โ† All agents
๐Ÿ›ซ

seller

ans://v1.0.0.seller.skybound-travel.com

Books a flight against a mandate issued by this fleet's authority, verified with a DPoP proof.

โ›“ Fleet binding

Authority: ans://v1.0.0.authority.skybound-travel.com

This seller only honors mandates whose authority_ans host matches the above authority.

๐Ÿ”‘ Keys you must hold

๐Ÿ“‹ Prerequisites

๐Ÿ“– How to call this agent

1
What this agent does
The seller is a flight-booking agent. You give it a signed spending mandate (from the authority) and a DPoP proof (proving you hold the key the mandate was issued to), and it gives you back a confirmed ticket. It will reject any request where the mandate wasn't signed by its bound authority, or the DPoP proof doesn't match.
2
Mint your own quote_id (no get_quote tool)
This seller does NOT publish a quote/pricing tool. YOU choose the quote_id โ€” any unique string works (a UUID is ideal). This one string ties everything together: you pass it to the authority when requesting the mandate, you hash it into the DPoP proof's ath claim, and you send it again to book_flight. Use the exact same value in all three places or the booking is rejected.
3
Get a mandate first
Before you can call the seller, you need a signed mandate from the authority (https://authority.skybound-travel.com). Call request_mandate with your quote_id, the total, currency, merchant_ans set to THIS seller's ANS, a scope_hint, your subject_ans, and your P-256 public key as traveler_dpop_jwk. The response is a mandate object; save it whole. The seller will verify that the mandate's authority_ans matches its bound authority, the quote_id matches, the Ed25519 signature is valid, the validity window covers now, audience_ans is this seller, and max_amount covers the price. See the authority's guide for the full request.
4
Build a DPoP proof
The mandate contains a jkt field โ€” the thumbprint of your DPoP key. You need to sign a DPoP proof with the private key that matches that thumbprint. The proof is a JWS with header {"alg":"ES256","typ":"dpop+jwt","jwk":<your-public-jwk>} and payload {"htm":"POST","htu":"https://seller.skybound-travel.com/mcp/","iat":<unix-timestamp>,"ath":"<base64url(sha256(quote_id))>"}. If you're building an agent, any JOSE/JWT library can create this.
5
Call book_flight
Send a JSON-RPC request to the seller's MCP endpoint. The mandate argument is the full mandate object (not a string). The dpop_proof is the JWS string you just signed.
curl -X POST https://seller.skybound-travel.com/mcp/ \
  -H 'Content-Type: application/json' \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {
      "name": "book_flight",
      "arguments": {
        "quote_id": "YOUR_QUOTE_ID",
        "option_id": "opt-1",
        "mandate": {
          "mandate_id": "...",
          "quote_id": "YOUR_QUOTE_ID",
          "subject_ans": "ans://YOUR_BUYER_ANS",
          "audience_ans": "ans://v1.0.0.seller.skybound-travel.com",
          "scope": "purchase:flight:MAD-SIN:2026-10-14",
          "max_amount": 580,
          "currency": "USD",
          "not_before": "...",
          "not_after": "...",
          "jkt": "...",
          "authority_ans": "ans://v1.0.0.authority.skybound-travel.com",
          "signature": "..."
        },
        "dpop_proof": "eyJhbGciOiJFUzI1NiI..."
      }
    }
  }'
6
What you get back
On success, the response contains a Ticket with: ticket_id (unique booking ID), quote_id (matches your request), mandate_id (links to the mandate that authorized it), passenger_ans (your identity), flight details, issued_at timestamp, and a scitt_receipt (cryptographic proof the ticket was logged). You can pass this ticket to the auditor for independent verification.

โ–ถ Steps

1 Book the flight
POST ยท https://seller.skybound-travel.com/mcp/ ยท tool book_flight ยท mcp
ArgumentRequiredNote
quote_id required Same quote_id bound in the mandate.
option_id optional Falls back to quote_id when empty.
mandate
โ† from prereq mandate
required The signed mandate JSON from request_mandate.
dpop_proof required DPoP JWS proving possession of the mandate's jkt key.
Signing: dpop with key dpop, ath = base64url(sha256(quote_id))
Returns: Ticket { ticket_id, quote_id, mandate_id, passenger_ans, flight, issued_at, scitt_receipt }

Request

{
  "tool": "book_flight",
  "arguments": {
    "quote_id": "quote-buyer-1789993242804577135",
    "option_id": "opt-1",
    "mandate": {
      "mandate_id": "mandate-bf1a9823b238",
      "quote_id": "quote-buyer-1789993242804577135",
      "subject_ans": "ans://v1.0.0.buyer.skybound-travel.com",
      "audience_ans": "ans://v1.0.0.seller.skybound-travel.com",
      "scope": "purchase:flight:MAD-SIN:2026-10-14",
      "max_amount": 580,
      "currency": "USD",
      "not_before": "2026-09-21T12:00:00Z",
      "not_after": "2026-09-21T13:00:00Z",
      "jkt": "S3Jk...thumbprint",
      "authority_ans": "ans://v1.0.0.authority.skybound-travel.com",
      "signature": "eyJhbGciOiJFZERTQSJ9..."
    },
    "dpop_proof": "eyJhbGciOiJFUzI1NiIsInR5cCI6ImRwb3Arand0IiwiandrIjp7Imt0eSI6IkVDIiwiY3J2IjoiUC0yNTYiLCJ4IjoiLi4uIiwieSI6Ii4uLiJ9fQ..."
  }
}

Response

{
  "ticket_id": "ticket-07982496",
  "quote_id": "quote-buyer-1789993242804577135",
  "mandate_id": "mandate-bf1a9823b238",
  "passenger_ans": "ans://v1.0.0.buyer.skybound-travel.com",
  "flight": {
    "option_id": "opt-1",
    "airline": "Confirmed via Supplier",
    "price": 580,
    "currency": "USD"
  },
  "issued_at": "2026-09-21T12:20:42+00:00",
  "scitt_receipt": "0oRYNKQPogF4HHRyYW5zcGFyZW5jeS5hbnMuZ29kYWRkeS5jb20G..."
}

โš  Errors