TypeScript Install
TypeScript Quick Start
The TypeScript helper verifies the grant token against JWKS before each tool invocation and checks its verified scopes. Set online: true with a Grantex client and connector to delegate enforcement to client.enforce(). Local verification alone does not prove current revocation. Capped calls require trusted amounts; see migration.
From version 0.2.0, both helpers also pass their audience option to
client.enforce() in online mode as the per-call grant token audience, as
offline verification already uses it. enforce() denies a token
that carries aud when no audience is expected (audience_unconfigured), so
set audience to the identifier your service is issued tokens for (see
Grant token audience).
Python Install
Python Quick Start
The Python helper verifies the grant token against JWKS and raises PermissionError if the required scope is missing.
Requirements
- Node.js 22.12+ and SDK 0.8+ for
@grantex/strands
- Python 3.11+ for
grantex-strands
- Strands Agents SDK for the language you use
Public Python-wheel tests, registry hashes and normal pinned PyPI index
installations passed; see release validation.
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Current Authority and Human Identity
Use the exact integration version and minimum primary SDK in Release Status.
Per-invocation issuer authority and trusted principal/agent binding are opt-in.
Configure the callback with the trusted issuer and derive identity from the host’s
authenticated session; signature and scope checks alone do not prove current
revocation or human consent. See SDK execution authority
for configuration, denial behavior and manifest/decision/caps boundaries.Last modified on October 4, 2026