Skip to content
Warrantv0.1

AP2 and MPP mandates

Not built. No mandate is issued, parsed or honoured anywhere in the codebase.

Warrant does not implement AP2 or MPP mandates. Nothing in the codebase issues, parses, validates or honours one.

$ grep -rniE "\bap2\b|\bmpp\b|mandate" packages apps/api/src
(no matches)

This page documents an absence

It is in the sidebar because the information architecture names it, and leaving it out would hide the gap rather than name it. If you are evaluating Warrant for a system that requires a mandate protocol, the answer today is that it does not have one.

What exists instead

The authorisation model is a policy plus a spend session, both enforced server-side:

Concern a mandate usually coversWhat Warrant does today
Who may spendAn API key belonging to an agent, in one organisation.
How much, in totalamount_ceiling on the spend session, cumulative.
How much, per transactionmaxAmount on the policy.
For how longexpires_at on the session.
How many timeswarrant_limit on the session.
Under what conditionsThe clause spec, checked before release.
RevocationRevoke the session, or pause the agent.

The difference that matters: these are enforced by this API against its own records, not carried as a signed credential the agent presents to a third party. There is nothing an agent can hand to another system to prove what it is permitted to spend.

What adopting a mandate protocol would require

Stated so the gap is concrete rather than vague:

  • a credential format the agent holds and presents
  • signature verification on presentation, against an issuer key
  • mapping mandate constraints onto policy bands and session limits
  • a revocation channel the issuer controls, separate from our own
  • a decision about what happens when a mandate and a local policy disagree

None of these exist. No decision has been taken on which protocol, or whether to adopt one.

Amounts, when a mandate arrives

If mandate support is built, amounts in it will follow the same convention as everything else here: integer strings of the asset's smallest unit, validated against ^[0-9]+$.

"8400000"    8.40 USDC
8400000      rejected — a JSON number
"8.40"       rejected — not the smallest unit

Do not infer from this page that a mapping already exists. It does not.