Mandact — The Trust Layer of the Agent Economy

Developers · changelog

Versions, honestly dated

OMP v0.5.2 · platform sprints 12–14

June 2026
  • All 19 denial codes implemented — new: MD-103 (unsupported_vct), MD-305 (frequency_limit), MD-306 (geo + time_window), MD-503 (minVerificationLevel).
  • API keys (mk_test_/mk_live_) mandatory on every verifier endpoint; the sandbox stays keyless.
  • Rate limits per key with X-RateLimit headers; 429 with a reset time.
  • Evidence export: integrity root, signed receipt, 24 h download, timestamp path.
  • OAuth/RAR bridge: mandate-bound access tokens (RFC 9396) + live introspection (RFC 7662) — revocation voids tokens immediately.
  • Correction: escalation is checked BEFORE the limit reservation; step-up approvals are single-use.

Platform sprints 7–11

June 2026
  • Supabase schema (006) with the evidence chain guard: append-only by trigger, 16 database validations.
  • Auth: magic link, Google OAuth, enterprise SSO, TOTP 2FA with an AAL2 gate.
  • Account lifecycle: GDPR export (Art. 20), deletion with anonymisation (the evidence chain remains).
  • Automation: daily expiry sweep, mandate.expiring, limit.threshold at 80%.
  • MCP server with 5 tools — the full lifecycle verified over stdio.

OMP v0.5 · platform sprints 1–6

June 2026
  • Verify engine with a deterministic check order, atomic limit reservation, timing-safe signatures.
  • Issuance wizard (6 steps), kill switch, escalation flow end to end (600 s), four-eyes signing by database trigger.
  • Evidence log (hash chain), webhooks (HMAC, retries, DLQ), verifier workspace with a rule editor.
  • SEO foundation: action, glossary, and comparison clusters, llms.txt.

Developer overview · Deutsche Fassung dieser Seite