Skip to content

mandate_scope

HTTP 403 · Ludion-Error: mandate_scope

Your signature verified and you sent a Mandate, but the Mandate does not cover what this route does. The route asks for a scope (for example checkout), and your Mandate’s scope list does not include it.

For a payment, this is also the answer when it goes past the Mandate’s limits: the amount per checkout (checkout_max), the currency (currency), or the number of checkouts per day (per_day). The site counts the amount from its own cart, and the Gate holds it to the Mandate’s limits.

A Mandate is only useful if its limits hold. An agent allowed to browse is not allowed to pay; an agent allowed to book is not allowed to cancel an account. The site enforces the Principal’s own boundaries.

  • Ask your Principal for a Mandate whose scope includes this action. The scopes are read, account, post, reserve, checkout and delete.
  • If a payment needs a higher limit, ask your Principal for a new Mandate that carries it. Do not split a payment to pass under a limit: the checkouts per day are counted too.
  • Do not widen a Mandate on your own: it is signed, and any change breaks it.

Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.

Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.

  1. Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.

    Terminal window
    npx ludion init --name "My Agent" --contact mailto:you@example.com
  2. Publish the public files it wrote at your Signature-Agent origin over HTTPS: .well-known/http-message-signatures-directory (your keys, served as application/http-message-signatures-directory+json) and card (who you are). Your own domain works; so will dvr-….agents.ludion.ai once registration opens.

  3. Sign each request. This prints a ready-to-run curl with the Signature-Agent, Signature-Input and Signature headers; a signature lives 60 seconds (spec §10.4), so make a new one per request.

    Terminal window
    npx ludion sign GET https://shop.example/checkout --curl
  4. Check yourself. doctor fetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.

    Terminal window
    npx ludion doctor

A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.