Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MANDARE_LEDGER_DBNoPath to the ledger database read by the MCP server./mandare-ledger.db

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
mandare_verifyA

Verify the local ledger: hash chain, door signatures, RFC 6962 tree head, spend trail and budget-counter replay, approval trail, and revocation state. With check_witness=true also checks the chain against the externally witnessed head history (catches truncation and rewrites). Returns the machine-readable verification report. Read-only.

mandare_budget_statusA

Per-mandate spend from the ledger: settled and reserved amounts (integer micro-units of the ledger currency), intent counts, refusal count, and whether the live budget counters equal a fresh replay of the ledger. Use before starting expensive work. Read-only.

mandare_issue_passportA

Issue an Agent Delegation Credential (SD-JWT VC) for a NEW agent: owner + local attestation authority keys from the vault, fresh agent did:key, revocation slot registered on the ledger. The credential and the agent private key are written to the operator-configured home directory; the result references them by path and never contains key material.

mandare_issue_mandateA

Issue an owner-signed mandate (SD-JWT VC) for an agent: spend caps in WHOLE currency units (per transaction / day / task / total), optional human-approval threshold, validity window. The mandate file path is returned; point the gateway at it (MANDARE_MANDATE_PATH).

mandare_issue_tokenA

Mint a short-lived proof-of-possession token an agent presents to the gateway (TTL ≤ 30 minutes). The grant INCLUDING ITS ONE-TIME SECRET is written 0600 to the operator-configured home directory; the result references it by path only — hand the FILE to the agent process (e.g. @mandarelabs/sdk tokenCredentialsFromIssueJson), never paste its contents into chat.

mandare_killA

The LOCAL, offline, fail-closed kill: revoke ONE agent, ONE mandate (the agent survives, the permission slip dies), or --all (halts the whole door). Writes the revocation to the ledger; the gateway refuses the subject on its very next request. Bound virtual cards are revoked too. Kills only CLOSE doors — reversing one requires the operator (mandare reinstate).

mandare_certifyA

Build the selective-disclosure integrity certificate (chain valid · witnessed · anchored) a third party can verify WITHOUT ledger access. Optionally disclose specific entries by seq; undisclosed entries stay salted hashes. Requires a configured witness.

mandare_gateway_healthA

Read the running gateway door /healthz (halted state, card rail, witness gating). Requires MANDARE_GATEWAY_URL in the MCP server environment. Read-only.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 8 tools

Disambiguation4/5

The three issue_* tools target clearly distinct artifacts (agent identity passport, spend mandate, session token), and the read-only tools split cleanly by target (ledger integrity, budget, gateway health). Minor potential overlap between mandare_verify and mandare_certify, since both concern ledger integrity, but their descriptions distinguish local verification from third-party disclosure certificates.

Naming Consistency4/5

All tools share the mandare_ prefix and are largely verb-led (verify, issue_*, kill, certify), which reads predictably. Two names (budget_status, gateway_health) are noun phrases rather than verbs, a small deviation from the otherwise consistent verb pattern.

Tool Count5/5

Eight tools is well-scoped for a delegated-authority gateway: identity issuance, mandate issuance, token minting, verification, budget inspection, revocation, certification, and health. Each tool earns its place with no obvious redundancy.

Completeness3/5

The issue/verify/budget/kill/certify lifecycle is mostly covered, but the kill description explicitly notes that reversal requires an operator-side 'reinstate' that has no MCP counterpart, and there is no tool to list or enumerate existing agents, mandates, or tokens. These are notable gaps an agent cannot work around from the tool surface alone.

Maintenance

ActivityMaintained
ResponsivenessNo issues