AP2 and MPP mandates
Not built. No mandate is issued, parsed or honoured anywhere in the codebase.
Warrant does not implement AP2 or MPP mandates. Nothing in the codebase issues, parses, validates or honours one.
$ grep -rniE "\bap2\b|\bmpp\b|mandate" packages apps/api/src
(no matches)This page documents an absence
It is in the sidebar because the information architecture names it, and leaving it out would hide the gap rather than name it. If you are evaluating Warrant for a system that requires a mandate protocol, the answer today is that it does not have one.
What exists instead
The authorisation model is a policy plus a spend session, both enforced server-side:
| Concern a mandate usually covers | What Warrant does today |
|---|---|
| Who may spend | An API key belonging to an agent, in one organisation. |
| How much, in total | amount_ceiling on the spend session, cumulative. |
| How much, per transaction | maxAmount on the policy. |
| For how long | expires_at on the session. |
| How many times | warrant_limit on the session. |
| Under what conditions | The clause spec, checked before release. |
| Revocation | Revoke the session, or pause the agent. |
The difference that matters: these are enforced by this API against its own records, not carried as a signed credential the agent presents to a third party. There is nothing an agent can hand to another system to prove what it is permitted to spend.
What adopting a mandate protocol would require
Stated so the gap is concrete rather than vague:
- a credential format the agent holds and presents
- signature verification on presentation, against an issuer key
- mapping mandate constraints onto policy bands and session limits
- a revocation channel the issuer controls, separate from our own
- a decision about what happens when a mandate and a local policy disagree
None of these exist. No decision has been taken on which protocol, or whether to adopt one.
Amounts, when a mandate arrives
If mandate support is built, amounts in it will follow the same convention as
everything else here: integer strings of the asset's smallest unit, validated
against ^[0-9]+$.
"8400000" 8.40 USDC
8400000 rejected — a JSON number
"8.40" rejected — not the smallest unitDo not infer from this page that a mapping already exists. It does not.