MandateShield Payment Authority API

REST contract for the authority lifecycle: analysis-only v1 preflight, strict v2 challenges and cryptographic verification, execution-authorization transitions, one-use execution permits, provider-submission reconciliation, signed decision/execution receipts, a zero-account lifecycle sandbox, the public proof network and deployment-activation proofs. 25 paths, 43 operations (17 explicit OPTIONS), 77 schemas, bearer API keys in VERIFY and PROCESSOR roles.

Operations 43

GET /api/account/execution-interlock Read the account-wide MandateShield execution interlock #
POST /api/account/execution-interlock Atomically PAUSE or RESUME new account-wide execution #
OPTIONS /api/v2/normalize Inspect CORS support #
POST /api/v2/normalize Project AP2, x402 v2, or MPP payment fields #
POST /api/v2/challenges Issue a one-time challenge for a registered mandate #
OPTIONS /api/v2/verify Inspect CORS support #
POST /api/v2/verify Verify signed purchase authority and issue a signed receipt #
OPTIONS /api/v2/execution-authorizations Inspect CORS support #
POST /api/v2/execution-authorizations Atomically transition one reserved execution authorization #
OPTIONS /api/v2/execution-permits/verify Inspect CORS support #
POST /api/v2/execution-permits/verify Verify a signed provider-bound execution permit #
OPTIONS /api/v2/execution-permits/redeem Inspect CORS support #
POST /api/v2/execution-permits/redeem Atomically claim one provider-bound execution permit #
OPTIONS /api/v2/provider-submissions Inspect CORS support #
POST /api/v2/provider-submissions Record one provider attempt and reconcile its outcome without trusting the caller #
POST /api/v2/provider-webhooks/stripe/{connectionId} Authenticate a Stripe event and trigger caller-independent reconciliation #
OPTIONS /api/v2/execution-receipts/verify Inspect CORS support #
POST /api/v2/execution-receipts/verify Verify a signed terminal execution receipt #
POST /api/v2/batch Verify 1–25 distinct strict authority inputs #
POST /api/v2/receipts/verify Verify a portable MandateShield decision receipt #
GET /api/v2/transparency/{receiptId} Retrieve a privacy-safe retained receipt issuance record #
OPTIONS /api/v1/preflight Inspect CORS support #
POST /api/v1/preflight Analyze a purchase against policy boundaries #
POST /api/v1/batch Analyze 1–25 purchases #
OPTIONS /api/v2/sandbox/lifecycle Inspect CORS support #
POST /api/v2/sandbox/lifecycle Run one isolated strict-lifecycle simulation #
OPTIONS /api/v1/proof-network/challenges Inspect CORS support #
POST /api/v1/proof-network/challenges Create an external-subject binding challenge #
OPTIONS /api/v1/proof-network/attestations Inspect CORS support #
POST /api/v1/proof-network/attestations Bind and sign one claimant self-report #
OPTIONS /api/v1/proof-network/proofs Inspect CORS support #
GET /api/v1/proof-network/proofs List externally bound self-report summaries #
OPTIONS /api/v1/proof-network/proofs/{proofId} Inspect CORS support #
GET /api/v1/proof-network/proofs/{proofId} Get one full signed self-report #
OPTIONS /api/v1/proof-network/proofs/{proofId}/badge.svg Inspect CORS support #
GET /api/v1/proof-network/proofs/{proofId}/badge.svg Get an explicitly labeled self-report badge #
OPTIONS /api/v1/deployment-proofs Inspect CORS support #
GET /api/v1/deployment-proofs List active server-observed deployment activations #
OPTIONS /api/v1/deployment-proofs/{proofId} Inspect CORS support #
GET /api/v1/deployment-proofs/{proofId} Get one signed deployment activation record #
OPTIONS /api/v1/deployment-proofs/{proofId}/badge.svg Inspect CORS support #
GET /api/v1/deployment-proofs/{proofId}/badge.svg Get an activation-observed badge #
GET /api/v1/threat-intelligence Get privacy-thresholded cross-account trends #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/payment-authority-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

mandateshield-com-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: MandateShield Payment Authority API
  version: 3.4.0
  description: Fail-closed authority verification, provider-bound execution permits and provider-outcome reconciliation that
    is caller-report-independent for autonomous AI-agent purchases. Only strict v2 may reserve execution; v1 is analysis-only.
    Portable permits require separate atomic online redemption. Configured Stripe API lookup and x402 canonical-chain verification
    can produce terminal evidence checked by MandateShield without trusting the caller and autonomous budget finalization.
    Caller-report-independent never means verification by an independent organization or an external audit, and publication
    does not represent adoption or enforcement by any external payment provider.
  termsOfService: https://mandateshield.com/terms
  contact:
    name: Gökhan Vodinali · MandateShield operator
    url: https://mandateshield.com/legal
    email: support@hemelion.com
servers:
- url: https://mandateshield.com
tags:
- name: Production authority
  description: Challenge, strict verification, and processor transitions. The documented eight-field invariant establishes
    only a RESERVED, consumable authorization; a trusted gateway must obtain the single winning PROCESSOR-scoped CONSUME transition
    and fresh permit claim before attempting an idempotent provider request. MandateShield does not guarantee exactly-once
    provider delivery.
- name: Account execution control
  description: Hosting-authenticated account-owner emergency control. The interlock governs new MandateShield-mediated strict
    operations inside one account regardless of provider profile. It cannot stop customer infrastructure that bypasses MandateShield
    or recall a step that committed before PAUSE.
  externalDocs:
    url: https://mandateshield.com/specifications/global-execution-interlock/v1
- name: Analysis only
  description: Policy diagnostics that always return enforcement_authorized=false.
- name: Protocol adapters
  description: Stateless documented-field projection for supported agent-payment inputs. X402 and MPP require a canonical
    payee identity whose rail-specific fields exactly match the source. A successful projection is not full source-protocol
    conformance or independent trust-evidence verification; output is deliberately non-executable and must pass strict authority
    verification before use.
- name: Receipts
  description: Public-key signed-receipt verification and privacy-safe issuance lookup.
- name: Execution evidence
  description: Provider-bound permit redemption, caller observation intake, Stripe API or x402 chain reconciliation that does
    not trust the caller assertion, autonomous terminal authorization finalization and signed execution-evidence verification.
    A signed webhook is an authenticated hint; terminal authority requires MandateShield to check the configured provider
    record or canonical-chain proof. This is not verification by an independent organization. Publication does not claim PSP
    adoption, partnership, certification or PROVIDER_ENFORCED status.
- name: Advisory intelligence
  description: Privacy-thresholded context. Signals can require REVIEW but do not automatically block.
- name: Public sandbox
  description: Zero-account, test-only and request-local lifecycle simulation. It uses ephemeral keys, contacts no external
    provider or independent organization, retains no lifecycle state and moves no money.
  externalDocs:
    url: https://mandateshield.com/specifications/strict-lifecycle-sandbox/v1
- name: Public proof network
  description: Signed externally bound self-reports. MandateShield verifies domain or exact GitHub-commit binding and claimant-report
    integrity; it does not run the claimant implementation, independently verify conformance, count entries as users or installations,
    or issue certification.
  externalDocs:
    url: https://mandateshield.com/specifications/proof-attestation/v1


# --- truncated at 32 KB (172 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/openapi/mandateshield-com-openapi.yml