โ† All agents
๐Ÿ›๏ธ

authority

ans://v1.0.0.authority.skybound-travel.com

Issues signed AP2 spending mandates after a max-per-trip policy check.

โ›“ Fleet binding

Authority: ans://v1.0.0.authority.skybound-travel.com

This is the fleet's mandate authority.

๐Ÿ”‘ Keys you must hold

๐Ÿ“– How to call this agent

1
What this agent does
The authority is the spending-approval agent. It issues signed mandates โ€” cryptographic permission slips that say "this buyer may spend up to $X with this seller." Without a mandate, no seller in this fleet will accept a booking. Anyone can request a mandate โ€” you don't need to be a registered agent. The only gate is a per-trip policy ceiling (currently $1000).
2
Generate a P-256 key pair
You need a P-256 (ECDSA) key pair. This is your DPoP key โ€” the mandate will be locked to it, and later the seller will require you to prove you hold it. You can generate one with openssl, any JWT library, or the Web Crypto API. Keep the private key; export the public key as a JWK (JSON Web Key with kty, crv, x, y fields).
# Generate a P-256 key pair with openssl:
openssl ecparam -genkey -name prime256v1 -noout -out dpop_key.pem
openssl ec -in dpop_key.pem -pubout -out dpop_pub.pem

# Or in Node.js:
# const { generateKeyPairSync } = require('crypto');
# const { privateKey, publicKey } = generateKeyPairSync('ec', { namedCurve: 'P-256' });

# Convert the public key to JWK format for the API call.
# You need: {"kty":"EC","crv":"P-256","x":"...","y":"..."}
3
Call request_mandate
Send a JSON-RPC request to the authority's MCP endpoint. You need: a unique quote_id (any string), the total amount and currency, the seller's ANS name (merchant_ans), a scope hint describing what you're buying, and your P-256 public key as a JWK. The authority will check the amount against its policy ceiling, then return a signed mandate.
curl -X POST https://authority.skybound-travel.com/mcp/ \
  -H 'Content-Type: application/json' \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "request_mandate",
      "arguments": {
        "quote_id": "my-quote-001",
        "total": 580,
        "currency": "USD",
        "merchant_ans": "ans://v1.0.0.seller.skybound-travel.com",
        "scope_hint": "purchase:flight:MAD-SIN:2026-10-14",
        "subject_ans": "ans://your-buyer-agent.example.com",
        "traveler_dpop_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}"
      }
    }
  }'
4
Understand the response
The response is a mandate object with these key fields: mandate_id (unique ID), quote_id (matches your request), subject_ans (your identity), audience_ans (the seller โ€” only this seller can accept the mandate), scope (what you're buying), max_amount and currency (the spending limit), jkt (the thumbprint of your DPoP key โ€” you'll prove you hold this key when you talk to the seller), authority_ans (who signed it), and signature (the Ed25519 signature). Save the entire mandate object โ€” you'll pass it verbatim to the seller.
5
Next: take the mandate to the seller
With the mandate in hand, you can now call the seller's book_flight tool. You'll also need to build a DPoP proof โ€” a JWS signed with the same P-256 key โ€” to prove you're the one the mandate was issued to. See the seller's guide for details.

โ–ถ Steps

1 Request a mandate
POST ยท https://authority.skybound-travel.com/mcp/ ยท tool request_mandate ยท mcp
ArgumentRequiredNote
quote_id required
total required Must be <= the authority's max_per_trip.
currency required
merchant_ans required The seller ANS; becomes the mandate audience_ans.
scope_hint required e.g. purchase:flight:...
traveler_dpop_jwk required Public JWK of your DPoP key; its thumbprint becomes the mandate jkt.
Signing: request_jws with key ans-identity โ€” bound fields: subject_ans quote_id total currency merchant_ans scope_hint traveler_dpop_jwk
Returns: Mandate { mandate_id, quote_id, subject_ans, audience_ans, scope, max_amount, currency, not_before, not_after, jkt, authority_ans, signature }

Request

{
  "tool": "request_mandate",
  "arguments": {
    "quote_id": "quote-buyer-1789993242804577135",
    "total": 580,
    "currency": "USD",
    "merchant_ans": "ans://v1.0.0.seller.skybound-travel.com",
    "scope_hint": "purchase:flight:MAD-SIN:2026-10-14",
    "subject_ans": "ans://v1.0.0.buyer.skybound-travel.com",
    "traveler_dpop_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}"
  }
}

Response

{
  "mandate_id": "mandate-bf1a9823b238",
  "quote_id": "quote-buyer-1789993242804577135",
  "subject_ans": "ans://v1.0.0.buyer.skybound-travel.com",
  "audience_ans": "ans://v1.0.0.seller.skybound-travel.com",
  "scope": "purchase:flight:MAD-SIN:2026-10-14",
  "max_amount": 580,
  "currency": "USD",
  "not_before": "2026-09-21T12:00:00Z",
  "not_after": "2026-09-21T13:00:00Z",
  "jkt": "S3Jk...thumbprint",
  "authority_ans": "ans://v1.0.0.authority.skybound-travel.com",
  "signature": "eyJhbGciOiJFZERTQSJ9..."
}

โš  Errors