MANDATE Credential Broker
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
사용해야 할까요
품질 및 안전성
발견 사항 (12)
- LOWmandate.discover에서
- LOWmandate.discover에서
- LOWmandate.mint에서
- LOWmandate.delegate에서
- LOWmandate.authorize-action에서
- LOWmandate.verify-proof에서
- LOWmandate.revoke에서
- LOWbroker.register-credential에서
- LOWbroker.request-access에서
- LOWbroker.use에서
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"mandate": {
"url": "https://mandate.nanocorp.app/mcp"
}
}
}원격 엔드포인트
https://mandate.nanocorp.app/mcpstreamable-http할 수 있는 일
도구 목록
도구 (11)
⚪mandate.discover
Returns this self-describing tool manifest.
입력 스키마
{
"type": "object",
"properties": {},
"additionalProperties": false
}⚪mandate.mint
Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.
입력 스키마
{
"type": "object",
"required": [
"organization_id",
"agent_id",
"grantor_principal_id",
"budget_currency",
"budget_total",
"per_action_limit",
"expires_at",
"scopes"
]
}⚪mandate.delegate
Creates a child mandate only when it is a no-escalation subset of the parent mandate.
입력 스키마
{
"type": "object",
"required": [
"parent_mandate_id",
"delegator_agent_id",
"delegate_agent_id",
"budget_total",
"per_action_limit",
"starts_at",
"expires_at",
"scopes"
]
}⚪mandate.authorize-action
Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.
입력 스키마
{
"type": "object",
"required": [
"acting_agent_id",
"action_type",
"amount_minor",
"counterparty"
]
}⚪mandate.verify-proof
Records a proof payload hash and appends proof evidence to the hash-chained ledger.
입력 스키마
{
"type": "object",
"required": [
"organization_id",
"subject_type",
"subject_id",
"proof_type",
"payload"
]
}⚪mandate.revoke
Revokes a mandate subtree and records the revocation to the hash-chained ledger.
입력 스키마
{
"type": "object",
"required": [
"revoked_by_principal_id",
"reason"
]
}⚪broker.register-credential(vault_handle, metadata)
Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.
입력 스키마
{
"type": "object",
"properties": {
"vault_handle": {
"type": "string",
"description": "Opaque vault reference such as vault://provider/path; never a plaintext secret."
},
"metadata": {
"type": "object"
}
},
"required": [
"organization_id",
"registered_by_agent_id",
"label",
"credential_type",
"vault_handle",
"allowed_action_type"
]
}⚪broker.request-access
Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.
입력 스키마
{
"type": "object",
"required": [
"credential_id",
"acting_agent_id",
"mandate_id",
"action"
]
}⚪broker.use
Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.
입력 스키마
{
"type": "object",
"required": [
"grant_token",
"acting_agent_id"
]
}⚪broker.revoke-grant
Revokes a broker grant by id and records the revocation to the ledger.
입력 스키마
{
"type": "object",
"required": [
"revoked_by_agent_id",
"reason"
]
}⚪broker.introspect-grant
Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.
입력 스키마
{
"type": "object",
"required": [
"grant_token"
]
}커뮤니티
증거