agent-mandate-mcp
Agent Mandate MCP
Verification-only MCP server exposing one tool: verify_action.
The tool sends caller-supplied mandate and action facts to Agent Mandate's
POST /v1/verify endpoint and returns its allow, deny, or
requires_approval receipts. It does not issue or revoke mandates, execute an
action, change an account, or call billing. It makes at most one API request per
tool call and never retries automatically.
Status: public source; npm package and Official MCP Registry release pending. The repository link below is live. The npm and Registry identities become available only after their separate public releases:
npm:
@api-disk-integrations/agent-mandate-mcp@0.1.0Official MCP Registry:
io.github.API-Disk-Integrations/agent-mandate@0.1.0source:
API-Disk-Integrations/agent-mandate-mcp
Install and run
After the exact package version is publicly published and independently read back, run it with the version pinned:
AGENT_MANDATE_API_KEY="$AGENT_MANDATE_API_KEY" \
npx --yes @api-disk-integrations/agent-mandate-mcp@0.1.0Do not commit a literal credential. A generic stdio client configuration is:
{
"mcpServers": {
"agent-mandate": {
"command": "npx",
"args": ["--yes", "@api-disk-integrations/agent-mandate-mcp@0.1.0"],
"env": {
"AGENT_MANDATE_API_KEY": "${AGENT_MANDATE_API_KEY}"
}
}
}
}${AGENT_MANDATE_API_KEY} denotes the host's secret/environment reference.
Use the client host's documented secret facility if its interpolation syntax
differs. The package uses stdio and reads exactly that environment variable;
it has no remote /mcp endpoint.
Tool contract
There is exactly one tool, verify_action. Supply either one action or an
actions array, never both. A batch contains 1–500 actions. Monetary amounts
are non-negative integer minor units and require currency.
Example input:
{
"mandate": {
"mandate": {"id": "mnd_example"},
"signature": "caller-supplied-signature"
},
"action": {
"agent": "procurement-agent",
"action": "payments.transfer",
"resource": "vendor.acme",
"amountMinor": 2500,
"currency": "USD",
"at": "2026-09-05T20:00:00Z"
}
}Representative successful structured output:
{
"count": 1,
"receipts": [
{
"decision": "deny",
"mandateId": "mnd_example",
"violations": [{"code": "action_not_granted", "detail": "No matching grant"}]
}
]
}Treat all three decisions literally. In particular, neither allow nor
requires_approval executes the proposed action.
Errors, limits, and safety
If
AGENT_MANDATE_API_KEYis absent, the tool returns an MCP error before making a request.A provider error is reduced to its numeric HTTP status and an allowlisted code. Provider-controlled message and request-ID text is never returned to the model.
One tool call produces at most one HTTPS request to the fixed
https://agentmandate-api.com/v1/verifyendpoint. There is no automatic retry; Fetch uses explicitredirect: error, and redirect responses are rejected without a follow-up request.The serialized UTF-8 request and decoded response body each have a hard 1 MiB (1,048,576-byte) limit. The request is measured before Fetch. The response is counted while streaming before JSON parsing, regardless of a missing, misleading, or chunked
Content-Lengthrepresentation.The request timeout defaults to 30 seconds. A batch is also limited to 500 actions. Provider account rate and monthly usage limits still apply; consult the current product pricing and documentation before production use.
The server is read-only with respect to mandate, account, and billing state, but an API verification consumes the caller's metered allowance.
Node.js 20 or newer is required. This release is tested for MCP protocol revision
2026-07-28and retains the SDK's listed 2025 compatibility revisions.
Links
The source link is not evidence that the npm package or Registry listing is available. Those two releases require their own public readback. A clone, install, download, tool call, or listing is not evidence of customer activation or revenue.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/API-Disk-Integrations/agent-mandate-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server