Install
Node.js 22.12+ is required. This release uses SDK 0.8 enforcement: expected
audience, trusted amounts for capped calls and default online revocation.
See migration. An agent-controlled CLI preflight
does not replace enforcement at the service that owns the side effect.
Config is saved to ~/.grantex/config.json. Environment variables override the config file.
Install skills for an agent CLI
The CLI bundles use-grantex-cli and integrate-grantex as portable Agent Skills:
See Agent CLIs & Skills for discovery paths, activation checks, and security boundaries.
JSON Output
All commands support --json for machine-readable output. This is useful for scripting, piping into jq, or when using the CLI from AI coding assistants (Claude Code, Cursor, Codex, etc.).
To disable colored output, set the NO_COLOR=1 environment variable.
Denied and invalid checks return a non-zero exit status in JSON mode as well as text mode.
Avoid putting grant tokens in shell history or process arguments:
The verification commands also accept --file and --stdin. enforce test accepts --token-file and --token-stdin.
Commands
Authorize (Core Flow)
Agents
Repeat --redirect-uri for multiple callbacks. On update, these values replace
the complete list. Omitting the option preserves existing callbacks, while
--clear-redirect-uris removes all of them. Live authorization requires an
exact match to a registered HTTPS URI.
Tokens
Grants
Budgets
Usage
Events
Audit Log
Webhooks
Supported events: grant.created, grant.revoked, token.issued.
Policies
Domains
Principal Sessions
Compliance
Anomaly Detection
Billing
Account
Vault (Credential Storage)
WebAuthn / FIDO2
Verifiable Credentials
Agent Passports (MPP)
SCIM
SSO
DPDP Records
These commands keep the records described in DPDP Compliance;
they help evidence DPDP Act obligations and are not legal advice.
Full Workflow Example
Local Development
For local development with Docker Compose:
Requirements
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.Last modified on September 30, 2026