{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_xjs6nbmy34ra","handle":"mandate-credential-broker","url":"https://wellknown.network/agents/mandate-credential-broker","links":{"self":"https://wellknown.network/agents/mandate-credential-broker/record.json","html":"https://wellknown.network/agents/mandate-credential-broker","markdown":"https://wellknown.network/agents/mandate-credential-broker/record.md","api":"https://wellknown.network/api/v1/agents/mandate-credential-broker","status":"https://wellknown.network/api/v1/agents/mandate-credential-broker/status","claim":"https://wellknown.network/agents/mandate-credential-broker/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/mandate-credential-broker/claim.json","badge":"https://wellknown.network/agents/mandate-credential-broker/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air:mandate.nanocorp.app:server:mandate-credential-broker","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"MANDATE Credential Broker","summary":"MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.","description":"MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.","publisher":{"name":"projetnanocorp","url":null},"homepage":"https://mandate.nanocorp.app/.well-known/mandate","repository":"https://github.com/projetnanocorp/mandate","version":"0.1.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://mandate.nanocorp.app/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-09-05T10:24:04.428373Z","publishedAt":"2026-09-05T10:24:04.428373Z","registryName":"io.github.projetnanocorp/mandate"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"security.secrets","name":"Secrets Management","confidence":0.992,"provenance":"derived"},{"slug":"dev.docs-lookup","name":"Documentation Lookup","confidence":0.54,"provenance":"derived"}],"categories":["dev","security"]},"observed":{"status":"live","statusReason":"Responded 1h ago.","lastOkAt":"2026-09-08T11:23:47.740Z","lastProbedAt":"2026-09-08T11:23:47.740Z","statusComputedAt":"2026-09-08T11:44:06.280Z","reliability30d":{"probes":6,"successRate":1,"p50Ms":205},"latestObservations":[{"at":"2026-09-08T11:23:47.740Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":228,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-08T05:23:05.203Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":182,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T23:25:27.465Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":230,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T16:26:13.609Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":287,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T09:28:57.787Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":163,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-07T02:24:08.943Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":179,"error":null,"detail":{"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"toolCount":11,"serverName":"MANDATE","capabilities":["tools"],"serverVersion":"0.1.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"mandate.discover","description":"Returns this self-describing tool manifest."},{"name":"mandate.mint","description":"Creates an active human-granted mandate for an agent and records it to the hash-chained ledger."},{"name":"mandate.delegate","description":"Creates a child mandate only when it is a no-escalation subset of the parent mandate."},{"name":"mandate.authorize-action","description":"Submits an action through the Gateway and canonical Policy Engine; returns ALLOW, DENY, or REQUIRE_APPROVAL with ledger proof."},{"name":"mandate.verify-proof","description":"Records a proof payload hash and appends proof evidence to the hash-chained ledger."},{"name":"mandate.revoke","description":"Revokes a mandate subtree and records the revocation to the hash-chained ledger."},{"name":"broker.register-credential","description":"Registers an opaque vault handle/reference only; plaintext secret fields are rejected and never ledgered."},{"name":"broker.request-access","description":"Asks the canonical Policy Engine for an ALLOW decision before issuing a short-lived HMAC-sealed grant bound to credential, mandate, agent, scope, and expiry."},{"name":"broker.use","description":"Redeems a sealed grant for the bound acting agent and executes the bound action through the Gateway and Policy Engine; does not expose plaintext secrets."},{"name":"broker.revoke-grant","description":"Revokes a broker grant by id and records the revocation to the ledger."},{"name":"broker.introspect-grant","description":"Validates a grant token seal, reports active/revoked/expired state, and records introspection to the ledger."}],"package":null},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"io.github.projetnanocorp/mandate","url":"https://registry.modelcontextprotocol.io/v0/servers/io.github.projetnanocorp%2Fmandate","firstSeenAt":"2026-09-07T01:22:51.110Z","fetchedAt":"2026-09-07T01:22:51.110Z","normalizedAt":"2026-09-07T01:22:51.110Z"}]},"firstSeenAt":"2026-09-07T01:22:51.110Z","updatedAt":"2026-09-08T11:44:37.514Z"}