Skip to main content
Glama

MandateShield AI Payment Authority

Server Details

Verifies signed AI payment authority before execution. Returns ALLOW, REVIEW or BLOCK; never pays.

Status
Healthy
Last Tested
Transport
Streamable HTTP
URL

Glama MCP Gateway

Connect through Glama MCP Gateway for full control over tool access and complete visibility into every call.

MCP client
Glama
MCP server

Full call logging

Every tool call is logged with complete inputs and outputs, so you can debug issues and audit what your agents are doing.

Tool access control

Enable or disable individual tools per connector, so you decide what your agents can and cannot do.

Managed credentials

Glama handles OAuth flows, token storage, and automatic rotation, so credentials never expire on your clients.

Usage analytics

See which tools your agents call, how often, and when, so you can understand usage patterns and catch anomalies.

100% free. Your data is private.

Tool Definition Quality

Score is being calculated. Check back soon.

Available Tools

2 tools
check_ai_payment_authorityCheck AI Payment Authority
Idempotent
Inspect

Analyze whether a proposed AI-agent purchase fits supplied policy facts. This v1 tool is non-executable and always returns enforcement_authorized=false; use the strict cryptographic tool for a production gate. Never send payment credentials or private keys.

ParametersJSON Schema
NameRequiredDescriptionDefault
amountYes
limitsNoSandbox analysis policy. Live v2 ignores caller policy and loads the registered mandate.
networkNoExact network or chain identifier; required for atomic X402 payments.
purposeNoNon-sensitive plain-language purchase purpose.
agent_idYesStable identifier for the acting AI agent.
asset_idNoExact token or asset identifier; required for atomic X402 payments.
protocolYesSource protocol or CUSTOM for a normalized envelope.
resourceNoExact paid resource identifier; required for atomic X402 payments.
created_atNo
expires_atNo
mandate_idYesStable identifier for the user-approved authority.
intent_hashNo
merchant_idYesStable identifier for the final seller or payee.
user_consentNo
checkout_hashNoDigest or stable identifier for the exact final checkout.
idempotency_keyYesUnique identifier for this intended payment attempt.
credential_bindingNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
modeYes
riskYes
errorNo
scoreYesDeterministic control-coverage indicator, not a calibrated probability of fraud or loss.
receiptYes
controlsYes
decisionYes
findingsYes
protocolYes
persistedYes
checked_atYes
recommended_actionYes
enforcement_authorizedYesTrue only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call.
verify_cryptographic_payment_authorityVerify Cryptographic Payment Authority
Idempotent
Inspect

Fail-closed production verification for JWS, an AP2-shaped closed-payment SD-JWT projection with RFC 9901 KB-JWT, or normalized TAP-shaped RFC 9421-style evidence. Full AP2 checkout/delegate-chain and Visa TAP structured-field/trust-store processing remain external. A qualifying live ALLOW creates only a short RESERVED authorization and cumulative-budget allocation. This MCP tool never executes payment and exposes no processor transition: a separate trusted gateway with an audience-bound PROCESSOR key must CONSUME before one provider submission, then COMMIT or RELEASE.

ParametersJSON Schema
NameRequiredDescriptionDefault
envelopeYes
evidenceYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
modeYes
riskYes
errorNo
scoreYesDeterministic control-coverage indicator, not a calibrated probability of fraud or loss.
receiptYes
controlsYes
decisionYes
findingsYes
protocolYes
assuranceYes
persistedYes
checked_atYes
transparencyYes
signed_receiptYes
recommended_actionYes
enforcement_authorizedYesTrue only when strict live verification durably creates a trusted, consumable execution reservation. It never permits a direct provider call.
execution_authorizationYes

Discussions

No comments yet. Be the first to start the discussion!

Try in Browser

Your Connectors

Sign in to create a connector for this server.

Resources