MandateShield AI Payment Evidence
Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.
What it says
The record the registry holds
Where it answers
https://mandateshield.com/api/mcp · streamable-http
the record
Copied from the official MCP registry, exactly as it holds it.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "com.mandateshield/payment-authority",
"description": "Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.",
"title": "MandateShield AI Payment Evidence",
"version": "1.13.0",
"websiteUrl": "https://mandateshield.com/connect",
"icons": [
{
"src": "https://mandateshield.com/icon-192.png",
"mimeType": "image/png",
"sizes": [
"192x192"
]
},
{
"src": "https://mandateshield.com/icon-512.png",
"mimeType": "image/png",
"sizes": [
"512x512"
]
},
{
"src": "https://mandateshield.com/favicon.svg",
"mimeType": "image/svg+xml",
"sizes": [
"any"
]
}
],
"remotes": [
{
"type": "streamable-http",
"url": "https://mandateshield.com/api/mcp",
"headers": [
{
"description": "Optional VERIFY-scoped API key for strict production tools. Include Bearer; never use a PROCESSOR key.",
"isSecret": true,
"name": "Authorization"
}
]
}
],
"_meta": {
"io.modelcontextprotocol.registry/publisher-provided": {
"a2aAgentCard": "https://mandateshield.com/.well-known/agent-card.json",
"agentCatalog": "https://mandateshield.com/.well-known/ai-catalog.json",
"analysisOnly": "https://mandateshield.com/api/v1/preflight",
"cli": "https://mandateshield.com/sdk/v1.13.0/mandateshield-cli.mjs",
"connect": "https://mandateshield.com/connect",
"cryptographicBatch": "https://mandateshield.com/api/v2/batch",
"cryptographicVerification": "https://mandateshield.com/api/v2/verify",
"currentRelease": "https://mandateshield.com/current-release.json",
"executionContract": {
"analysisIsExecutable": false,
"authorityValid": true,
"authorizationState": "RESERVED",
"callerReportIndependentEvidenceCanAutonomouslyFinalize": true,
"callerReportIndependentEvidenceClasses": [
"PROVIDER_API_VERIFIED",
"CHAIN_FINALIZED"
],
"consumable": true,
"decision": "ALLOW",
"enforcementAuthorized": true,
"externalAuditOrIndependentOrganizationClaimed": false,
"keyTrust": "ACCOUNT_PINNED",
"legacyUnboundConsumeAllowedOnlyForAccountsCreatedBefore": "2026-07-26T12:01:24.000Z",
"missingAccountCreationTimeFailsClosed": true,
"mode": "live",
"offlineVerificationPermitsSubmission": false,
"persisted": true,
"processorConsumeRequired": true,
"providerBoundConsumeRequiredForNewAccounts": true,
"providerBoundConsumeRequiredFromAccountCreatedAt": "2026-07-26T12:01:24.000Z",
"providerOrFacilitatorAdoptionClaimed": false,
"providerRedemptionRequired": true,
"providerSubmissionReportIsTerminalProof": false,
"signedWebhookIsTerminalProof": false,
"unknownAndConflictRemainFailClosed": true
},
"executionEvidenceVerifier": "https://mandateshield.com/sdk/v1.13.0/mandateshield-execution-evidence-verifier.mjs",
"executionRule": "V1 tools never authorize payment. Strict live verification creates only RESERVED. New accounts must CONSUME with exact provider binding in a credential-isolated gateway; older accounts retain legacy compatibility. A fresh claim authorizes an idempotent provider request, not exactly-once delivery. Reports and webhooks are hints. MandateShield checks configured Stripe or x402 evidence without trusting the caller before finalization. Caller-independent is not an external audit or independent-organization verification. Unknown or conflicting outcomes fail closed.",
"fullDiscovery": "https://mandateshield.com/.well-known/mandateshield.json",
"installableCurrentPackage": "https://mandateshield.com/sdk/mandateshield-sdk-current.tgz",
"installableVersionedPackage": "https://mandateshield.com/packages/npm/1.13.0/mandateshield-sdk-1.13.0.tgz",
"installableVersionedPackageSha256": "https://mandateshield.com/packages/npm/1.13.0/SHA256SUMS",
"integrationGuide": "https://mandateshield.com/integrations",
"javascriptClient": "https://mandateshield.com/sdk/v1.13.0/mandateshield.mjs",
"jwks": "https://mandateshield.com/.well-known/jwks.json",
"openapi": "https://mandateshield.com/openapi.json",
"paymentAuthorityDiscovery": "https://mandateshield.com/.well-known/agent-payment-authority.json",
"proofAttestationSpec": "https://mandateshield.com/specifications/proof-attestation/v1",
"proofNetwork": "https://mandateshield.com/api/v1/proof-network/proofs",
"proofNetworkAttestation": "https://mandateshield.com/api/v1/proof-network/attestations",
"proofNetworkChallenge": "https://mandateshield.com/api/v1/proof-network/challenges",
"publicProofSemantics": "Externally bound self-report; not users, installations, certification, or independently executed conformance.",
"releaseManifest": "https://mandateshield.com/evidence/v1.13.0/release-manifest.json",
"specification": "https://mandateshield.com/standard",
"standaloneNoAuthMcp": "https://mandateshield.com/api/mcp/plugin",
"standardVersion": "2.4.0",
"verificationChallenge": "https://mandateshield.com/api/v2/challenges",
"versionedOpenapi": "https://mandateshield.com/openapi/3.4.0.json",
"website": "https://mandateshield.com",
"zeroAccountSandbox": "https://mandateshield.com/api/v2/sandbox/lifecycle",
"zeroAccountSandboxSpec": "https://mandateshield.com/specifications/strict-lifecycle-sandbox/v1",
"zeroAccountTrial": "https://mandateshield.com/sdk/mandateshield-trial.mjs"
}
}
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-07-28T18:28:01.853949Z",
"publishedAt": "2026-07-28T18:28:01.853949Z",
"updatedAt": "2026-07-28T18:28:01.853949Z",
"isLatest": true
}
}
}
Make it installable
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
What this is
MCP server
application/mcp-server-record+jsonhosted · an address you callversion 1.13.0last seen 2026-08-23
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.
Where it lives
The publisher's own address
https://mandateshield.com/connect
The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.