BUILD WITH MANDATE

Verify

Start with one action.

Add MANDATE Verify yourself, or give your coding agent a focused integration task.

Managed SDK preview · Use the matching package-manager command from your dashboard. The new packages are not yet published on npm; native workflows currently run in Observe mode.

FOR DEVELOPERS

Developer quickstart

Install once, connect your app, and manage its policies in Studio.

  1. Install with your package manager.

    Open your app’s Setup page in the dashboard. Choose npm, Bun, or pnpm and run its install command from your repository. It installs the CLI, Node SDK, and Next.js collector directly. No ZIP extraction or SDK directory paths are needed.

    The current preview installs matching package files directly through your package manager. The published npm 0.3.0 SDK is a legacy release and does not provide managed setup.

  2. Connect your app.

    Run the login command shown in the dashboard. Select your app in the browser and approve the connection. The CLI presets server-only configuration in your ignored .env.local.

    npx --no-install mandate login

    With Bun, use bun run mandate login. With pnpm, use pnpm exec mandate login. A preview or private deployment’s generated command also selects its dashboard. The approval screen explains the organization-wide verification-key scope. Keep generated values out of Git and add them to your host’s secret settings when deploying.

  3. Connect a browser action.

    Discover supported Next.js App Router handlers, then preview integration for your chosen route:

    npx --no-install mandate setup --managed
    npx --no-install mandate setup --managed --route /api/signup --method POST

    Review the plan and repeat the second command with --write. Setup reuses your installed packages and adds browser collection and a managed server guard. It preserves existing authentication and business logic. The handler uses:

    import { withMandateManaged } from "@mandate-security/node/next";
    
    export const runtime = "nodejs";
    export const POST = withMandateManaged(signupHandler);

    signupHandler is your existing handler. The SDK reads the saved connection automatically. You do not configure gate URLs, cookie names, or verification strength in this wrapper.

  4. Configure Policy Studio.

    Register the desired routes and methods, configure the workflow, and activate an Observe release before sending traffic through the managed guard. Future changes apply within installed handler coverage. Each new Next.js handler needs the guard too; Express can mount managed middleware over a browser API router.

    A draft is not active configuration. Missing, disabled, or invalid configuration returns 503; a valid unmatched route continues normally. Native workflows currently observe. Keep webhooks, machine APIs, OAuth callbacks, and the collector outside browser-only coverage.

  5. Check real activity.

    Restart your app and perform the action in a browser. Review browser activity and hosted verification separately in Activity for the intended app and route.

    npx --no-install mandate verify

    Received calls do not prove enforcement or business completion. Login configures your local project; deployment secrets and production verification remain separate steps.

Go, Python, and other frameworks

The managed SDK preview also includes Go ManagedMiddleware{}.Handler(handler), Flask require_mandate_managed(), and FastAPI ManagedMandateRoute. Use the matching SDK source candidate; these additions are not yet published to their registries. Browser collection and server middleware must be connected manually outside the supported Next.js installer.

Run the same installed mandate login command to connect. Next.js loads .env.local automatically. For Go and Python, load that explicit file into the process environment at startup using your application’s dotenv loader, or supply its values through your host’s secret settings. The SDK reads that environment; it never searches for credential files. Cookie transport and policy requirements come from MANDATE.

Managed source installation supports Next.js App Router layouts using npm, Bun, or pnpm. Server Actions, unsupported route structures, workspace layouts, and Yarn PnP require manual integration. Existing explicit hosted adapters remain supported.

Explore integration examples ↗

FOR CODING AGENTS

Agentic quickstart

Install the packages with the command from your dashboard, then give your coding agent this task. Complete browser login yourself.

Integrate MANDATE using the installed @mandate-security/cli and @mandate-security/node packages.

Read their README files. Inspect the framework and routes, then propose one browser-originated action to connect. I will complete mandate login myself. Do not read or print credentials or .env.local.

Use mandate setup --managed to discover supported handlers. Preview the selected handler with --route and --method; apply the reviewed plan with --write. Reuse installed dependencies and preserve existing authentication and business logic.

Confirm an Observe release is active for the selected routes in Policy Studio before exercising the app. Keep machine APIs, webhooks, OAuth callbacks, and the collector outside browser-only coverage.

Check browser and server activity for the selected app and route. Report changed files, actual checks, remaining gaps, and rollback steps. Do not claim enforcement from a successful login or recorded call.

Review source changes before deploying. Policy Studio configures policy within installed coverage; it cannot protect handlers the SDK never sees.