Skip to main content
Glama

Prepare SAP Agent Mandate

sap_prepare_mandate
Read-onlyIdempotent

Free AP2-style mandate planner for SAP MCP agent commerce. It converts a user intent into a bounded, unsigned planning artifact with spend limits, tool/protocol allow-lists, freshness rules, confirmation thresholds, proof-tape fields, and the correct hosted/local signing route. This tool does not sign, submit, authorize payment, or replace wallet confirmation.

SAP MCP execution guidance: Intent: SAP MCP tool workflow. Pricing: free; call directly without x402. Routing: free hosted call; call directly and keep it small/exact when possible. Signer boundary: hosted reads/builders never receive keypair bytes; value-moving results must be finalized locally when signing is required.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
intentYesHuman intent to bind, for example "check solking.sol", "register Solking", "swap 0.05 SOL to USDC", or "open a $10 BONK short".
walletNoOptional expected owner/signer wallet public key in base58. Used only as a public constraint, never as a keypair path.
profileNoOptional local SAP profile name the user expects the runtime to use. Do not guess wallet/keypair paths from this value.
maxX402UsdNoMaximum x402/pay.sh fee the agent may auto-pay for one hosted tool call under the user policy.
maxTradeUsdNoMaximum value-moving notional in USD for swaps, perps, escrow, or transaction finalization under this mandate.
allowedToolsNoExact SAP MCP tool allow-list for this mandate. Use exact names from tools/list and do not rewrite hyphenated tools.
operationTypeNoClosest operation family. Use registry-write for SAP agent registration/update, escrow for SAP Escrow V2, and transaction-finalize when an unsigned hosted transaction is already available.
maxSlippageBpsNoMaximum slippage in basis points for swap or trading routes. 100 means 1%.
maxTotalX402UsdNoMaximum total x402/pay.sh spend for this mandate before asking the user again.
allowedProtocolsNoProtocol allow-list such as sap, mcp, x402, jupiter, adrena, pyth, metaplex, sns, magicblock, or custom protocol ids.
expiresInSecondsNoMandate TTL in seconds. Defaults to 900 and is capped to 86400.
requireConfirmationAboveUsdNoRequire a human preview and explicit confirmation above this USD notional or spend threshold.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
routeYesCanonical hosted/local route for this operation type.
mandateYesUnsigned mandate planning artifact. This is not a signature and not a payment authorization.
successYesWhether the mandate draft was generated.
freshnessYesData that must be fetched fresh before paid, signed, or value-moving actions.
nextToolCallsYesExact next SAP MCP tool calls recommended for this mandate.
forbiddenActionsYesActions agents must not perform under this mandate.
proofTapeTemplateYesAudit record shape to fill as execution proceeds.
confirmationPolicyYesWhen the agent must show a compact preview and ask the user to confirm.

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=true, idempotentHint=true), the description adds important behavioral traits: 'hosted reads/builders never receive keypair bytes', 'value-moving results must be finalized locally', and explicit non-actions (sign, submit, authorize payment). These details help an agent avoid unauthorized or unsafe operations and are not present in the annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is relatively long and includes a second paragraph of 'SAP MCP execution guidance' that is partly boilerplate. The line 'Intent: SAP MCP tool workflow' is vague and does not add value. While the first paragraph is clear and structured, the overall text could be tightened without losing critical information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description effectively conveys the tool's role, output (unsigned planning artifact), and safety boundaries, which is sufficient given the rich input schema and presence of an output schema. It does not explain error conditions, but that is not required for a read-only planning tool with good annotations. The guidance about free routing and signer boundaries adds operational completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 100% description coverage with individual parameter descriptions. The tool description mentions high-level categories (spend limits, allow-lists, confirmation thresholds) but does not add additional semantics beyond what the schema already provides. Baseline of 3 is appropriate since the schema handles parameter meaning comprehensively.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function: 'converts a user intent into a bounded, unsigned planning artifact' with specific components like spend limits, allow-lists, and thresholds. It distinguishes itself from signing/submitting tools by explicitly saying what it does not do ('does not sign, submit, authorize payment'), which sets it apart from sibling tools like sap_sign_transaction or sap_submit_signed_transaction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context that this is a planning/preparation tool, not an execution tool, and includes routing guidance ('Pricing: free; call directly without x402'). It does not explicitly name alternative tools but implicitly tells the agent to use it when constructing a mandate and to use signing/finalization tools separately. This is strong enough for an agent to decide when to invoke it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.2/5.0
Disambiguation4/5

Tools are organized by protocol prefix (e.g., adrena_, jupiter_, sap_) which helps distinguish domains. Within each protocol, tool names clearly indicate actions (e.g., openPosition, getQuote). However, with 360 tools, some cross-protocol overlaps (e.g., multiple swap tools) and many similar fetch tools in the sap_* family require careful reading of descriptions to disambiguate.

Naming Consistency4/5

Each protocol group follows a consistent naming convention (e.g., snake_case for adrena_, camelCase for 3land, sap_ prefix for SAP SDK tools). The mix of conventions across protocols is acceptable, though a uniform style would improve predictability. Minor inconsistency: hyphenated names like metaplex-nft_ vs underscores.

Tool Count2/5

360 tools is far too many for a well-scoped MCP server. This aggregates dozens of protocols and SAP-specific features, making navigation difficult. The server would benefit from being split into focused micro-servers (e.g., SAP identity, Jupiter DEX, NFT tools). The current count overwhelms the coherence of the set.

Completeness4/5

The tool set covers a vast range of Solana ecosystem activities: token operations, swaps, staking, NFT management, bridging, oracle data, identity registration, chat, escrow, subscriptions, and premium streaming. Major lifecycle operations are present, though some niche subdomains may have missing functions (e.g., detailed governance or lending management). Overall, it's comprehensive for the intended scope.