Skip to main content

Overview

@grantex/adapters provides pre-built adapters for popular APIs — Google Calendar, Gmail, Stripe, and Slack. Each adapter verifies grant tokens offline (JWKS), checks scopes, enforces constraints, and calls the upstream API.
Node.js 22.12+ is required. Configure the expected resource audience and derive trusted amounts at your service boundary. Offline adapter checks do not prove current revocation; combine them with operational current-state enforcement. See migration.

Google Calendar

Scopes: calendar:read, calendar:write

Gmail

Scopes: email:read, email:send

Stripe

Scopes: payments:read, payments:initiate Supports constraint enforcement — payments:initiate:max_500 limits payments to $500.

Slack

Scopes: notifications:send, notifications:read

Constraint Enforcement

Scopes can include constraints that adapters enforce automatically:

Dynamic Credentials

Pass an async function instead of a static string:

Audit Logging

Connect adapters to Grantex audit:

Grant token audience

From version 0.2.0 (not in @grantex/adapters 0.1.5). This is a breaking change: a grant token that carries an aud claim is refused unless the adapter is configured with that audience. Tokens issued without an audience are unaffected.
Every adapter checks the token’s aud claim (RFC 7519 section 4.1.3) with the same semantics as enforce() in the SDKs, right after the signature and before the upstream call. aud may be a string or an array of strings and matches when the configured audience is one of its values, compared as exact strings.
To keep the earlier behaviour while you find the audience, pass audienceCheck: 'off', and remove it once audience is set.

Building Custom Adapters

Extend BaseAdapter to integrate any API:

Error Codes

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.

Current Authority and Human Identity

Use the exact integration version and minimum primary SDK in Release Status. Per-invocation issuer authority and trusted principal/agent binding are opt-in. Configure the callback with the trusted issuer and derive identity from the host’s authenticated session; signature and scope checks alone do not prove current revocation or human consent. See SDK execution authority for configuration, denial behavior and manifest/decision/caps boundaries.
Last modified on October 4, 2026