MANDATE Credential Broker

MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.

使うべきか

品質と安全性

B
説明の品質
95%
スキーマの完全性
44%
命名の品質
50%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(12)

  • LOWTool 'mandate.discover' description lacks action verbmandate.discover 内
  • LOWTool 'mandate.discover' doesn't follow camelCase/snake_casemandate.discover 内
  • LOWTool 'mandate.mint' doesn't follow camelCase/snake_casemandate.mint 内
  • LOWTool 'mandate.delegate' doesn't follow camelCase/snake_casemandate.delegate 内
  • LOWTool 'mandate.authorize-action' doesn't follow camelCase/snake_casemandate.authorize-action 内
  • LOWTool 'mandate.verify-proof' doesn't follow camelCase/snake_casemandate.verify-proof 内
  • LOWTool 'mandate.revoke' doesn't follow camelCase/snake_casemandate.revoke 内
  • LOWTool 'broker.register-credential' doesn't follow camelCase/snake_casebroker.register-credential 内
  • LOWTool 'broker.request-access' doesn't follow camelCase/snake_casebroker.request-access 内
  • LOWTool 'broker.use' doesn't follow camelCase/snake_casebroker.use 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~676トークン数(ツール定義)
~326 B一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 0.53%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "mandate": {
      "url": "https://mandate.nanocorp.app/mcp"
    }
  }
}

リモートエンドポイント

https://mandate.nanocorp.app/mcpstreamable-http

できること

ツール一覧

ツール(11)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
⚪mandate.discover

Returns this self-describing tool manifest.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}
⚪mandate.mint

Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.

入力スキーマ

{
  "type": "object",
  "required": [
    "organization_id",
    "agent_id",
    "grantor_principal_id",
    "budget_currency",
    "budget_total",
    "per_action_limit",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.delegate

Creates a child mandate only when it is a no-escalation subset of the parent mandate.

入力スキーマ

{
  "type": "object",
  "required": [
    "parent_mandate_id",
    "delegator_agent_id",
    "delegate_agent_id",
    "budget_total",
    "per_action_limit",
    "starts_at",
    "expires_at",
    "scopes"
  ]
}
⚪mandate.authorize-action

Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.

入力スキーマ

{
  "type": "object",
  "required": [
    "acting_agent_id",
    "action_type",
    "amount_minor",
    "counterparty"
  ]
}
⚪mandate.verify-proof

Records a proof payload hash and appends proof evidence to the hash-chained ledger.

入力スキーマ

{
  "type": "object",
  "required": [
    "organization_id",
    "subject_type",
    "subject_id",
    "proof_type",
    "payload"
  ]
}
⚪mandate.revoke

Revokes a mandate subtree and records the revocation to the hash-chained ledger.

入力スキーマ

{
  "type": "object",
  "required": [
    "revoked_by_principal_id",
    "reason"
  ]
}
⚪broker.register-credential(vault_handle, metadata)

Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.

入力スキーマ

{
  "type": "object",
  "properties": {
    "vault_handle": {
      "type": "string",
      "description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
    },
    "metadata": {
      "type": "object"
    }
  },
  "required": [
    "organization_id",
    "registered_by_agent_id",
    "label",
    "credential_type",
    "vault_handle",
    "allowed_action_type"
  ]
}
⚪broker.request-access

Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.

入力スキーマ

{
  "type": "object",
  "required": [
    "credential_id",
    "acting_agent_id",
    "mandate_id",
    "action"
  ]
}
⚪broker.use

Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.

入力スキーマ

{
  "type": "object",
  "required": [
    "grant_token",
    "acting_agent_id"
  ]
}
⚪broker.revoke-grant

Revokes a broker grant by id and records the revocation to the ledger.

入力スキーマ

{
  "type": "object",
  "required": [
    "revoked_by_agent_id",
    "reason"
  ]
}
⚪broker.introspect-grant

Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.

入力スキーマ

{
  "type": "object",
  "required": [
    "grant_token"
  ]
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 11 件
検証済みバージョンは記録されていませんツール 11 件