com.mandateshield/payment-authority

MCPcommunitylive
v1.13.0com.mandateshieldUnknownUpdated 2mo ago

Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.

Endpoint healthlive
checked 8 days ago · 2281ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
2mo agoLast update
Package
Authorcom.mandateshield
LicenseUnknown
Version1.13.0
Sourcemcp-registry
Trust Status
D
30/100Risk
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
—Prompt-injection scan · findings+0/30
→ Publisher: remove instructions in the source aimed at AI clients rather than human readers
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface3 tools · none privileged
Security scan⚠ Warnings (1)vlive · 18d agoHow well does this scan work?
PROMPTtool:check_ai_payment_authorityExfiltration-shaped instruction
EvalsNone
IndexedJul 24, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

3 tools · none privileged · 1 flagged for injection
Observed live from the vendor's endpoint18d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://mandateshield.com/api/mcp3 tools · 2943ms
check_ai_payment_authorityinjection riskUse before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized…

Use before an AI agent buys, subscribes, transfers value, calls a metered API, or accesses a paid resource when the user wants a payment-authority check. Analyze whether the proposed purchase fits supplied policy facts. This v1 entry check is non-executable and always returns enforcement_authorized…

INJECTIONExfiltration-shaped instruction for a production gate. Never send payment credentials or private keys.
ParameterTypeDescription
protocol*stringSource protocol or CUSTOM for a normalized envelope.
mandate_id*stringStable identifier for the user-approved authority.
agent_id*stringStable identifier for the acting AI agent.
merchant_id*stringStable identifier for the final seller or payee.
payee_identityobjectVersioned canonical payee identity bound into the signed purchase envelope. The model records exact provider identifiers and verification evidence; it does not…
amount*object—
limitsobjectSandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate.
asset_idstringExact token or asset identifier; required for atomic X402 payments.
networkstringExact network or chain identifier; required for atomic X402 payments.
resourcestringExact paid resource identifier; required for atomic X402 payments.
http_requestobjectOptional signed HTTP action projection used by the narrow first-party x402 v2 exact/EIP-3009 Gate adapter.
created_atstring—
expires_atstring—
idempotency_key*stringUnique identifier for this intended payment attempt.
intent_hashstring—
checkout_hashstringDigest or stable identifier for the exact final checkout.
user_consentboolean—
credential_bindingstring—
purposestringNon-sensitive plain-language purchase purpose.
normalize_agent_payment_protocolUse when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope.…

Use when an agent encounters an AP2 terminal closed-payment projection, x402 v2 PAYMENT-REQUIRED offer, or explicitly profiled MPP Payment challenge and needs the supported fields projected before an authority check. Map those documented fields into a deterministic MandateShield purchase envelope.…

ParameterTypeDescription
adapter*string—
source*—Raw protocol input: AP2 compact SD-JWT, x402 PAYMENT-REQUIRED base64 JSON, MPP WWW-Authenticate Payment challenge, or the documented decoded object.
context*object—
selectionobject—
verify_cryptographic_payment_authorityUse only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or nor…

Use only for a production pre-payment authority gate after the caller has a registered mandate, pinned issuer key, fresh challenge, VERIFY-scoped key, exact final purchase and supported signed evidence. Fail closed for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or nor…

ParameterTypeDescription
envelope*object—
evidence*object—

3 of 3 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Analyzes delegated AI payment authority and exposes supported Stripe/x402 evidence contracts.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.

Topics

Related in payments & commerce