# MandateShield Payment Authority API

**Canonical:** https://apis.io/apis/mandateshield-com/payment-authority-api/  
**Provider:** MandateShield — https://apis.io/providers/mandateshield-com/  
**Base URL:** https://mandateshield.com  
**Documentation:** https://mandateshield.com/docs

MandateShield Payment Authority API is one of 3 APIs that [MandateShield](https://apis.io/providers/mandateshield-com/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 2 JSON Schema definitions. Tagged areas include Payments, Agentic Commerce, AI Agents, Payment Authorization, and Cryptographic Verification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, authentication docs, rate-limit docs, and 2 JSON Schemas.

REST contract for the authority lifecycle: analysis-only v1 preflight, strict v2 challenges and cryptographic verification, execution-authorization transitions, one-use execution permits, provider-submission reconciliation, signed decision/execution receipts, a zero-account lifecycle sandbox, the public proof network and deployment-activation proofs. 25 paths, 43 operations (17 explicit OPTIONS), 77 schemas, bearer API keys in VERIFY and PROCESSOR roles.

## Operations (43)

| Method | Path | Summary |
|---|---|---|
| GET | `/api/account/execution-interlock` | Read the account-wide MandateShield execution interlock |
| POST | `/api/account/execution-interlock` | Atomically PAUSE or RESUME new account-wide execution |
| OPTIONS | `/api/v2/normalize` | Inspect CORS support |
| POST | `/api/v2/normalize` | Project AP2, x402 v2, or MPP payment fields |
| POST | `/api/v2/challenges` | Issue a one-time challenge for a registered mandate |
| OPTIONS | `/api/v2/verify` | Inspect CORS support |
| POST | `/api/v2/verify` | Verify signed purchase authority and issue a signed receipt |
| OPTIONS | `/api/v2/execution-authorizations` | Inspect CORS support |
| POST | `/api/v2/execution-authorizations` | Atomically transition one reserved execution authorization |
| OPTIONS | `/api/v2/execution-permits/verify` | Inspect CORS support |
| POST | `/api/v2/execution-permits/verify` | Verify a signed provider-bound execution permit |
| OPTIONS | `/api/v2/execution-permits/redeem` | Inspect CORS support |
| POST | `/api/v2/execution-permits/redeem` | Atomically claim one provider-bound execution permit |
| OPTIONS | `/api/v2/provider-submissions` | Inspect CORS support |
| POST | `/api/v2/provider-submissions` | Record one provider attempt and reconcile its outcome without trusting the caller |
| POST | `/api/v2/provider-webhooks/stripe/{connectionId}` | Authenticate a Stripe event and trigger caller-independent reconciliation |
| OPTIONS | `/api/v2/execution-receipts/verify` | Inspect CORS support |
| POST | `/api/v2/execution-receipts/verify` | Verify a signed terminal execution receipt |
| POST | `/api/v2/batch` | Verify 1–25 distinct strict authority inputs |
| POST | `/api/v2/receipts/verify` | Verify a portable MandateShield decision receipt |
| GET | `/api/v2/transparency/{receiptId}` | Retrieve a privacy-safe retained receipt issuance record |
| OPTIONS | `/api/v1/preflight` | Inspect CORS support |
| POST | `/api/v1/preflight` | Analyze a purchase against policy boundaries |
| POST | `/api/v1/batch` | Analyze 1–25 purchases |
| OPTIONS | `/api/v2/sandbox/lifecycle` | Inspect CORS support |
| POST | `/api/v2/sandbox/lifecycle` | Run one isolated strict-lifecycle simulation |
| OPTIONS | `/api/v1/proof-network/challenges` | Inspect CORS support |
| POST | `/api/v1/proof-network/challenges` | Create an external-subject binding challenge |
| OPTIONS | `/api/v1/proof-network/attestations` | Inspect CORS support |
| POST | `/api/v1/proof-network/attestations` | Bind and sign one claimant self-report |
| OPTIONS | `/api/v1/proof-network/proofs` | Inspect CORS support |
| GET | `/api/v1/proof-network/proofs` | List externally bound self-report summaries |
| OPTIONS | `/api/v1/proof-network/proofs/{proofId}` | Inspect CORS support |
| GET | `/api/v1/proof-network/proofs/{proofId}` | Get one full signed self-report |
| OPTIONS | `/api/v1/proof-network/proofs/{proofId}/badge.svg` | Inspect CORS support |
| GET | `/api/v1/proof-network/proofs/{proofId}/badge.svg` | Get an explicitly labeled self-report badge |
| OPTIONS | `/api/v1/deployment-proofs` | Inspect CORS support |
| GET | `/api/v1/deployment-proofs` | List active server-observed deployment activations |
| OPTIONS | `/api/v1/deployment-proofs/{proofId}` | Inspect CORS support |
| GET | `/api/v1/deployment-proofs/{proofId}` | Get one signed deployment activation record |
| OPTIONS | `/api/v1/deployment-proofs/{proofId}/badge.svg` | Inspect CORS support |
| GET | `/api/v1/deployment-proofs/{proofId}/badge.svg` | Get an activation-observed badge |
| GET | `/api/v1/threat-intelligence` | Get privacy-thresholded cross-account trends |

## Machine-readable artifacts (18)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/openapi/mandateshield-com-openapi.yml
- **OpenAPI** — https://mandateshield.com/openapi.json
- **OpenAPI** — https://mandateshield.com/openapi/3.4.0.json
- **Documentation** — https://mandateshield.com/docs
- **APIReference** — https://mandateshield.com/docs
- **GettingStarted** — https://mandateshield.com/connect
- **Authentication** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/authentication/mandateshield-com-authentication.yml
- **Conventions** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/conventions/mandateshield-com-conventions.yml
- **Idempotency** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/conventions/mandateshield-com-conventions.yml
- **ErrorCatalog** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/errors/mandateshield-com-problem-types.yml
- **ErrorCodes** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/errors/mandateshield-com-error-codes.yml
- **DataModel** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/data-model/mandateshield-com-data-model.yml
- **RateLimits** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/rate-limits/mandateshield-com-rate-limits.yml
- **Sandbox** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/sandbox/mandateshield-com-sandbox.yml
- **Overlay** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/overlays/mandateshield-com-openapi-overlay.yaml
- **JSONSchema** — https://mandateshield.com/schemas/execution-permit-v1.json
- **JSONSchema** — https://mandateshield.com/schemas/execution-receipt-v1.json
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/mandateshield-com/refs/heads/main/apis.yml

## Other MandateShield APIs (2)

- [MandateShield MCP Server](https://apis.io/apis/mandateshield-com/mcp-server/)
- [MandateShield Payment Authority Agent (A2A)](https://apis.io/apis/mandateshield-com/a2a-agent/)

## Tags

Payments, Agentic Commerce, AI Agents, Payment Authorization, Cryptographic Verification

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/mandateshield-com/payment-authority-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/mandateshield-com/.
