Mandate (agent authorization)
A signed record of what a principal authorized an agent to do, with limits, checked before acting. AP2 v0.2 defines Checkout and Payment Mandates.
A mandate is a signed statement of what a principal has authorized an agent to do on its behalf, including the limits of that authority, which a counterparty verifies before it acts.
The general idea. An agent that says “my user approved this” gives a business nothing to check. A mandate turns the claim into evidence: it describes the permitted action and its limits, carries a signature that traces back to the principal’s approval, and binds the authority to the agent that will use it. The verifier checks the mandate against the request in front of it and refuses anything outside it.
AP2 v0.2. The Agent Payments Protocol splits agent authorization into two steps. In mandate delegation, the user approves mandate content on a trusted surface and the resulting mandate goes to the agent. In action authorization, a verifier asks the agent for a relevant mandate and returns a receipt. Version 0.2, released on 28 April 2026, defines two mandate types, each secured as an SD-JWT:
| Mandate | Proves | Verified by |
|---|---|---|
| Checkout Mandate | The agent may buy this specific checkout; bound by hash to a merchant-signed checkout JWT | Merchant |
| Payment Mandate | The agent may pay for that checkout | Credential provider, network, merchant payment processor |
When the user is present, they approve the closed checkout directly. When they are not, they approve open mandates with constraints, such as a price limit. Open mandates must carry the agent’s public key in a cnf claim, and the specification recommends the shortest expiry that lets the agent finish. The agent then signs closed mandates that must satisfy those constraints. AP2’s 2025 launch materials described Intent and Cart Mandates; the v0.2 specification replaces them with Checkout and Payment Mandates.
Beyond payments. A2A signals that authorization is needed with TASK_STATE_AUTH_REQUIRED and states that it does not define the scope, representation, validity or revocation of the resulting credential. Emissar’s Mandate module is a proposal for a general, scoped and revocable mandate carried as an A2A extension. Status: Spec in progress.
Neighbouring terms. Delegation is the act a mandate records. A scoped credential is the wider family of limited-authority credentials that mandates belong to.