Getting started
Demo data
Loads a complete fictitious client in seconds: 3 assets, 2 verified principals, 3 agents (two with live sandbox endpoints), 4 mandates, a month of operations decided by the real engine, pending approvals, alerts and paid attestations. Ideal to demo the product or test an integration. It never deletes what you already have; loading it twice does not duplicate the activity.
Step by step
- Sign inThe first administrator opens the invitation link Mandatary.ai sent and creates a passkey. From then on, one button.
Which buttons, in which order
- Click the blue button "Sign in with a passkey" and follow your device: fingerprint, face or PIN. There is nothing to type.
- First time? Open the invitation link your administrator sent you: it creates your passkey and signs you in.
- For the local demo, or for a system: click "Use an API key instead" and paste the key (dev-key-demo-0000). Click "Sign in with the key".
- No data yet? On "Getting started", card "Demo data", click "Load demo data": a complete fictitious client (assets, principals, agents, mandates, a month of operations, alerts) appears in seconds.
- Your account & devicesAdd a second device (your phone) right away, so that losing one does not lock you out.
Which buttons, in which order
- Card "Devices I can sign in with": click "Add a device". To add your phone from a computer, choose "another device" when the browser asks where to save the passkey, and scan the QR code with the phone.
- Give each device a name you will recognise ("My phone", "Office laptop").
- "Remove" takes a device off the list; your only device cannot be removed.
- Lost every device? Ask your administrator for a new invitation link.
- Members & rolesInvite each colleague by name and e-mail and give them a role: compliance officer, agent operator, auditor or administrator. The "i" next to "Role" says what each role can and cannot do.
Which buttons, in which order
- Tab "Members", card "Invite a member": write the "Full name" and the "Work e-mail", and choose the "Role". Point at the small "i" next to "Role" (or read the box below the list) to see what that role can and cannot do. For an auditor, set "Access expires on". Click "Create invitation link".
- Copy the link from the green box now ("Copy link"): it is shown only once. Send it to the person over a channel you trust. They open it, create their passkey and are in.
- Card "Members" (below): each person with role, status and devices. "Edit" changes name, e-mail or role (the new role applies at once). "Suspend" stops them immediately; "Reactivate" brings them back. "New link" is for somebody who lost every device. "Remove" erases their name, e-mail and devices and keeps their history. "Activity" shows what they changed.
- Tab "API keys": card "Create a key" issues a key for a system (or a read-only, scoped, expiring key for an auditor's tool); copy it from the green box, it is displayed only once. "Revoke" disables a key immediately.
- API keys for your systemsCreate the key your platform's backend uses to ask the engine before each operation. Keys are for systems; people sign in with a passkey.
Which buttons, in which order
- Open "Members & API keys" and click the tab "API keys".
- Card "Create a key": in "Type" choose the role the system needs (Administrator for a backend that calls /verify and manages mandates; Auditor for a read-only tool, with scope and expiry). In "Who is it for" write the name of the system, never a personal name. Click "Create key".
- Copy the key from the green box now: it is displayed only once. Store it in your secrets manager and configure it in the SDK or in the "x-api-key" header.
- Card "Keys" (below): "Revoke" disables a key immediately; create a new one first if the system is in use.
- AssetsName the tokens your agents will trade (address → symbol and name).
Which buttons, in which order
- Card "Add an asset" (left): paste the token contract address in "Token address". The issuer publishes this address (for example Dinari or Ondo list their tokens per network).
- Click "Look up on-chain" (gray button under the field). The console reads what the contract calls itself and fills "Symbol" and "Name" if they are empty. A yellow box means what you typed does not match the contract: double-check the address with the issuer.
- Choose "Kind" (stock, bond, fund…), optionally "Issuer" and "Reference" (ISIN or CUSIP), then click the blue button "Save asset".
- Card "Catalog" (bottom): every saved asset. Click "Edit" on a row to change it; the address never changes.
- PrincipalsRegister who grants the mandates: company with LEI, or individual; record the identity verification.
Which buttons, in which order
- Card "Register a principal" (top left): paste the signing wallet in "Signing wallet". Wallets that already granted mandates but have no record appear as gray buttons under the field: click one to fill it.
- Choose "Type": Company or Individual. For an individual write only a label in "Label" (for example "Client 1042"); personal data stays in your KYC provider.
- For a company, type its LEI in "LEI (Legal Entity Identifier)" and click "Look up in GLEIF". A green box shows the official legal name and status; "Legal name" and "Jurisdiction" fill in. The LEI is saved only if GLEIF confirms it.
- Click the blue button "Save principal".
- Card "Registered principals" (bottom left): click a row. The card "Verification of …" appears on the right: choose "Result" and "Level" (Basic, Professional, Institutional), the provider and the case reference, then click "Record verification result". Professional and Institutional require a validated LEI for companies. A verification expires after twelve months.
- AgentsGive each agent an identity: operator, services, liveness, operator verification, credential, on-chain registration.
Which buttons, in which order
- Tab "Directory", card "Register an agent" (top left): paste the agent wallet in "Agent wallet address" (the same address that appears in its mandates), fill "Agent name", "Operator", "What it does" and, if the operator has one, "Operator LEI".
- Under "Services", type the endpoint the agent exposes (public https only) and click the blue button "Save agent". Its ERC-8004 registration file is published immediately at the address shown in the green box.
- Card "Registered agents" (bottom): click the agent name in blue to open its detail page. There you check its endpoints, record the operator verification, issue the credential and register it on-chain.
- Tab "Fleet": choose the operator and the window in the two selectors above the table. The four cards are the totals: agents (verified, alive), active mandates (on-chain, valid credentials), verifications in the window (denied, attestations consumed) and open alerts.
- In the fleet table, green badges are healthy. "Adherence" is the share of operations that stayed inside the mandate: green from 90 %, yellow from 70 %, red below. Column "Alerts": click "N open" to go to Alerts and acknowledge them.
- Grant a mandateThe principal signs a limited power for the agent (template, limits, jurisdiction, legal document).
Which buttons, in which order
- Step "1. Who": click a template card (Basic, Professional, Institutional) to pre-fill sensible limits; choose the "Jurisdiction of the legal document"; enter the principal wallet, the agent wallet and the asset (pick it from "Pick a catalogued asset" if you registered it under Assets). "Use test values" fills a test agent and the demo token. Click "Continue" (bottom right).
- Step "2. What": tick the allowed actions (Buy, Sell, Transfer, Subscribe, Redeem). Click "Continue".
- Step "3. How much": per-operation cap, daily cap, total cap, optional human-approval threshold with its deadline, optional speed limit (operations per time window) and maximum risk score. Click "Continue".
- Step "4. When": validity in months and, optionally, the trading window (days and hours, UTC). Click "Continue".
- Step "5. Confirm": read the summary in plain words and the full "Legal document" below it. Then click "Sign with wallet and register on-chain" (MetaMask asks the principal for two signatures: the readable terms, then the technical message; no gas is charged to the principal) or "Register in engine only" (no wallet, no chain; for development).
- SimulatorTry operations against the mandate and read which rule decides, without recording anything.
Which buttons, in which order
- Card "Operation" (left): choose the mandate in "Mandate", the "Action", the "Amount (USD)" and, optionally, "Quantity" and "Unit price" (quantity × price must match the amount within 1%), the platform and the counterparty.
- Click the blue button "Simulate".
- Card "Engine answer" (right): the outcome (Allowed, Denied, Requires approval), the reason code, the rule that decided in code, and the explanation in plain words. Change one value and simulate again to see which rule reacts.
- Platform rulesSet your own limits on top of every mandate (optional).
Which buttons, in which order
- Card (left): fill the rules you need: "Per-transaction cap", "Human approval from", "Maximum agent risk score", tick "Only agents whose operator is verified" if you require verified operators, tick the actions your platform does not offer, paste an asset whitelist or blocked agents (one address per line).
- Click the blue button "Save rules". The green box shows the new version number; it applies to every verification from now on.
- Every decision records which version of your rules was in force, so the evidence explains it later. Denials show "platform.…" as the rule.
- WebhooksConnect your platform: it calls the API before each operation (SDK, with the system key from step 4) and receives signed events.
Which buttons, in which order
- Card "Register a webhook" (left): paste your https URL in "URL", tick the events you want (none ticked = all), optionally a description, and click "Register webhook".
- Copy the secret shown in the green box now: it is displayed only once. Your server uses it to verify the header x-mandatary-signature (the SDK has parseWebhook for this).
- Card "Webhooks" (bottom): click "Send test" on a row to deliver a test event, "Deliveries" to see attempts, responses and retries (1 min, 5 min, 30 min, 2 h, 12 h), "Deactivate" to stop it.
- Approval inboxDecide the operations above the human-approval threshold before their deadline.
Which buttons, in which order
- Each card shows the full context: agent, principal, asset, amount in USD, the threshold, the reference price and the time left. Read it before deciding.
- Click the green button "Approve" or the red button "Reject"; optionally write a note first in "Note". If a wallet is connected, the decision is signed by it and the signature is kept as evidence.
- If nobody decides before the deadline, the request expires and the operation is rejected by default. Resolved requests move to the "Resolved" list below.
- Operation verificationsRead every decision and the evidence fingerprint behind it.
Which buttons, in which order
- Table (left): one row per verification with date, outcome, operation (action, asset, quantity, price) and reason. Click a row.
- Card "Decision detail" (right): the rule that decided in plain words and in code, the operation, agent, platform, execution status reported by the platform, the evidence fingerprint and the on-chain anchor when the batch was published.
- Only platforms create rows here (through the API or SDK); the simulator does not.
- AlertsReview what the engine flagged and acknowledge it.
Which buttons, in which order
- The list shows open alerts first; the red number in the left menu is the count.
- Click "Acknowledge" on an alert once you reviewed it; it moves out of the open list and the evidence keeps who acknowledged and when.
- To receive alerts outside the console, register a webhook subscribed to the event "alert": left menu → "Webhooks".
- Evidence dossiersPackage a period for an auditor or regulator (signed JSON, CSV, PDF). To let an auditor look for themselves, invite them in "Members & roles" with the Auditor role: read-only, with an expiry.
Which buttons, in which order
- Card "Build a dossier" (left): set "From (UTC)" and "To (UTC)" (at most one year), optionally a principal or an agent, and click "Generate dossier".
- The dossier appears below with a summary, the mandates, the decisions and the approvals. It is signed by Mandatary.ai: anyone can verify the signature with the published key id (kid).
- Top right of the dossier: "Download JSON (signed)" for machines and auditors, "Download CSV" for spreadsheets, "Print / Save as PDF" for a paper copy.
- Principal reportThe statement each principal receives, in plain words and as a ledger.
Which buttons, in which order
- Card "Build a report" (left): choose the principal in "Principal" and the period (Last 7 / 30 / 90 days) and click the blue button "Build report".
- Read the box "In plain words" first, then the four cards, the "Mandate statement" (charges = purchases, credits = sales, running balance, opening and closing balance), the position by asset, the mandates with their usage bars, what the engine denied, alerts and expirations.
- Top right of the report: "Download JSON (signed)" or "Print / Save as PDF". The report is signed like the dossier.
- Attestations (x402)See the signed statements that counterparties can buy about your agents (identity, mandate, reputation).
Which buttons, in which order
- Card "Pricing" (top left): read what each attestation answers and what it costs. "Free (development)" means this API has no x402 facilitator configured; in production the counterparty pays cents in USDC per query and Mandatary.ai never holds the funds.
- Card "Ask about one of your agents" (top right): choose the agent in "Agent" and, for the mandate attestation, the principal in "Principal".
- Click the blue button "Ask: Identity", "Ask: Mandate", "Ask: Validation" or "Ask: Reputation". The console asks the public endpoint without your API key, exactly as a third party would.
- Card "… attestation: what the counterparty receives" (bottom left): the statement, line by line. The mandate attestation never shows amounts; the reputation one is a table of six dimensions (mandate adherence, availability, honesty, competence, solvency, disputes), each with its source and confidence, never a single score.
- Card "Signature check (done in your browser)" (bottom right): expect the green box "Valid". The hash is recomputed locally and the signature is checked against the published key, the same check the SDK does.
- Card "On-chain publications" (bottom): in production each attestation is also written to the ERC-8004 validation registry of the agent; here you see the queue and the transaction of each one.
- If the box "payment required (HTTP 402)" appears instead, the attestation is paid: it shows the amount, asset and account the asking agent must pay. The asking agent pays automatically through the Mandatary.ai SDK; this console only shows what it would receive.
Why people come first. Everything a person changes is recorded under their own name, and whoever asks for an approval cannot be the one who grants it. That only works if each person has their own access from day one, instead of a key passed from hand to hand.
The tags at the top of this page turn green as your organization completes each stage; the blue one is what to do next. The panel "How to use this page" on every screen reopens if you click it after closing it.