---
title: "codespar mandate"
description: "Create and manage consumer mandates (the agent's allowance / wallet)"
---

Create and manage consumer mandates (the agent's allowance / wallet)

3 commands in `@codespar/cli 0.16.0`.

Each one prints what its operation answered. [What a command prints](/docs/cli/reference#what-a-command-prints) has the rule, and [Configuration](/docs/cli/config#what-a-script-gets-when-a-command-fails) has the exit codes and the shape of a failure.

### `codespar mandate create`

Create a consumer mandate via the directed-pay consent flow

```bash
codespar mandate create [options]
```

| option | what it does |
|---|---|
| `-c, --consumer <id>` | Consumer id (its derived wallet funds usdc-onchain spends) |
| `--agent <id>` | Agent id the mandate authorizes |
| `--purpose <text>` | Human purpose, signed into the mandate |
| `-p, --payee <list>` | Allowlisted payee(s): x402 URL / EVM address / Pix key (comma-separated) |
| `--cap <minor>` | Total cap in minor units (legacy single-currency; omit when using --slot) |
| `--per-tx-cap <minor>` | Per-transaction cap in minor units (legacy single-currency; omit when using --slot) |
| `--slot <spec>` | Wallet slot CURRENCY:RAIL:CAP:PER_TX_CAP (repeatable) — builds a multi-currency mandate, caps per-currency (no FX) (default: []) |
| `--currency <code>` | Mandate currency for the legacy single-currency path (default: "USDC") |
| `--rail <rail>` | Funding rail (usdc-onchain, pix-consent, card-token, ...) (default: "usdc-onchain") |
| `--ttl <seconds>` | Mandate lifetime in seconds (default: "86400") |
| `--pin-kind <kind>` | Allowlist entry kind: merchant-id, pix-key, mcc (default: "merchant-id") |
| `--provider-token <token>` | Rail provider token (defaults to a placeholder for usdc-onchain) |

### `codespar mandate verify`

Verify a V3 mandate presentation token offline (agent + issuer Ed25519 signatures)

```bash
codespar mandate verify [options] <token>
```

| option | what it does |
|---|---|
| `--agent-pubkey <hex>` | Raw 32-byte Ed25519 agent public key (hex). Forces pure-offline verification (no network). |
| `--issuer-pubkey <hex>` | Raw 32-byte Ed25519 issuer public key (hex). Forces pure-offline verification (no network). |
| `--issuer-did <did>` | Issuer DID for network mode (default: did:web derived from the agent DID host) |
| `--resolver <url>` | Network mode: resolver consulted for any DID whose did:web document is unreachable. Without it, only DIDs under the deployment's identity hosts fall back to the API. |
| `--did-domain <host>` | Identity host the API's DID route may answer for (repeatable; adds to config didDomains / CODESPAR_DID_DOMAINS). Built in: the API host, plus id.codespar.dev for the default API. (default: []) |

### `codespar mandate revoke`

Revoke a consumer mandate (POST /v1/mandates/\{id\}/revoke); active or paused → revoked, terminal

```bash
codespar mandate revoke [options] <id>
```

| option | what it does |
|---|---|
| `--reason <text>` | Recorded in the mandate's evidence row (max 280 chars); not echoed back |
