Skip to main content
Glama
API-Disk-Integrations

agent-mandate-mcp

Verify an action against an Agent Mandate

verify_action
Read-only

Verifies a proposed action against a signed mandate envelope, returning an allow, deny, or requires_approval receipt without executing the action.

Instructions

Verification only: evaluate supplied action facts against a signed mandate. The mandate argument is the envelope returned by POST /v1/mandates, which carries the claims under mandate alongside its signature — pass that response through unchanged. A bare claims object is what the keyless POST /v1/demo/verify route accepts, and it is rejected here. This tool does not execute the action or mutate any account.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
actionNo
actionsNo
mandateYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
countYes
receiptsYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.1.1
    • addedInput schema / properties / mandate / properties
      Added value: +{
      +  "mandate": {
      +    "additionalProperties": {},
      +    "propertyNames": {
      +      "type": "string"
      +    },
      +    "type": "object"
      +  },
      +  "signature": {
      +    "minLength": 1,
      +    "type": "string"
      +  }
      +}
    • removedInput schema / properties / mandate / propertyNames
      Removed value: -{
      -  "type": "string"
      -}
    • addedInput schema / properties / mandate / required
      Added value: +[
      +  "mandate",
      +  "signature"
      +]
  2. First observedv0.1.0

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false. The description reinforces this non-mutating behavior and adds useful nuances: the mandate must be passed as the full envelope, not a bare claims object, which would be rejected. This goes beyond the annotations without contradicting them.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences: the first states the core purpose, the second details the required mandate format, and the third rules out execution/mutation. Every sentence earns its place, and the most important information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema covers return values and annotations cover safety, the description handles the key trap: correctly passing the mandate envelope. The only notable gap is the lack of orientation around the optional `action` and `actions` parameters, which could leave an agent unsure which to supply. Still, the core usage is well covered.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It does a good job on the `mandate` parameter, explaining it is the envelope from POST /v1/mandates with claims under `mandate` beside `signature` and should be passed unchanged. However, it gives no guidance on the `action` vs `actions` parameters—whether they are alternatives, when each should be used, or what their fields mean—leaving that to inference from the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'Verification only: evaluate supplied action facts against a signed mandate,' which states a specific verb, resource, and scope. It also explicitly distinguishes itself from executing or mutating, making the purpose unmistakable even without sibling tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly establishes this tool is for verification only and should not be used to execute actions ('This tool does not execute the action or mutate any account'). It also explains which input form is accepted ('mandate envelope returned by POST /v1/mandates') and which is rejected ('bare claims object'), providing practical usage context. It does not name alternatives, but there are no siblings, and the context is otherwise clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools