Skip to content

mandate_required

HTTP 403 · Ludion-Error: mandate_required

Your signature verified, but this route acts on someone’s behalf (a purchase, an account change, a booking) and asks for a Mandate: a signed, short-lived delegation from the person or company you act for (the Principal). Your request carried none that holds here.

A Mandate that is there counts as none when:

  • it is for another site, or for a category this site is not in;
  • it has expired;
  • the Principal has withdrawn it;
  • no Ludion-Staple came with it. Whom a Mandate delegates to is checked against the Diver your Staple names.

A Mandate says who you act for (as a pseudonym unique to each site), where, what you may do (read, account, post, reserve, checkout, delete), up to what limit, and until when. It contains no name, address or contact details.

Even a legitimate agent can be steered by a prompt injection. A Mandate lets the site check that this action is within what the Principal actually agreed to, before it happens.

  • Ask your Principal for a Mandate that covers this site and this action. In Ludion Protocol v0, the Principal consents with a passkey and the Registry issues the Mandate; your agent sends it in the Ludion-Mandate header, inside the signature.
  • Always send your Staple with a Mandate, with Ludion-Staple inside the same signature.
  • An expired or withdrawn Mandate stays unusable until your Principal consents again.
  • Mandate issuance is not open yet. Until it is, this route stays closed to agents without one.

Ludion does not replace Web Bot Auth: any agent that signs requests with Web Bot Auth (RFC 9421) and publishes its key directory is already VERIFIED by Ludion Gates, at depth 0. If you have not signed anything yet, the free Ludion CLI gets you there.

Three minutes is our target for this path, written down as the check DIV-1: in a clean container, from init to VERIFIED within 180 seconds.

  1. Create your agent identity (a Diver). The Root key is sealed with your passphrase and never signs a request; a short-lived Session key does.

    Terminal window
    npx ludion init --name "My Agent" --contact mailto:you@example.com
  2. Publish the public files it wrote at your Signature-Agent origin over HTTPS: .well-known/http-message-signatures-directory (your keys, served as application/http-message-signatures-directory+json) and card (who you are). Your own domain works; so will dvr-….agents.ludion.ai once registration opens.

  3. Sign each request. This prints a ready-to-run curl with the Signature-Agent, Signature-Input and Signature headers; a signature lives 60 seconds (spec §10.4), so make a new one per request.

    Terminal window
    npx ludion sign GET https://shop.example/checkout --curl
  4. Check yourself. doctor fetches your published directory and Card and checks what a Gate checks: a 200 without redirects, the content type, and your current key in the directory.

    Terminal window
    npx ludion doctor

A Gate now classifies your requests as VERIFIED. What a site additionally asks for (Depth, Ballast, a Mandate) is on top of that; each has its own page among the Gate errors.