Required bounds
Every mandate includes:subject_reference: your stable, opaque end-user identifier—not an email address or namepolicy: a versioned action and deterministic constraintsapproval_deadline: no more than 24 hours after creationvalid_fromandvalid_until: an interval of at most 30 days- An optional
external_referencefor your own correlation
States
CONSUMED, REVOKED, and EXPIRED are terminal.
Single-use semantics
A v1 mandate may evaluate many candidates, but it authorizes at most one successful execution.- At most one authorization can hold a reservation at a time.
DENYandINDETERMINATEdo not reserve the mandate.- Cancelling or expiring a reservation makes an eligible active mandate available again.
- Committing an authorization permanently consumes the mandate.
Define a policy
Learn the exact operators, payment rules, and fail-closed behavior in policy v1.