Skip to main content
Glama

Wever Labs Agent Products

AP2 Mandate Gateway

wever_ap2-mandate-gateway
Destructive

Unavailable historical backend. Sandbox/demo: parses mandate-reference text and hashes a binding to a generated sample receipt. It does not verify an AP2 signature, principal, merchant, budget or expiry, and it grants no payment or execution authority. Accept AP2-style mandate references, check bounded authority, and bind the mandate to rail run receipt proof. Operating boundary: Accepts AP2-style mandate references for bounded agent-to-merchant authority checks and binds the mandate reference to run, receipt, callback, and return-package proof. POST /api/ap2-mandate-gateway. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
modeNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

C2.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes well beyond annotations: it discloses that no AP2 signature, principal, merchant, budget, or expiry is verified, that it confers no payment/execution authority, that it never supplies server credentials, and that unavailable or non-JSON backends surface as tool errors. That is unusually rich operational disclosure, though the internal tension between 'check bounded authority' and 'grants no... authority' muddies the picture.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The text is repetitive and self-contradictory: authority denial is restated three times, while 'check bounded authority' sits against 'grants no... authority'. The lead sentence ('Unavailable historical backend') front-loads a caveat instead of the tool's purpose, and the API endpoint is buried mid-paragraph.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a proxy POST with no output schema, the description covers prerequisites, authority limits, and error surface, which is most of what an agent needs. It still leaves unclear what a successful call returns (only 'a generated sample receipt' is mentioned) and how the sandbox/demo behavior relates to the documented gateway contract.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% for the single 'mode' property, so the description has to compensate. It adds that the POST body must carry documented mode/arguments plus required signed authority or grants, which meaningful beyond the bare 'mode' enum-less string, but it supplies no format, casing, or valid values for mode itself.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a concrete resource and action set ('Accept AP2-style mandate references... bind the mandate to rail run receipt proof'), but the opening line 'Unavailable historical backend' and the sandbox framing leave the agent unsure whether this tool actually performs those actions. It also never distinguishes itself from the many adjacent authority/payment siblings (wever_delegated-authority, wever_payment-authority-inspector, wever_unified-agent-checkout).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use or when-not-to-use guidance and no named alternative, despite a crowded sibling set covering authority checks, mandates, and payment rails. The only contextual line ('Existing product credentials, signed mandates, and single-use action grants remain required where applicable') is a prerequisite, not routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.