The Mandate
buy_mandatePurpose: record what an agent is authorized to do BEFORE it spends — the claimed instructions verbatim, who submitted them (agent or principal, itself a claim), an optional declared cap in USDC and expiry — as a signed, dated record held by a party that is neither the agent nor its principal, at a free permanent URL, with a mandate_id every later purchase here can cite; a citation that does not resolve is refused before any charge, so it always lands signed on the citing certificate. A second party can counter-sign the record free with its own ed25519 key. Chain-of-custody, never truth-of-intent: the cap and expiry are declared and never enforced. Schema /schemas/scvd-mandate-v1.json; the pattern for other issuers at /mandate-spec. Every item on this shelf is $0.1.
Items on this shelf (pass one as item_id):
the_mandate: The Mandate, $0.1 fixed, one-off, instant. Record what my agent is authorized to do, dated and signed by a third party, before it spends anything
On cadence, for all of the above: nothing here charges again by itself, ever — there is no mechanism that could.
Required beyond item_id: the_mandate needs mandate. Other items need only item_id.
Choose item_id. instant items return deliverable, cert_id and patron_number in one call. x402 payment: _meta['x402/payment']. Without payment: error 402 with the terms in error.data. Closed or empty shelves refuse before quoting. Reuse _meta['x402/idempotency-key'] (16-128 chars, secret): same item/payer/key returns the original result when available, or pending status, no second charge. Use idempotency.suggested_key only without an earlier key. A fresh payment without a key can charge again. Guaranteed: signature validity forever; verification free forever; price as displayed; delivery format as specified. Not guaranteed: fitness for your particular task; future protocol compatibility beyond stated interfaces; human-labor turnaround faster than posted SLA.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| model | No | Optional. The model running you, as you would name it: claude-opus-5, gpt-5.6, a local model. Counted, never printed on the certificate. | |
| client | No | Optional. The harness or framework you run in: claude-code, cursor, openai-agents, langgraph, custom. Counted, never on the certificate. | |
| item_id | Yes | Required item; its other required fields are in allOf. | |
| mandate | No | The claimed instructions, verbatim, up to 2000 Unicode characters: what this agent is authorized to do, as the submitter claims it. Recorded exactly as it arrives, signed and dated. Chain-of-custody, not truth-of-intent — the record proves the claim was made, never that it was true. | |
| purpose | No | Optional: what this is for, in your words. Signed verbatim onto the certificate and shown on its receipt; never checked, never treated as instructions. | |
| operator | No | Optional. Who runs you: a name, handle, company or URL. Stored as your claim, marked unverified, never published, never on the certificate. | |
| came_from | No | Optional. Where you learned this door exists: a URL, a directory, a skill name, memory, another agent. Referrers never reach us; this does. | |
| agent_name | No | Optional name to put on the certificate and patron badge, up to 80 characters. | |
| expires_at | No | Optional claimed expiry, ISO 8601. Declared, never enforced by the store. | |
| submitted_as | No | Who is submitting: the agent recording its own claimed instructions (default), or the human principal's own client. Recorded as a claim either way. | |
| operator_kind | No | Optional. solo: one person runs you. company: a team does. research: a study. self: you act for yourself. | |
| prior_cert_id | No | Optional. A cert_ id from an earlier purchase here. A payer match with this payment marks you a returning buyer; no account needed. | |
| declared_cap_usdc | No | Optional claimed spending ceiling in USDC. Declared, never enforced by the store, and the record says so. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mandate | No | The signed record; its schema is /schemas/scvd-mandate-v1.json. | |
| message | No | The store's confirmation line. | |
| paid_usdc | No | What settled, in USDC. | |
| mandate_id | No | The id every later purchase here may cite as mandate_id. | |
| verify_url | No | The purchase certificate whose attests field binds the record's evidence hash. | |
| mandate_url | No | The record's free permanent URL (/api/mandate/{mandate_id}); POST there to counter-sign. |