  "required": [
                    "max_amount"
                  ]
                }
              ]
            },
            {
              "required": [
                "max_atomic_units",
                "asset_decimals",
                "assets",
                "networks",
                "resources",
                "merchants"
              ]
            }
          ],
          "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "description": "Exact token or asset identifier; required for atomic X402 payments."
        },
        "network": {
          "type": "string",
          "minLength": 1,
          "description": "Exact network or chain identifier; required for atomic X402 payments."
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "description": "Exact paid resource identifier; required for atomic X402 payments."
        },
        "http_request": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "url",
            "method",
            "body_sha256",
            "headers_sha256",
            "redirect_policy"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
            },
            "url": {
              "type": "string",
              "format": "uri"
            },
            "method": {
              "type": "string",
              "enum": [
                "GET",
                "HEAD",
                "POST",
                "PUT",
                "PATCH",
                "DELETE"
              ]
            },
            "body_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "headers_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "redirect_policy": {
              "const": "ERROR"
            }
          },
          "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256,
          "pattern": "^[A-Za-z0-9._:~-]+$",
          "description": "Unique identifier for this intended payment attempt."
        },
        "intent_hash": {
          "type": "string"
        },
        "checkout_hash": {
          "type": "string",
          "minLength": 1,
          "description": "Digest or stable identifier for the exact final checkout."
        },
        "user_consent": {
          "type": "boolean"
        },
        "credential_binding": {
          "type": "string"
        },
        "purpose": {
          "type": "string",
          "description": "Non-sensitive plain-language purchase purpose."
        }
      }
    },
    "assurance": {
      "type": "object",
      "required": [
        "projection_fields_valid",
        "source_signature_verified",
        "source_trust_verified",
        "delegated_authority_verified",
        "payment_credential_verified",
        "settlement_verified",
        "enforcement_authorized"
      ],
      "properties": {
        "projection_fields_valid": {
          "const": true
        },
        "source_signature_verified": {
          "const": false
        },
        "source_trust_verified": {
          "const": false
        },
        "delegated_authority_verified": {
          "const": false
        },
        "payment_credential_verified": {
          "const": false
        },
        "settlement_verified": {
          "const": false
        },
        "enforcement_authorized": {
          "const": false
        }
      }
    },
    "next_step": {
      "type": "string"
    },
    "warnings": {
      "type": "array",
      "items": {
        "type": "string"
      }
    }
  },
  "required": [
    "adapter",
    "adapter_version",
    "protocol",
    "source_digest",
    "envelope_digest",
    "envelope",
    "assurance",
    "next_step",
    "warnings"
  ],
  "additionalProperties": true
}
⚪verify_cryptographic_payment_authority(envelope, evidence)

Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME and freshly redeem the provider-bound permit before attempting an idempotent provider operation, then reconcile the outcome.

入力スキーマ

{
  "type": "object",
  "properties": {
    "envelope": {
      "type": "object",
      "additionalProperties": true,
      "required": [
        "protocol",
        "mandate_id",
        "agent_id",
        "merchant_id",
        "amount",
        "idempotency_key"
      ],
      "properties": {
        "protocol": {
          "type": "string",
          "enum": [
            "AP2",
            "TAP",
            "UCP",
            "X402",
            "MPP",
            "ACP",
            "CUSTOM"
          ],
          "description": "Source protocol or CUSTOM for a normalized envelope."
        },
        "mandate_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the user-approved authority."
        },
        "agent_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the acting AI agent."
        },
        "merchant_id": {
          "type": "string",
          "minLength": 1,
          "description": "Stable identifier for the final seller or payee."
        },
        "payee_identity": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "provider",
            "merchant_id",
            "binding",
            "verification"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_PAYEE_IDENTITY_V1"
            },
            "provider": {
              "type": "string",
              "enum": [
                "X402",
                "MPP",
                "STRIPE",
                "CUSTOM"
              ]
            },
            "merchant_id": {
              "type": "string",
              "minLength": 1,
              "maxLength": 240
            },
            "binding": {
              "type": "object"
            },
            "verification": {
              "type": "object",
              "additionalProperties": false,
              "required": [
                "method",
                "verifier",
                "evidence_ref"
              ],
              "properties": {
                "method": {
                  "type": "string",
                  "enum": [
                    "TRUSTED_MERCHANT_MAPPING",
                    "TLS_SERVICE_ORIGIN",
                    "STRIPE_ACCOUNT_CONFIGURATION",
                    "HTTPS_WELL_KNOWN"
                  ]
                },
                "verifier": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 240
                },
                "evidence_ref": {
                  "type": "string",
                  "minLength": 1,
                  "maxLength": 2048
                }
              }
            }
          },
          "oneOf": [
            {
              "properties": {
                "provider": {
                  "const": "X402"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "network",
                    "pay_to"
                  ],
                  "properties": {
                    "network": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "pay_to": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 500
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TRUSTED_MERCHANT_MAPPING"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "MPP"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "method"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "method": {
                      "type": "string",
                      "pattern": "^[a-z]+$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "TLS_SERVICE_ORIGIN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 2048
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "STRIPE"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "connected_account_id",
                    "merchant_account_id"
                  ],
                  "properties": {
                    "connected_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    },
                    "merchant_account_id": {
                      "type": "string",
                      "pattern": "^acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "STRIPE_ACCOUNT_CONFIGURATION"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "pattern": "^urn:stripe:connected-account:acct_[A-Za-z0-9_]{8,240}$"
                    }
                  }
                }
              }
            },
            {
              "properties": {
                "provider": {
                  "const": "CUSTOM"
                },
                "binding": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "service_origin",
                    "provider_id"
                  ],
                  "properties": {
                    "service_origin": {
                      "type": "string",
                      "pattern": "^https://[^/?#]+$"
                    },
                    "provider_id": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    }
                  }
                },
                "verification": {
                  "type": "object",
                  "additionalProperties": false,
                  "required": [
                    "method",
                    "verifier",
                    "evidence_ref"
                  ],
                  "properties": {
                    "method": {
                      "const": "HTTPS_WELL_KNOWN"
                    },
                    "verifier": {
                      "type": "string",
                      "minLength": 1,
                      "maxLength": 240
                    },
                    "evidence_ref": {
                      "type": "string",
                      "format": "uri",
                      "pattern": "^https://[^/?#]+/\\.well-known/mandateshield-payee\\.json$"
                    }
                  }
                }
              }
            }
          ],
          "description": "Versioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not independently validate an external registry, TLS session, provider account or domain-control document."
        },
        "amount": {
          "type": "object",
          "additionalProperties": false,
          "oneOf": [
            {
              "required": [
                "value",
                "currency"
              ]
            },
            {
              "required": [
                "atomic_units",
                "asset_decimals"
              ]
            }
          ],
          "properties": {
            "value": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "minor_units": {
              "type": "integer",
              "minimum": 1,
              "description": "Optional exact integer amount in the currency's minor unit."
            },
            "currency": {
              "type": "string",
              "pattern": "^[A-Za-z]{3}$",
              "description": "Three-letter ISO currency code."
            },
            "atomic_units": {
              "type": "string",
              "pattern": "^(?:0|[1-9][0-9]{0,77})$",
              "description": "Exact integer atomic-asset amount. This string is authoritative for X402."
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            }
          }
        },
        "limits": {
          "type": "object",
          "properties": {
            "max_amount": {
              "type": "number",
              "exclusiveMinimum": 0
            },
            "max_amount_minor": {
              "type": "integer",
              "exclusiveMinimum": 0
            },
            "max_atomic_units": {
              "type": "string",
              "pattern": "^[1-9][0-9]{0,77}$"
            },
            "asset_decimals": {
              "type": "integer",
              "minimum": 0,
              "maximum": 30
            },
            "currencies": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "pattern": "^[A-Za-z]{3}$"
              }
            },
            "merchants": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "assets": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "networks": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            },
            "resources": {
              "type": "array",
              "minItems": 1,
              "items": {
                "type": "string",
                "minLength": 1
              }
            }
          },
          "oneOf": [
            {
              "required": [
                "currencies",
                "merchants"
              ],
              "anyOf": [
                {
                  "required": [
                    "max_amount_minor"
                  ]
                },
                {
                  "required": [
                    "max_amount"
                  ]
                }
              ]
            },
            {
              "required": [
                "max_atomic_units",
                "asset_decimals",
                "assets",
                "networks",
                "resources",
                "merchants"
              ]
            }
          ],
          "description": "Sandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate."
        },
        "asset_id": {
          "type": "string",
          "minLength": 1,
          "description": "Exact token or asset identifier; required for atomic X402 payments."
        },
        "network": {
          "type": "string",
          "minLength": 1,
          "description": "Exact network or chain identifier; required for atomic X402 payments."
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "description": "Exact paid resource identifier; required for atomic X402 payments."
        },
        "http_request": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "profile",
            "url",
            "method",
            "body_sha256",
            "headers_sha256",
            "redirect_policy"
          ],
          "properties": {
            "profile": {
              "const": "MANDATESHIELD_X402_V2_EXACT_EIP3009_V1"
            },
            "url": {
              "type": "string",
              "format": "uri"
            },
            "method": {
              "type": "string",
              "enum": [
                "GET",
                "HEAD",
                "POST",
                "PUT",
                "PATCH",
                "DELETE"
              ]
            },
            "body_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "headers_sha256": {
              "type": "string",
              "pattern": "^sha256:[a-f0-9]{64}$"
            },
            "redirect_policy": {
              "const": "ERROR"
            }
          },
          "description": "Optional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter."
        },
        "created_at": {
          "type": "string",
          "format": "date-time"
        },
        "expires_at": {
          "type": "string",
          "format": "date-time"
        },
        "idempotency_key": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256,
          "pattern": "^[A-Za-z0-9._:~-]+$",
          "description": "Unique identifier for this intended payment attempt."
        },
        "intent_hash": {
          "type": "string"
        },
        "checkout_hash": {
          "type": "string",
          "minLength": 1,
          "description": "Digest or stable identifier for the exact final checkout."
        },
        "user_consent": {
          "type": "boolean"
        },
        "credential_binding": {
          "type": "string"
        },
        "purpose": {
          "type": "string",
          "description": "Non-sensitive plain-language purchase purpose."
        }
      }
    },
    "evidence": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "format",
        "public_key"
      ],
      "properties": {
        "format": {
          "type": "string",
          "enum": [
            "jws",
            "sd-jwt",
            "http-message-signature"
          ]
        },
        "compact": {
          "type": "string"
        },
        "public_key": {
          "type": "object"
        },
        "expected_audience": {
          "type": "string"
        },
        "expected_nonce": {
          "type": "string"
        },
        "expected_authority": {
          "type": "string"
        },
        "algorithm": {
          "type": "string",
          "enum": [
            "ES256",
            "RS256",
            "PS256"
          ]
        },
        "signature": {
          "type": "string"
        },
        "signature_input": {
          "type": "object"
        },
        "components": {
          "type": "object"
        }
      }
    }
  },
  "required": [
    "envelope",
    "evidence"
  ],
  "additionalProperties": false
}

出力スキーマ

{
  "type": "object",
  "properties": {
    "decision": {
      "type": "string",
      "enum": [
        "ALLOW",
        "REVIEW",
        "BLOCK"
      ]
    },
    "score": {
      "type": "integer",
      "minimum": 0,
      "maximum": 100,
      "description": "Deterministic control-coverage indicator, not a calibrated probability of fraud or loss."
    },
    "receipt": {
      "type": "string"
    },
    "checked_at": {
      "type": "string",
      "format": "date-time"
    },
    "protocol": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "required": [
          "code",
          "message",
          "severity"
        ],
        "properties": {
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "high",
              "medium",
              "low"
            ]
          }
        }
      }
    },
    "risk": {
      "type": "object",
      "required": [
        "level",
        "requested_value",
        "mandate_headroom",
        "blocked_value",
        "primary_reason"
      ],
      "properties": {
        "level": {
          "type": "string",
          "enum": [
            "CLEAR",
            "GUARDED",
            "ELEVATED",
            "CRITICAL"
          ]
        },
        "requested_value": {
          "type": [
            "number",
            "null"
          ]
        },
        "mandate_headroom": {
          "type": [
            "number",
            "null"
          ]
        },
        "blocked_value": {
          "type": "number",
          "minimum": 0
        },
        "primary_reason": {
          "type": [
            "string",
            "null"
          ]
        }
      }
    },
    "recommended_action": {
      "type": "string"
    },
    "controls": {
      "type": "object",
      "required": [
        "evaluated",
        "passed"
      ],
      "properties": {
        "evaluated": {
          "type": "integer",
          "minimum": 0
        },
        "passed": {
          "type": "integer",
          "minimum": 0
        }
      }
    },
    "mode": {
      "type": "string"
    },
    "persisted": {
      "type": "boolean"
    },
    "enforcement_authorized": {
      "type": "boolean",
      "description": "True only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call."
    },
    "error": {
      "type": "string"
    },
    "assurance": {
      "type": "object",
      "required": [
        "status",
        "format",
        "key_trust",
        "signature_valid",
        "authority_valid",
        "input_digest",
        "findings"
      ]
    },
    "signed_receipt": {
      "type": "object",
      "required": [
        "format",
        "compact",
        "receipt_id",
        "key_id",
        "jwks_uri",
        "verify_uri",
        "transparency_uri"
      ]
    },
    "transparency": {
      "type": "object",
      "required": [
        "status",
        "uri"
      ],
      "properties": {
        "status": {
          "type": "string",
          "enum": [
            "RECORDED",
            "NOT_RECORDED"
          ]
        },
        "uri": {
          "type": "string"
        }
      }
    },
    "execution_authorization": {
      "type": "object",
      "required": [
        "state",
        "consumable",
        "transition_uri",
        "processor_integration_required"
      ],
      "properties": {
        "state": {
          "type": "string",
          "enum": [
            "RESERVED",
            "NOT_RESERVED",
            "ARCHIVAL_ONLY"
          ]
        },
        "consumable": {
          "type": "boolean"
        },
        "transition_uri": {
          "type": "string"
        },
        "expires_at": {
          "type": [
            "string",
            "null"
          ]
        },
        "processor_integration_required": {
          "type": "boolean",
          "const": true
        }
      }
    }
  },
  "required": [
    "decision",
    "score",
    "receipt",
    "checked_at",
    "protocol",
    "findings",
    "risk",
    "recommended_action",
    "controls",
    "mode",
    "persisted",
    "enforcement_authorized",
    "assurance",
    "signed_receipt",
    "transparency",
    "execution_authorization"
  ]
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 3 件
検証済みバージョンは記録されていませんツール 3 件