Mandare
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MANDARE_LEDGER_DB | No | Path to the ledger database read by the MCP server | ./mandare-ledger.db |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| mandare_verifyA | Verify the local ledger: hash chain, door signatures, RFC 6962 tree head, spend trail and budget-counter replay, approval trail, and revocation state. With check_witness=true also checks the chain against the externally witnessed head history (catches truncation and rewrites). Returns the machine-readable verification report. Read-only. |
| mandare_budget_statusA | Per-mandate spend from the ledger: settled and reserved amounts (integer micro-units of the ledger currency), intent counts, refusal count, and whether the live budget counters equal a fresh replay of the ledger. Use before starting expensive work. Read-only. |
| mandare_issue_passportA | Issue an Agent Delegation Credential (SD-JWT VC) for a NEW agent: owner + local attestation authority keys from the vault, fresh agent did:key, revocation slot registered on the ledger. The credential and the agent private key are written to the operator-configured home directory; the result references them by path and never contains key material. |
| mandare_issue_mandateA | Issue an owner-signed mandate (SD-JWT VC) for an agent: spend caps in WHOLE currency units (per transaction / day / task / total), optional human-approval threshold, validity window. The mandate file path is returned; point the gateway at it (MANDARE_MANDATE_PATH). |
| mandare_issue_tokenA | Mint a short-lived proof-of-possession token an agent presents to the gateway (TTL ≤ 30 minutes). The grant INCLUDING ITS ONE-TIME SECRET is written 0600 to the operator-configured home directory; the result references it by path only — hand the FILE to the agent process (e.g. @mandarelabs/sdk tokenCredentialsFromIssueJson), never paste its contents into chat. |
| mandare_killA | The LOCAL, offline, fail-closed kill: revoke ONE agent, ONE mandate (the agent survives, the permission slip dies), or --all (halts the whole door). Writes the revocation to the ledger; the gateway refuses the subject on its very next request. Bound virtual cards are revoked too. Kills only CLOSE doors — reversing one requires the operator (mandare reinstate). |
| mandare_certifyA | Build the selective-disclosure integrity certificate (chain valid · witnessed · anchored) a third party can verify WITHOUT ledger access. Optionally disclose specific entries by seq; undisclosed entries stay salted hashes. Requires a configured witness. |
| mandare_gateway_healthA | Read the running gateway door /healthz (halted state, card rail, witness gating). Requires MANDARE_GATEWAY_URL in the MCP server environment. Read-only. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
The three issue_* tools target clearly distinct artifacts (agent identity passport, spend mandate, session token), and the read-only tools split cleanly by target (ledger integrity, budget, gateway health). Minor potential overlap between mandare_verify and mandare_certify, since both concern ledger integrity, but their descriptions distinguish local verification from third-party disclosure certificates.
All tools share the mandare_ prefix and are largely verb-led (verify, issue_*, kill, certify), which reads predictably. Two names (budget_status, gateway_health) are noun phrases rather than verbs, a small deviation from the otherwise consistent verb pattern.
Eight tools is well-scoped for a delegated-authority gateway: identity issuance, mandate issuance, token minting, verification, budget inspection, revocation, certification, and health. Each tool earns its place with no obvious redundancy.
The issue/verify/budget/kill/certify lifecycle is mostly covered, but the kill description explicitly notes that reversal requires an operator-side 'reinstate' that has no MCP counterpart, and there is no tool to list or enumerate existing agents, mandates, or tokens. These are notable gaps an agent cannot work around from the tool surface alone.