{"name":"io.github.projetnanocorp/mandate","slug":"projetnanocorp-mandate","title":"MANDATE Credential Broker","description":"MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.","url":"https://mcp.market/server/projetnanocorp-mandate","rating":null,"grade":"B","score":80,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":23,"stars":0,"forks":0,"downloads_week":null,"last_push_at":"2026-09-05T10:22:13.000Z","license":null},"uptime":{"percent":100,"checks":6,"ok":6,"last_checked_at":"2026-09-20T23:25:45.933Z","last_ok_at":"2026-09-20T23:25:45.933Z","latency_ms":699},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":"https://github.com/projetnanocorp/mandate","website":"https://mandate.nanocorp.app/.well-known/mandate","version":"0.1.0","remotes":[{"type":"streamable-http","url":"https://mandate.nanocorp.app/mcp"}],"packages":[],"tools":[{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["grant_token"]}},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"vault_handle":{"type":"string","description":"Opaque vault reference such as vault://provider/path; never a plaintext secret."},"metadata":{"type":"object"}},"required":["organization_id","registered_by_agent_id","label","credential_type","vault_handle","allowed_action_type"]}},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["credential_id","acting_agent_id","mandate_id","action"]}},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["revoked_by_agent_id","reason"]}},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["grant_token","acting_agent_id"]}},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof.","write_action":true,"price_micros":0,"input_schema":{"type":"object","required":["acting_agent_id","action_type","amount_minor","counterparty"]}},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate.","write_action":true,"price_micros":0,"input_schema":{"type":"object","required":["parent_mandate_id","delegator_agent_id","delegate_agent_id","budget_total","per_action_limit","starts_at","expires_at","scopes"]}},{"name":"mandate.discover","description":"Returns this self-describing tool manifest.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger.","write_action":true,"price_micros":0,"input_schema":{"type":"object","required":["organization_id","agent_id","grantor_principal_id","budget_currency","budget_total","per_action_limit","expires_at","scopes"]}},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["revoked_by_principal_id","reason"]}},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger.","write_action":false,"price_micros":0,"input_schema":{"type":"object","required":["organization_id","subject_type","subject_id","proof_type","payload"]}}],"scan":{"score":80,"grade":"B","scanned_at":"2026-09-20T11:38:33.911Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T11:38:33.814Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 1291ms"]},"poisoning":{"score":15,"max":15,"notes":["11 tool descriptions checked"]},"auth":{"score":3,"max":15,"notes":["open endpoint exposes 3 write-action tools with no auth"]},"maintenance":{"score":15,"max":15,"notes":["last push 15 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"auth.open-write","severity":"high","component":"auth","title":"Write-action tools reachable without authentication"}],"inputs":{"probes":[{"url":"https://mandate.nanocorp.app/mcp","reachable":true,"authRequired":false,"latencyMs":1291,"serverInfo":{"name":"MANDATE","version":"0.1.0"}}],"packages":[],"repo":{"found":true,"owner":"projetnanocorp","repo":"mandate","archived":false,"pushedAt":"2026-09-05T10:22:13Z","stars":0,"forks":0,"openIssues":0,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/322429220?v=4","ownerCreatedAt":"2026-08-29T09:05:58Z"},"icon":{"url":"https://mandate.nanocorp.app/favicon.ico?favicon.3fpu2ql9ns1a0.ico","source":"site","width":256,"height":256},"presence":{"stars":0,"forks":0,"downloadsWeek":null,"license":null,"lastPushAt":"2026-09-05T10:22:13.000Z","score":23}}}},"grade_history":[],"reviews":[]}