A Stamped Mandate is Sumvin’s own object. It is not an AP2 mandate or a card-network mandate, and it doesn’t claim to work with them.
Three layers
A Sigil is identity. It never authorises anything on its own. A mandate is the authorisation. An errand is one kind of work that runs under a mandate: a purchase.
What a mandate says
Three properties hold for every mandate:
- Signed by you, on your own page. You read what the mandate says in plain words on a Sumvin page in your own browser, then approve it with your passkey or decline.
- Revocable. You can withdraw it at any time. Revocation is permanent.
- Checkable. Whoever your agent deals with can check what it permits and whether it still stands, without learning who you are. See What a verifier checks.
What mandates are for
The use cases below are examples, not a complete list. See Use cases for each one in detail.Share data
Share that you are verified, or share verified identity details, with a merchant or provider.
Open-banking data
Let an agent read your linked accounts and transactions through Meld.
Prove you are a person
Show a booking site that a verified person sent this agent.
Make purchases
Let an agent buy within a ceiling you set. Purchases run as errands.
How a mandate is made
- Your agent asks. It drafts the mandate and gives you a link to a Sumvin page.
- You read it. The page shows what you would be signing, in plain words, including any ceiling in your own money’s terms.
- You sign, or you don’t. Only you can approve it, with your passkey, in your own browser. An agent can ask for a mandate; it can’t approve one, for itself or any other agent.
The approval link is given to your agent once. If it is lost, your agent asks again rather than looking it up.
Two modes for purchases
Approve each purchase. This is the default. Your agent searches and prepares, then stops. Nothing is bought until you approve that purchase. Pre-authorised. You tell your agent it may complete a purchase without asking again, as long as it stays within your mandate and any conditions you set, such as a price. This is what makes repeat errands possible. Your agent only chooses it when you have clearly asked for it. Either way, the mandate is the outer limit. A pre-authorised errand can’t spend past its ceiling or its expiry.Revoking
You can revoke a Stamped Mandate at any time. A revoked mandate never becomes active again. Anything relying on it stops, including errands that were using it and any smaller mandate drawn from it. To give the authority back, sign a new mandate. Disconnecting an agent is separate from revoking the mandates it asked for. A disconnected agent can’t act for you, but the mandates it asked for stay valid until they expire or you revoke them. Revoke them separately. See Revoke a mandate or disconnect an agent.Next
The mandate language
How scopes, resources and limits fit together.
Stamp your first mandate
Ask, read, sign.
Set limits
Amount, merchant, expiry.
Check a mandate
For anyone an agent presents one to.