# MandateShield

**Canonical:** https://apis.io/providers/mandateshield-com/  
**Website:** https://mandateshield.com/  
**APIs profiled:** 4

MandateShield is a fail-closed authority-verification and execution-evidence boundary for autonomous AI-agent purchases, operated from Bern, Switzerland. It binds a signed purchase approval (AP2, TAP, UCP, x402, MPP, ACP or a custom envelope) to a registered mandate and a pinned issuer key, reserves cumulative budget atomically, consumes the reservation into a one-use provider-bound execution permit for an exact Stripe PaymentIntent or x402 request, and then checks the provider outcome without trusting the caller before issuing a signed terminal receipt. The hosted service never moves money or holds payment credentials. It publishes an OpenAPI 3.1 contract with 26 operations, a remote MCP server whose tools/list answers anonymously, a signed A2A agent card, llms.txt, an SPDX SBOM, a JWKS, a 91-code reason registry, a 19-vector conformance suite and self-hosted JavaScript, Python and Go clients.

## Kin Score — 75.2 / 100 (exemplar)

Scored 2026-10-09 under rubric 0.23.0. Trend: flat (+0.5 from 74.7).

| Facet | Score |
|---|---|
| Discoverability | 80.0 |
| Contract Quality | 53.4 |
| Contract Governance | 18.2 |
| Operational Transparency | 63.2 |
| Developer Ergonomics | 80.4 |
| Access Clarity | 84.2 |

Regulatory layer — **Payments**: 50.0 (matched via tags).

## Agent readiness — 40.3 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | flavored |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (22)

- **MandateShield MCP Server** — Hosted, stateless Streamable HTTP MCP server at https://mandateshield.com/api/mcp. Anonymous initialize and tools/list; three tools (check_ai_payment_authority, normalize_agent_...
- **MandateShield Payment Authority Agent (A2A)** — JSONRPC A2A interface at https://mandateshield.com/a2a serving A2A 1.0 and 0.3 profiles (selected by the A2A-Version header) with three skills: project agent payment fields, ana...
- **MandateShield Account execution control API** — Hosting-authenticated account-owner emergency control. The interlock governs new MandateShield-mediated strict operations inside one account regardless of provider profile. It c...
- **MandateShield Advisory intelligence API** — Privacy-thresholded context. Signals can require REVIEW but do not automatically block.
- **MandateShield Analysis only API** — Policy diagnostics that always return enforcement_authorized=false.
- **MandateShield Deployment activation proofs API** — Signed, account-bound records of an externally bound subject reaching one server-observed strict live reservation and one fresh credential-bound permit redemption. The proof flo...
- **MandateShield Deployment Proofs API** — The Deployment Proofs API from MandateShield — 3 operation(s) for deployment proofs.
- **MandateShield Execution Authorizations API** — The Execution Authorizations API from MandateShield — 1 operation(s) for execution authorizations.
- **MandateShield Execution evidence API** — Provider-bound permit redemption, caller observation intake, Stripe API or x402 chain reconciliation that does not trust the caller assertion, autonomous terminal authorization ...
- **MandateShield Execution Permits API** — The Execution Permits API from MandateShield — 2 operation(s) for execution permits.
- **MandateShield Execution Receipts API** — The Execution Receipts API from MandateShield — 1 operation(s) for execution receipts.
- **MandateShield Normalize API** — The Normalize API from MandateShield — 1 operation(s) for normalize.
- **MandateShield Preflight API** — The Preflight API from MandateShield — 1 operation(s) for preflight.
- **MandateShield Production authority API** — Challenge, strict verification, and processor transitions. The documented eight-field invariant establishes only a RESERVED, consumable authorization; a trusted gateway must obt...
- **MandateShield Proof Network API** — The Proof Network API from MandateShield — 5 operation(s) for proof network.
- **MandateShield Protocol adapters API** — Stateless documented-field projection for supported agent-payment inputs. X402 and MPP require a canonical payee identity whose rail-specific fields exactly match the source. A ...
- **MandateShield Provider Submissions API** — The Provider Submissions API from MandateShield — 1 operation(s) for provider submissions.
- **MandateShield Public proof network API** — Signed externally bound self-reports. MandateShield verifies domain or exact GitHub-commit binding and claimant-report integrity; it does not run the claimant implementation, in...
- **MandateShield Public sandbox API** — Zero-account, test-only and request-local lifecycle simulation. It uses ephemeral keys, contacts no external provider or independent organization, retains no lifecycle state and...
- **MandateShield Receipts API** — Public-key signed-receipt verification and privacy-safe issuance lookup.
- **MandateShield Sandbox API** — The Sandbox API from MandateShield — 1 operation(s) for sandbox.
- **MandateShield Verify API** — The Verify API from MandateShield — 1 operation(s) for verify.

## MCP servers (3)

- **MandateShield MCP Server** — One hosted, stateless Streamable HTTP MCP server at https://mandateshield.com/api/mcp. Anonymous initialize and tools/list both succeed (probed 2026-09-19); three tools are expo...
- **MCP endpoint, no-auth plugin profile**
- **MCP registry server.json**

## Agentic access (1)

- **Mandateshield Com Agentic Access** — 43 operations · 17 acting · 1 human-in-the-loop

## Security (4)

- **Mandateshield Com Authentication** — apiKey/http · 2 schemes
- **Mandateshield Com Domain Security** — TLSv1.3 · HSTS · DMARC
- **Mandateshield Com Vulnerability Disclosure** — security.txt · contact published
- **Mandateshield Com Trust Center** — trust center published

## Plans (1)

- **Mandateshield Com Plans Pricing**

## Tags

Company, Payments, Agentic Commerce, AI Agents, Payment Authorization, Fraud Prevention, Cryptographic Verification, MCP, A2A, x402, AP2, Stripe, Agent-Native, Switzerland

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/mandateshield-com/). Scores are computed from the provider's own public artifacts under a published rubric.
