Install
Quick Start
Two lines of middleware protect your entire API:
After requireGrantToken() succeeds, every downstream handler can access req.grant — a fully typed VerifiedGrant object containing the principal, agent, scopes, and timestamps.
How It Works
requireGrantToken() extracts the Bearer token from the Authorization header
- It resolves the signing key from the configured JWKS endpoint and verifies the RS256 signature and claims locally
- On success,
req.grant is populated and next() is called
requireScopes() checks that req.grant.scopes contains every required scope
- If any scope is missing, it returns a
403 Forbidden response
Factory Pattern
Use createGrantex() to avoid repeating the same options on every route:
You can still override options per-route:
By default, the middleware reads the Authorization: Bearer <token> header. You can override this:
Custom Error Handling
Provide an onError callback to customize error responses:
Error Codes
req.grant Reference
After requireGrantToken() succeeds, req.grant contains a VerifiedGrant:
Full Example
A complete Express API protected by Grantex:
TypeScript Support
Import GrantexRequest for typed route handlers:
All types are exported:
Requirements
- Node.js 18+
- Express 4.18+
@grantex/sdk >= 0.1.0
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Current Authority and Human Identity
Use the exact integration version and minimum primary SDK in Release Status.
Per-invocation issuer authority and trusted principal/agent binding are opt-in.
Configure the callback with the trusted issuer and derive identity from the host’s
authenticated session; signature and scope checks alone do not prove current
revocation or human consent. See SDK execution authority
for configuration, denial behavior and manifest/decision/caps boundaries.Last modified on September 29, 2026