Non-custodial execution layer
Sign the intent. Mandate executes it.
You authorize a decision inside boundaries you set. Mandate simulates it, verifies every constraint, routes around MEV, settles on-chain, and proves the receipt — while your keys never leave your wallet.
Any AI agent can propose. Only Mandate can safely execute.
Every wallet will ship an agent that can plan a trade within the year. Almost none of them can be trusted to move capital — because planning is cheap, and execution, simulated and constrained and protected and proven, is the hard, valuable, defensible part.
Mandate is not the agent that decides. It's the layer between a plan and the chain: the boundary an agent can propose into but never step outside of, because it moves real money under real constraints.
One request. Nine enforced checkpoints.
However the plan is proposed — by you or by an agent acting for you — it flows through the same path the object above just walked. Nothing skips a checkpoint; a failed constraint stops it before it ever touches the chain.
Describeplain language
You say what you want — "rebalance my portfolio to 40/30/30" — no forms, no code.
natural languageInterpretAI agent
An agent — Mandate's or your own — parses the request into a structured plan: target allocation, constraints, urgency. This step is a commodity; any agent can do it.
agent-agnosticValidatepolicy engine
Before anything is costed, the plan is checked against your mandate — slippage caps, venue allowlists, position limits, exposure. Anything outside the boundary is rejected here, not after.
deterministic · pass/failRoutesolver
A solver searches every path that satisfies your boundaries and picks the optimal one — best price, lowest impact, cheapest gas.
solver · optimal pathSimulateforked state
The chosen route is replayed against forked mainnet state. Outcomes, fees, and price impact are proven before a single wei moves.
~1,200 paths · 240msSignyour review
You see the exact proven outcome, not a promise, and sign a scoped authorization. Nothing executes without this — the agent can propose, only you can authorize.
EIP-712 · off-chainRelayMEV-protected
The signed order is submitted through private orderflow, so it can't be sandwiched or front-run.
private relay · no mempoolSettleon-chain
Mandate enforces exactly the signed authorization — nothing more. The bundle lands atomically; partial fills are impossible.
atomic bundle · 1 blockReceiptproven
The realized outcome is checked against the simulation and signed into a receipt you can verify independently. Proof, not a promise.
signed · verifiableCompose an intent. Watch it execute.
Set a target, define your boundaries, and run it. An agent drafts the plan, Mandate validates, routes, simulates, and — only once you sign — settles and returns a signed receipt. The same nine checkpoints, on demand.
Intent builder
Mandate never holds your keys. It only acts inside your boundaries.
Custody is not a policy you trust us to keep — it is a property of how the system is built. You sign an authorization scoped to a set of rules. Mandate can execute exactly that and nothing else.
Revoke any mandate on-chain at any time. No withdrawal, no cooperation, no waiting required.
Active mandate · #M-4471
Rebalance — ETH / BTC / USDC
You decide. You authorize. Mandate executes.
Access is opening to funds, market makers, treasuries, and protocol teams first. Tell us what you run — we'll route you in.