Skip to main content

Install

OpenAI Agents SDK is a peer dependency:

Quick Start

If the grant token doesn’t include the required scope, create_grantex_tool raises a PermissionError immediately — the tool is never created.

API Reference

create_grantex_tool()

Creates an OpenAI Agents SDK FunctionTool that verifies the token against the configured JWKS endpoint before enforcing scopes from verified claims.

get_tool_scopes(grant_token)

Returns unverified scopes decoded from a grant token. Use this only for display or debugging, never for authorization.

decode_jwt_payload(token)

Decodes the payload of a JWT without verifying the signature. Useful for inspecting token claims.

Requirements

  • Python 3.9+
  • grantex >= 0.1.0
  • openai-agents >= 0.0.3 (peer dependency)

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.

Current Authority and Human Identity

Use the exact integration version and minimum primary SDK in Release Status. Per-invocation issuer authority and trusted principal/agent binding are opt-in. Configure the callback with the trusted issuer and derive identity from the host’s authenticated session; signature and scope checks alone do not prove current revocation or human consent. See SDK execution authority for configuration, denial behavior and manifest/decision/caps boundaries.
Last modified on September 29, 2026