# Grantex > Documentation and API reference for Grantex AI agent authorization, delegated OAuth grants, agent identity, scoped permissions, MCP authorization, verification, and audit. Grantex is owned by Orchestrum Technologies LLP; inventor and owner: Sanjeev Kumar. - [Grantex AI Agent Authorization](https://docs.grantex.dev/introduction.md): Learn how Grantex provides delegated authorization, verifiable identity, scoped permissions, human consent, and audit records for AI agents. - [Ownership](https://docs.grantex.dev/ownership.md): Meet Grantex inventor Sanjeev Kumar, Founder & CEO of Orchestrum Technologies LLP, and find official ownership contacts and public profiles. - [AI Agent Authorization Quickstart](https://docs.grantex.dev/quickstart.md): Implement AI agent authorization with Grantex: register an agent, request consent, exchange a code, verify a JWT grant, and write audit records. - [Release Status](https://docs.grantex.dev/release-status.md): Choose the current Grantex CLI, TypeScript, Python, Go, or MCP package with exact versions, runtime requirements, limitations, and reproducible install commands. - [Migrating to Grantex 0.6](https://docs.grantex.dev/migration-0.6.md): Every change from Grantex 0.5 to 0.6 that can break an integration — manifests, purpose-bound grants, caps, ES256 signing and standard token claims — and what to do about each. - [Enforcement SDK migration](https://docs.grantex.dev/migration-enforcement.md): Migrate TypeScript 0.8, Python 0.7, MCP Auth 3 and enforcement integrations with explicit audience, amounts, revocation and runtime requirements. - [Local Development](https://docs.grantex.dev/local-development.md): Run the full Grantex stack locally with Docker Compose. - [How It Works](https://docs.grantex.dev/concepts/how-it-works.md): The three primitives that make up the Grantex protocol. - [Grant Token](https://docs.grantex.dev/concepts/grant-token.md): Grantex grant tokens are RS256- or ES256-signed JWTs with agent-specific claims. - [Scopes](https://docs.grantex.dev/concepts/scopes.md): Grantex scopes use the resource:action[:constraint] naming convention. - [Scope Registry](https://docs.grantex.dev/concepts/scope-registry.md): Standard scope definitions for common domains, plus guidelines for custom scopes. - [Multi-Agent Delegation](https://docs.grantex.dev/concepts/delegation.md): How Grantex handles authorization chains across multi-agent pipelines. - [Grantex vs OAuth 2.0](https://docs.grantex.dev/concepts/vs-oauth.md): How Grantex compares to OAuth 2.0 and when to use each. - [Tool Manifests](https://docs.grantex.dev/concepts/tool-manifests.md): How tool manifests map every tool to a permission level, enabling precise scope enforcement for AI agent tool calls. - [Purpose-Bound Grants](https://docs.grantex.dev/concepts/purpose-bound-grants.md): Bind a grant to the purpose a person approved, and let tools refuse calls made for any other purpose. - [Agent Passport and Grant](https://docs.grantex.dev/concepts/passport-vs-grant.md): An Agent Passport says who an agent is; a grant says what a person lets it do. How a grant is bound to a passport. - [Grantex and AgenticOrg Governed Cases](https://docs.grantex.dev/guides/agenticorg-governed-cases.md): What Grantex verifies for AgenticOrg business onboarding cases, what AgenticOrg enforces locally, and which purpose and cap controls are not yet wired into the integration. - [Decision Grants](https://docs.grantex.dev/concepts/decision-grants.md): Require a named person's approval, bound to one exact action and made outside the platform's reach, before an agent can decide, file, close or pay. - [Caps and Metering](https://docs.grantex.dev/concepts/caps-and-metering.md): Per-tool call caps over rolling windows and per case, cost-unit budgets, and a meter that cannot be raced past a cap. - [Evidence and Verification](https://docs.grantex.dev/concepts/evidence-and-verification.md): A per-case evidence package - grants, tool calls, upstream records, policy scores, human decisions - in a hash chain the auth service anchors and signs, verifiable without trusting the system that produced it. - [Event Bridge and Revocation](https://docs.grantex.dev/concepts/event-bridge-and-revocation.md): Ingest signed provider events (SSF/CAEP Security Event Tokens or signed webhooks) and turn them into grant actions, never failing open. - [Trust Registry](https://docs.grantex.dev/features/trust-registry.md): Public organization directory with DID identity and DNS ownership verification. - [Becoming an Accredited Issuer](https://docs.grantex.dev/issuers/becoming-an-accredited-issuer.md): What the registry records about an accredited issuer in Phase 1, and how an accredited issuer posts, withdraws and refreshes attestations. - [Running the Mock Issuer](https://docs.grantex.dev/issuers/running-the-mock-issuer.md): A mock accredited issuer for local runs and CI: static JWKS, Agent Passport issuance, passport status lists and attestations, with no external party and no network. - [Implementing an Issuer Adapter](https://docs.grantex.dev/issuers/implementing-an-issuer-adapter.md): The one interface between the registry and an accredited issuer: three operations, an entry point, and five environment variables. The mock issuer implements it in the repository; a real issuer's adapter lives in its own package. - [Registering Agents and Their Keys](https://docs.grantex.dev/providers/registering-agents.md): Register an agent's keys, prove possession with a signed challenge, rotate with an overlap, and report a compromised key. - [Verifying agents](https://docs.grantex.dev/relying-parties/verifying-agents.md) - [FIDO2 / WebAuthn](https://docs.grantex.dev/features/fido-webauthn.md): Enroll customer passkeys, verify live consent, and export opt-in portable WebAuthn assertion evidence. - [Verifiable Credentials](https://docs.grantex.dev/features/verifiable-credentials.md): W3C Verifiable Credentials issued alongside grant tokens. Portable, tamper-proof proof of agent authorization for any verifier. - [SD-JWT (Selective Disclosure)](https://docs.grantex.dev/features/sd-jwt.md): Selective Disclosure JWTs let agents present only the claims needed for a given transaction, enabling privacy-preserving authorization and Verifiable Intent compatibility. - [DID Infrastructure](https://docs.grantex.dev/features/did-infrastructure.md): W3C Decentralized Identifier (DID) infrastructure for independent credential verification. Resolve did:web:grantex.dev to verify any Grantex-issued credential. - [MPP Agent Passport](https://docs.grantex.dev/features/mpp-agent-passport.md): W3C Verifiable Credential for agent identity in machine-to-machine payments via the Machine Payments Protocol (MPP). - [Irregularity Detection](https://docs.grantex.dev/features/anomaly-detection.md): What Grantex detects, when it runs, and how an account chooses alert-only or revocation. - [Offline Authorization](https://docs.grantex.dev/features/offline-authorization.md): How Grantex enables offline authorization for on-device AI agents. Architecture, security model, and limitations. - [Consent Bundles](https://docs.grantex.dev/features/consent-bundles.md): Consent bundles package a grant token, JWKS snapshot, and audit signing key for offline-capable authorization. - [Agent Prepaid Wallets](https://docs.grantex.dev/features/prepaid-wallets.md): Principal-controlled prepaid balances, multi-wallet assignment, spend policy, reload approval, and emergency blocking for AI agents. - [Agent Wallet Governance](https://docs.grantex.dev/guides/agent-wallet-governance.md): Responsibility boundaries, layered spend controls, exact payment approvals, reload governance, and deployment gaps for AI-agent prepaid wallets. - [Prepaid Wallet Production Readiness](https://docs.grantex.dev/guides/prepaid-wallet-production.md): External dependencies, deployment boundaries, routing, notification delivery, merchant recovery, and release checks for self-hosted Grantex prepaid wallets and x402 v2. - [Base USDC Custody](https://docs.grantex.dev/guides/base-usdc-custody.md): Governed x402 EIP-3009 signing, verified funding, safe retries and finalized-chain reconciliation. - [x402 Architecture](https://docs.grantex.dev/features/x402-architecture.md): Official x402 v2 payment messages backed by principal-controlled Grantex prepaid-wallet reservations. - [GDT Specification](https://docs.grantex.dev/features/x402-gdt-spec.md): Specification of the Grantex Delegation Token (GDT) — a W3C Verifiable Credential 2.0 for agent spend authorization. - [MCP Auth Server](https://docs.grantex.dev/features/mcp-auth-server.md): MCP Auth 4 binds rendered consent to the authenticated human and checks current grant authority before protected tool execution. - [MCP Auth 4.0: authenticated human consent](https://docs.grantex.dev/mcp-auth.md): Bind MCP consent to an authenticated human, preserve principal identity across callbacks and refresh, and check current grant authority before execution. - [OACP Authority Overview](https://docs.grantex.dev/guides/oacp/overview.md): The canonical Grantex overview for Open Agentic Commerce Protocol authority, artifacts, policy, and adapter governance. - [OACP Truth Inventory](https://docs.grantex.dev/guides/oacp/truth-inventory.md): Evidence-backed inventory of what is implemented, gated, missing, or stale across the current OACP split. - [OACP Architecture](https://docs.grantex.dev/guides/oacp/architecture.md): The Grantex view of the OACP four-party architecture. - [OACP Artifact Authority](https://docs.grantex.dev/guides/oacp/artifact-authority.md): How Grantex issues, refuses, and verifies OACP artifacts for AgenticOrg. - [OACP Merchant Self-Service Config Boundary](https://docs.grantex.dev/guides/oacp/merchant-self-service-config.md): What AgenticOrg merchant configuration owns, what Grantex signs, and how future connectors and bank providers stay non-executing until approved. - [OACP Protocol Adapter Authority](https://docs.grantex.dev/guides/oacp/protocol-adapter.md): How Grantex maps canonical OACP artifacts to compatibility payloads. - [OACP Policy And Governance](https://docs.grantex.dev/guides/oacp/policy-governance.md): Policy, freshness, source, revocation, and adapter governance for Grantex OACP authority. - [OACP Merchant Source Of Record](https://docs.grantex.dev/guides/oacp/merchant-source-of-record.md): Why Shopify and merchant systems remain authoritative in OACP. - [OACP Buyer Safety And Freshness](https://docs.grantex.dev/guides/oacp/buyer-safety-freshness.md): How source, freshness, cache, and refusal behavior keep buyer agents grounded. - [OACP Provider And Payment Boundary](https://docs.grantex.dev/guides/oacp/provider-payment-boundary.md): How OACP treats Pine Labs Plural/P3P and other payment rails. - [OACP Offline POS Bridge Boundary](https://docs.grantex.dev/guides/oacp/pos-bridge-boundary.md): How Grantex treats Offline POS handoff evidence without owning POS transactions. - [OACP Integration Guide For AgenticOrg](https://docs.grantex.dev/guides/oacp/agenticorg-integration.md): How AgenticOrg requests and consumes Grantex OACP authority artifacts. - [OACP Operator Runbook](https://docs.grantex.dev/guides/oacp/operator-runbook.md): Grantex operator runbook for authority requests, cache safety, launch checks, and rollback. - [OACP Launch Readiness](https://docs.grantex.dev/guides/oacp/launch-readiness.md): Launch readiness gates, rollback criteria, and remaining gaps for Grantex OACP authority. - [Move Your Shopify Store To Agentic Commerce](https://docs.grantex.dev/guides/oacp/explainers/shopify-to-agentic-commerce.md): Merchant explainer for bringing Shopify into AgenticOrg with Grantex OACP authority. - [How Buyer Agents Shop Safely With OACP](https://docs.grantex.dev/guides/oacp/explainers/buyer-agent-safety.md): Buyer explainer for OACP source, freshness, and refusal behavior. - [Build Against OACP Artifacts And Bridges](https://docs.grantex.dev/guides/oacp/explainers/developer-artifacts-bridges.md): Developer explainer for OACP artifacts, AgenticOrg bridges, and adapter payloads. - [How OACP Maps To Schema.org, UCP, ACP, AP2, A2A, And MCP](https://docs.grantex.dev/guides/oacp/explainers/protocol-partner-mappings.md): Protocol partner explainer for OACP compatibility mappings. - [Provider-Owned Mandate And Payment Evidence In OACP](https://docs.grantex.dev/guides/oacp/explainers/provider-owned-payment-evidence.md): Payment and fintech partner explainer for OACP evidence boundaries. - [Launch And Rollback Runbook](https://docs.grantex.dev/guides/oacp/explainers/launch-rollback-runbook.md): Operator explainer for OACP launch, smoke tests, monitoring, and rollback. - [Commerce V1 Overview](https://docs.grantex.dev/guides/commerce-v1-overview.md): Start here for Grantex Agentic Commerce architecture, readiness, safety gates, and audience-specific paths. - [Agentic Commerce PRD](https://docs.grantex.dev/guides/commerce-v1-agentic-commerce-prd.md): Canonical product requirements document for Grantex Commerce and AgenticOrg agentic commerce implementation. - [Agentic Commerce Implementation PRD](https://docs.grantex.dev/guides/commerce-v1-agentic-commerce-implementation-prd.md): Merchant-readable product requirements and gap plan for making Grantex Commerce and AgenticOrg ready for self-serve agentic commerce. - [End-To-End Agentic Commerce Flow](https://docs.grantex.dev/guides/commerce-v1-end-to-end-agentic-commerce-flow.md): Plain-language buyer and seller flow for OACP agentic commerce with AgenticOrg agents and Grantex trust authority. - [Merchant Guide To Agentic Commerce](https://docs.grantex.dev/guides/commerce-v1-merchant-agentic-commerce-user-guide.md): A detailed merchant-facing guide for using Grantex Commerce V1 safely with AI agents, read-only discovery, consent, approvals, launch readiness, operations, and support workflows. - [Commerce V1 Developer Guide](https://docs.grantex.dev/guides/commerce-v1-developer-guide.md): Grantex Commerce REST/MCP model, consent/passport sequence, idempotency, webhooks, Shopify live-pilot usage, and provider boundaries. - [Commerce V1 Merchant And Operator Guide](https://docs.grantex.dev/guides/commerce-v1-merchant-operator-guide.md): Merchant onboarding, catalog, policy, audit, webhook, emergency control, and production no-go guidance for Grantex Commerce V1. - [Commerce V1 Operations](https://docs.grantex.dev/guides/commerce-v1-operations.md): Sandbox operations, import columns, and runbooks for Grantex Commerce V1. - [DPDP & GDPR Evidence Module](https://docs.grantex.dev/features/dpdp-compliance.md): Consent records bound to grants and versioned notices, withdrawal, erasure, grievances, a breach register and exports that help a Data Fiduciary evidence its DPDP Act, GDPR and EU AI Act obligations. - [DPDP Act 2023 and DPDP Rules 2025](https://docs.grantex.dev/compliance/dpdp-act-2023.md): How Grantex features map to India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 for AI agent deployments, what Grantex provides and what remains the Data Fiduciary's responsibility. - [EU AI Act](https://docs.grantex.dev/compliance/eu-ai-act.md): The EU AI Act timeline as amended by Regulation (EU) 2026/1744, provider and deployer obligations, and how Grantex records can help evidence them, with their limits. - [Sub processors](https://docs.grantex.dev/compliance/sub-processors.md) - [Data residency](https://docs.grantex.dev/compliance/data-residency.md) - [BFSI platform baseline](https://docs.grantex.dev/compliance/bfsi-platform-baseline.md): How the authority layer contributes to a bank-grade enterprise AI platform baseline, and where it stops. - [Dpa](https://docs.grantex.dev/compliance/dpa.md) - [Privacy policy](https://docs.grantex.dev/compliance/privacy-policy.md) - [Terms of service](https://docs.grantex.dev/compliance/terms-of-service.md) - [Cookie policy](https://docs.grantex.dev/compliance/cookie-policy.md) - [Rate Limits](https://docs.grantex.dev/guides/rate-limits.md): Understand and work with Grantex API rate limits. - [Webhooks](https://docs.grantex.dev/guides/webhooks.md): Receive real-time notifications for grant lifecycle events. - [Self-Hosting](https://docs.grantex.dev/guides/self-hosting.md): Run your own Grantex auth service — from local dev to production Kubernetes. - [Dependency Updates and Validation](https://docs.grantex.dev/guides/dependency-updates.md): Validate dependency upgrades locally before deploying Grantex. - [Security Hardening](https://docs.grantex.dev/guides/security-hardening.md): Enterprise-grade security controls built into the Grantex auth service — headers, rate limiting, CORS, input validation, and more. - [Supply Chain and License Security](https://docs.grantex.dev/guides/supply-chain-security.md): Audit Grantex npm, Python, Go, container, GitHub Action, and third-party license dependencies before deploying or redistributing it. - [OAuth Agent Grants Profile](https://docs.grantex.dev/guides/oauth-agent-grants.md): Implement the Grantex OAuth agent-grants profile with PAR, PKCE, DPoP, consent, rotating refresh tokens, token exchange, and revocation. - [Operations](https://docs.grantex.dev/guides/operations.md): Run Grantex in production — health checks, required configuration, graceful shutdown, connection management, and webhook delivery. - [Security Best Practices](https://docs.grantex.dev/guides/security-best-practices.md): Harden your Grantex integration with token storage strategies, scope design, revocation handling, and more. - [Token Verification Strategy](https://docs.grantex.dev/guides/token-verification.md): Choose between offline, online, and hybrid token verification strategies. - [SDK Execution Authority](https://docs.grantex.dev/guides/sdk-execution-authority.md): Keep human identity, consent, current grant authority and execution policy separate at every SDK boundary. - [Troubleshooting](https://docs.grantex.dev/guides/troubleshooting.md): Common issues and solutions when working with the Grantex API and SDKs. - [End-User Permission Dashboard](https://docs.grantex.dev/guides/end-user-permissions.md): Give your users a self-service page to view and revoke agent access. - [Migration Guide](https://docs.grantex.dev/guides/migration.md): Step-by-step guides for migrating to Grantex from API keys or raw OAuth 2.0. - [Metrics & Observability](https://docs.grantex.dev/guides/metrics-observability.md): Monitor your Grantex deployment with Prometheus metrics, Grafana dashboards, alerting rules, and structured logging. - [OpenTelemetry Tracing](https://docs.grantex.dev/guides/opentelemetry.md): Instrument your Grantex auth service with OpenTelemetry for distributed tracing and APM. - [Event Streaming](https://docs.grantex.dev/guides/event-streaming.md): Stream Grantex authorization events in real time via SSE or WebSocket, and forward them to external systems with @grantex/destinations. - [Datadog Integration](https://docs.grantex.dev/guides/siem-datadog.md): Forward Grantex authorization events to Datadog for centralized logging, dashboards, and anomaly detection monitors. - [Splunk Integration](https://docs.grantex.dev/guides/siem-splunk.md): Forward Grantex authorization events to Splunk via the HTTP Event Collector for search, alerting, and compliance dashboards. - [S3 & BigQuery Archival](https://docs.grantex.dev/guides/siem-s3-bigquery.md): Archive Grantex authorization events to Amazon S3 and Google BigQuery for compliance, auditing, and long-term analytics. - [Budget & Spending Controls](https://docs.grantex.dev/guides/budget-controls.md): Allocate budgets to grants and track spending with per-transaction debit, threshold alerts, and JWT budget claims. - [Terraform Provider](https://docs.grantex.dev/guides/terraform.md): Manage Grantex resources as infrastructure with the official Terraform provider. - [Pulumi](https://docs.grantex.dev/guides/pulumi.md): Use the Grantex Terraform provider with Pulumi via the Terraform bridge. - [Interactive Playground](https://docs.grantex.dev/guides/playground.md): Run the Grantex sandbox authorization, refresh, and revocation flow in a browser with an automatically created sandbox account. - [OPA Integration](https://docs.grantex.dev/guides/opa-integration.md): Use Open Policy Agent as your Grantex policy backend - [Cedar Integration](https://docs.grantex.dev/guides/cedar-integration.md): Use AWS Cedar as your Grantex policy backend - [Policy-as-Code](https://docs.grantex.dev/guides/policy-as-code.md): Manage Grantex policies in Git with automated sync - [Usage Metering](https://docs.grantex.dev/guides/usage-metering.md): Track and monitor API usage across your Grantex deployment - [Custom Domains](https://docs.grantex.dev/guides/custom-domains.md): Use your own domain for Grantex API endpoints (Enterprise) - [Trust Registry Setup](https://docs.grantex.dev/guides/trust-registry-setup.md): Register a did:web organization and complete DNS TXT ownership verification. - [MPP Integration Guide](https://docs.grantex.dev/guides/mpp-integration.md): Step-by-step guide to adding Grantex agent identity to MPP payment flows — for both agents and merchants. - [MCP Certification Applications](https://docs.grantex.dev/guides/mcp-certification.md): Register an MCP server and submit a Bronze, Silver, or Gold certification application. - [Enterprise SSO](https://docs.grantex.dev/guides/enterprise-sso.md): Configure enterprise identity providers and enforce human SSO for dashboard and consent decisions. - [Compliance Matrix](https://docs.grantex.dev/guides/compliance-matrix.md): How Grantex maps to OWASP Agentic Top 10, EU AI Act, and NIST AI RMF requirements for AI agent security and authorization. - [Irregularity Detection Setup](https://docs.grantex.dev/guides/anomaly-detection-setup.md): Run Grantex's explicit detector and choose an account-wide alert-only or revocation response. - [Raspberry Pi Guide](https://docs.grantex.dev/guides/raspberry-pi.md): Run Grantex-authorized Gemma agents on Raspberry Pi 5 with offline token verification, scope enforcement, local audit records, and later synchronization. - [Android + Gemma 4 Guide](https://docs.grantex.dev/guides/android-gemma4.md): Integrate Grantex offline authorization into Android apps running Gemma 4 agents. - [iOS + Gemma 4 Guide](https://docs.grantex.dev/guides/ios-gemma4.md): Integrate Grantex offline authorization into iOS apps running Gemma 4 agents using Swift and CryptoKit. - [Scope Enforcement](https://docs.grantex.dev/guides/scope-enforcement.md): Enforce per-tool permissions on every AI agent tool call using manifests, the enforce() API, and framework integrations. - [Custom Manifests](https://docs.grantex.dev/guides/custom-manifests.md): Define tool manifests for any connector — internal APIs, new SaaS tools, proprietary services. No dependency on Grantex. - [AgenticOrg Case Study](https://docs.grantex.dev/case-studies/agenticorg.md): How AgenticOrg enforces scope on 35 AI agents, 53+ connectors, and 339+ tools using Grantex tool manifests. - [Quickstart (TypeScript)](https://docs.grantex.dev/examples/quickstart-ts.md): End-to-end authorization lifecycle with the TypeScript SDK. - [Quickstart (Python)](https://docs.grantex.dev/examples/quickstart-py.md): End-to-end authorization lifecycle with the Python SDK. - [Next.js Starter](https://docs.grantex.dev/examples/nextjs-starter.md): Interactive Next.js app showing the full Grantex consent flow. - [LangChain Agent](https://docs.grantex.dev/examples/langchain-agent.md): Scoped tools with automatic audit logging using LangChain. - [Vercel AI Chatbot](https://docs.grantex.dev/examples/vercel-ai-chatbot.md): Scope-enforced tools with audit logging using Vercel AI SDK. - [CrewAI Agent](https://docs.grantex.dev/examples/crewai-agent.md): Scoped tools with audit logging using CrewAI. - [OpenAI Agents SDK](https://docs.grantex.dev/examples/openai-agents.md): Scope-enforced tools using the OpenAI Agents SDK. - [Google ADK](https://docs.grantex.dev/examples/google-adk.md): Scope-enforced tools using Google Agent Development Kit. - [Anthropic SDK Tool Use](https://docs.grantex.dev/examples/anthropic-tool-use.md): Scope-enforced tool use with audit logging using the Anthropic SDK. - [Multi-Agent Email Flow](https://docs.grantex.dev/examples/multi-agent-email-flow.md): Multi-agent delegation with failure handling, cascade revocation, and audit trail. - [Token Refresh & Rotation](https://docs.grantex.dev/examples/token-expiry-refresh.md): Active-grant refresh rotation, lost-response recovery, and the expired-grant re-authorization boundary. - [Audit Dashboard](https://docs.grantex.dev/examples/audit-dashboard.md): Query, filter, and analyze the Grantex audit trail with metrics and hash chain verification. - [Quickstart: Gemma 4 Offline Auth](https://docs.grantex.dev/examples/quickstart-gemma.md): Get offline authorization working with Gemma 4 agents in under 5 minutes. Install @grantex/gemma, create a consent bundle, and verify tokens offline. - [TypeScript SDK](https://docs.grantex.dev/sdks/typescript/overview.md): Install, configure, and get started with the @grantex/sdk TypeScript SDK. - [Authorization](https://docs.grantex.dev/sdks/typescript/authorization.md): Initiate the delegated authorization flow to request user consent for your agent. - [Tokens](https://docs.grantex.dev/sdks/typescript/tokens.md): Exchange authorization codes for grant tokens, verify tokens online, and revoke them. - [Offline Verification](https://docs.grantex.dev/sdks/typescript/offline-verification.md): Verify grant tokens locally with published JWKS keys, without a per-token Grantex verification API call. - [PKCE](https://docs.grantex.dev/sdks/typescript/pkce.md): Protect the authorization flow with Proof Key for Code Exchange (PKCE) using S256 challenges. - [Agents](https://docs.grantex.dev/sdks/typescript/agents.md): Register, list, update, and delete AI agents with the Grantex TypeScript SDK. - [Grants](https://docs.grantex.dev/sdks/typescript/grants.md): Manage grants, delegate authorization to sub-agents, and verify tokens via the API. - [Audit](https://docs.grantex.dev/sdks/typescript/audit.md): Log agent actions and query the tamper-evident audit trail. - [Webhooks](https://docs.grantex.dev/sdks/typescript/webhooks.md): Receive real-time notifications for grant and token lifecycle events. - [Policies](https://docs.grantex.dev/sdks/typescript/policies.md): Define allow/deny authorization policies to control agent access. - [Compliance](https://docs.grantex.dev/sdks/typescript/compliance.md): Generate compliance summaries, export grants and audit data, and produce evidence packs for SOC 2 and GDPR. - [Anomaly Detection](https://docs.grantex.dev/sdks/typescript/anomalies.md): Detect, list, and acknowledge anomalous agent behavior patterns. - [Billing](https://docs.grantex.dev/sdks/typescript/billing.md): Manage subscriptions and access Stripe checkout and billing portal sessions. - [SCIM 2.0](https://docs.grantex.dev/sdks/typescript/scim.md): Provision and manage users via the SCIM 2.0 protocol, and manage SCIM bearer tokens. - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/typescript/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, with multi-IdP connections and domain enforcement. - [Principal Sessions](https://docs.grantex.dev/sdks/typescript/principal-sessions.md): Generate session tokens for end-users to view and manage their agent permissions. - [WebAuthn](https://docs.grantex.dev/sdks/typescript/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users. - [Credentials](https://docs.grantex.dev/sdks/typescript/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures. - [Credential Vault](https://docs.grantex.dev/sdks/typescript/vault.md): Store encrypted upstream credentials and exchange grant tokens for scoped access. - [Budgets](https://docs.grantex.dev/sdks/typescript/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history. - [Events](https://docs.grantex.dev/sdks/typescript/events.md): Subscribe to real-time authorization events via Server-Sent Events. - [Usage](https://docs.grantex.dev/sdks/typescript/usage.md): Track current UTC API usage metrics and view daily usage history. - [Domains](https://docs.grantex.dev/sdks/typescript/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/typescript/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity. - [Commerce V1](https://docs.grantex.dev/sdks/typescript/commerce.md): Use the @grantex/sdk Commerce V1 client for OACP merchant discovery, catalog grounding, consent, Commerce Passport, payment intent, checkout, webhook, and ops flows. - [Enforce](https://docs.grantex.dev/sdks/typescript/enforce.md): Check whether an agent's grant token permits a specific tool call. Load manifests, call enforce(), and wrap LangChain tools. - [Error Handling](https://docs.grantex.dev/sdks/typescript/errors.md): Understand the error hierarchy and handle API, authentication, token, and network errors. - [Python SDK](https://docs.grantex.dev/sdks/python/overview.md): Install and configure the Grantex Python SDK for delegated authorization of AI agents. - [Authorization](https://docs.grantex.dev/sdks/python/authorization.md): Initiate the delegated authorization flow to request permissions from a user on behalf of an AI agent. - [Tokens](https://docs.grantex.dev/sdks/python/tokens.md): Exchange authorization codes for grant tokens, verify tokens online, and revoke tokens. - [Offline Verification](https://docs.grantex.dev/sdks/python/offline-verification.md): Verify signatures and claims locally with a remote JWKS request per standalone call, without online token introspection. - [PKCE](https://docs.grantex.dev/sdks/python/pkce.md): Use Proof Key for Code Exchange (PKCE) to secure the authorization flow against code interception attacks. - [Agents](https://docs.grantex.dev/sdks/python/agents.md): Register, retrieve, update, list, and delete AI agents using the Grantex Python SDK. - [Grants](https://docs.grantex.dev/sdks/python/grants.md): Retrieve, list, revoke, delegate, and verify grants using the Grantex Python SDK. - [Audit](https://docs.grantex.dev/sdks/python/audit.md): Log, query, and retrieve tamper-evident audit entries for agent actions using the Grantex Python SDK. - [Webhooks](https://docs.grantex.dev/sdks/python/webhooks.md): Register webhook endpoints, receive event notifications, and verify webhook signatures with the Grantex Python SDK. - [Policies](https://docs.grantex.dev/sdks/python/policies.md): Create, manage, and enforce authorization policies for fine-grained access control with the Grantex Python SDK. - [Compliance](https://docs.grantex.dev/sdks/python/compliance.md): Generate compliance summaries, export grants and audit data, and produce SOC 2/GDPR evidence packs with the Grantex Python SDK. - [Anomaly Detection](https://docs.grantex.dev/sdks/python/anomalies.md): Detect, list, and acknowledge authorization anomalies using the Grantex Python SDK. - [Billing](https://docs.grantex.dev/sdks/python/billing.md): Manage subscriptions, create checkout sessions, and access the billing portal with the Grantex Python SDK. - [SCIM 2.0](https://docs.grantex.dev/sdks/python/scim.md): Provision and manage users via SCIM 2.0, and manage SCIM bearer tokens with the Grantex Python SDK. - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/python/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, using the Grantex Python SDK. - [Principal Sessions](https://docs.grantex.dev/sdks/python/principal-sessions.md): Generate session tokens for end-users to view and manage their agent permissions. - [WebAuthn](https://docs.grantex.dev/sdks/python/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users. - [Credentials](https://docs.grantex.dev/sdks/python/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures. - [Budgets](https://docs.grantex.dev/sdks/python/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history. - [Events](https://docs.grantex.dev/sdks/python/events.md): Subscribe to real-time authorization events via Server-Sent Events. - [Usage](https://docs.grantex.dev/sdks/python/usage.md): Track current UTC-date API usage metrics and view daily usage history. - [Domains](https://docs.grantex.dev/sdks/python/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/python/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity. - [Commerce V1](https://docs.grantex.dev/sdks/python/commerce.md): Use the Grantex Python SDK Commerce V1 client for OACP merchant discovery, catalog grounding, consent, payment, webhook, and ops flows. - [Vault](https://docs.grantex.dev/sdks/python/vault.md): Store, retrieve, and exchange encrypted service credentials through the Grantex credential vault. - [Enforce](https://docs.grantex.dev/sdks/python/enforce.md): Check whether an agent's grant token permits a specific tool call. Load manifests, call enforce(), and wrap LangChain tools. - [Error Handling](https://docs.grantex.dev/sdks/python/errors.md): Handle API errors, authentication failures, token verification errors, and network issues in the Grantex Python SDK. - [Go SDK](https://docs.grantex.dev/sdks/go/overview.md): Official Go SDK for the Grantex delegated authorization protocol - [Authorization](https://docs.grantex.dev/sdks/go/authorization.md): Create authorization requests and manage the consent flow - [Tokens](https://docs.grantex.dev/sdks/go/tokens.md): Exchange, refresh, verify, and revoke grant tokens - [Offline Verification](https://docs.grantex.dev/sdks/go/offline-verification.md): Verify signatures and claims locally with a remote JWKS request per standalone call - [PKCE](https://docs.grantex.dev/sdks/go/pkce.md): Proof Key for Code Exchange (S256) for enhanced security - [Agents](https://docs.grantex.dev/sdks/go/agents.md): Register and manage AI agents - [Grants](https://docs.grantex.dev/sdks/go/grants.md): Manage authorization grants and delegation - [Audit](https://docs.grantex.dev/sdks/go/audit.md): Log and query tamper-evident audit entries - [Webhooks](https://docs.grantex.dev/sdks/go/webhooks.md): Manage webhook endpoints and verify signatures - [Policies](https://docs.grantex.dev/sdks/go/policies.md): Create and manage access policies - [Compliance](https://docs.grantex.dev/sdks/go/compliance.md): Generate compliance reports and evidence packs - [Anomalies](https://docs.grantex.dev/sdks/go/anomalies.md): Detect and manage security anomalies - [Billing](https://docs.grantex.dev/sdks/go/billing.md): Manage subscriptions and billing - [SCIM](https://docs.grantex.dev/sdks/go/scim.md): SCIM 2.0 user provisioning - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/go/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, using the Grantex Go SDK. - [Principal Sessions](https://docs.grantex.dev/sdks/go/principal-sessions.md): Create end-user dashboard sessions - [WebAuthn](https://docs.grantex.dev/sdks/go/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users - [Credentials](https://docs.grantex.dev/sdks/go/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures - [Budgets](https://docs.grantex.dev/sdks/go/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history - [Events](https://docs.grantex.dev/sdks/go/events.md): Subscribe to real-time authorization events via Server-Sent Events - [Usage](https://docs.grantex.dev/sdks/go/usage.md): Track current UTC-date API usage metrics and view daily usage history - [Domains](https://docs.grantex.dev/sdks/go/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/go/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity - [Commerce V1](https://docs.grantex.dev/sdks/go/commerce.md): Use the Grantex Go SDK Commerce V1 client for OACP merchant discovery, catalog grounding, consent, payment, webhook, and ops flows. - [Vault](https://docs.grantex.dev/sdks/go/vault.md): Store, retrieve, and exchange encrypted service credentials through the Grantex credential vault - [Error Handling](https://docs.grantex.dev/sdks/go/errors.md): Error types and handling patterns - [AI Agent Framework Integrations](https://docs.grantex.dev/integrations/overview.md): Choose Grantex integrations for Hermes, OpenClaw, Agent Skills, OpenAI Agents, Anthropic, LangChain, CrewAI, Google ADK, AutoGen, MCP, and service frameworks. - [Service Provider Adapters](https://docs.grantex.dev/integrations/adapters.md): Pre-built integrations that translate Grantex grants into real API calls. - [Grantex Gateway](https://docs.grantex.dev/integrations/gateway.md): Zero-code reverse-proxy that enforces grant tokens in front of any API. - [MCP Authorization](https://docs.grantex.dev/integrations/mcp-auth.md): Install MCP Auth 4 with authenticated human consent, durable state, resource binding and issuer-side current authority. - [Trust Registry](https://docs.grantex.dev/integrations/registry.md): Public organization directory with DID identity and DNS ownership verification. - [Agent CLIs & Skills](https://docs.grantex.dev/integrations/agent-cli.md): Give Hermes, OpenClaw, and other shell-capable agents a portable Grantex skill bundle and a stable JSON CLI contract. - [Hermes Agent](https://docs.grantex.dev/integrations/hermes.md): Install Grantex Agent Skills into Hermes and operate delegated authorization through the JSON CLI. - [OpenClaw](https://docs.grantex.dev/integrations/openclaw.md): Install Grantex Agent Skills in an OpenClaw workspace and use the JSON CLI for delegated authorization. - [Express.js](https://docs.grantex.dev/integrations/express.md): Grant token verification and scope-based authorization middleware for Express.js. - [FastAPI](https://docs.grantex.dev/integrations/fastapi.md): Grant token verification and scope-based authorization for FastAPI using dependency injection. - [MCP Server](https://docs.grantex.dev/integrations/mcp.md): Use Grantex from Claude Desktop, Cursor, or Windsurf via the Model Context Protocol. - [LangChain](https://docs.grantex.dev/integrations/langchain.md): Scope-enforced tools and automatic audit logging for LangChain agents. - [Vercel AI SDK](https://docs.grantex.dev/integrations/vercel-ai.md): Scope-enforced tools and audit logging for Vercel AI SDK agents. - [AutoGen / OpenAI](https://docs.grantex.dev/integrations/autogen.md): Scope-enforced function calling and registry for OpenAI-style agents. - [CrewAI](https://docs.grantex.dev/integrations/crewai.md): Scope-enforced, audited agent tools for CrewAI. - [OpenAI Agents SDK](https://docs.grantex.dev/integrations/openai-agents.md): Scope-enforced FunctionTool wrappers for the OpenAI Agents SDK. - [Google ADK](https://docs.grantex.dev/integrations/google-adk.md): Scope-enforced plain function tools for Google Agent Development Kit. - [Anthropic SDK](https://docs.grantex.dev/integrations/anthropic.md): Scope-enforced tool use, registry, and audit logging for Claude models. - [Strands Agents SDK](https://docs.grantex.dev/integrations/strands.md): Scope-enforced tools for Strands Agents SDK in TypeScript and Python. - [Gemma 4 SDK](https://docs.grantex.dev/sdks/gemma.md): Complete API reference for @grantex/gemma — offline authorization for Gemma 4 on-device agents. TypeScript and Python. - [Gemma 4 (On-Device)](https://docs.grantex.dev/integrations/gemma.md): Offline authorization for Gemma 4 on-device AI agents — consent bundles, JWT verification, and tamper-evident audit logging without network calls. - [DPDP & GDPR Compliance](https://docs.grantex.dev/integrations/dpdp.md): DPDP Act 2023 and GDPR evidence tooling for AI agent deployments: consent records bound to grants, versioned notices, withdrawal, erasure, grievances, a breach register and exports. - [A2A Protocol Bridge (TypeScript)](https://docs.grantex.dev/integrations/a2a.md): Inject Grantex grant tokens into Google A2A agent-to-agent communication - [A2A Protocol Bridge (Python)](https://docs.grantex.dev/integrations/a2a-py.md): Inject Grantex grant tokens into Google A2A agent-to-agent communication from Python - [x402 Prepaid Wallets](https://docs.grantex.dev/integrations/x402.md): Assign one or more prepaid wallets to an AI agent and enforce principal-controlled spend policy through official x402 v2 payment messages. - [CLI](https://docs.grantex.dev/integrations/cli.md): Manage agents, grants, audit logs, and more from your terminal. - [grantex verify](https://docs.grantex.dev/cli/verify.md): Inspect any Grantex grant token from the command line. See scopes, expiry, delegation chain, and revocation status. Works offline — no account needed. - [grantex manifest](https://docs.grantex.dev/cli/manifest.md): Browse, generate, and validate tool manifests — define your own or use 53 pre-built ones. - [grantex enforce](https://docs.grantex.dev/cli/enforce.md): Dry-run scope enforcement from the command line. Test whether a grant token permits a specific tool call before deploying. - [Conformance Suite](https://docs.grantex.dev/integrations/conformance.md): Validate that your Grantex server implementation is spec-compliant with automated black-box testing. - [Conformance Status](https://docs.grantex.dev/integrations/conformance-results.md): How to obtain current, reproducible Grantex conformance results. - [API Reference](https://docs.grantex.dev/api-reference/introduction.md): Complete REST API reference for the Grantex Auth Service - [Health check](https://docs.grantex.dev/api-reference/system/health-check.md) - [Json web key set](https://docs.grantex.dev/api-reference/system/json-web-key-set.md) - [Developer dashboard](https://docs.grantex.dev/api-reference/system/developer-dashboard.md) - [Principal permissions dashboard](https://docs.grantex.dev/api-reference/system/principal-permissions-dashboard.md) - [Register a new developer account](https://docs.grantex.dev/api-reference/authentication/register-a-new-developer-account.md) - [Get current developer profile](https://docs.grantex.dev/api-reference/authentication/get-current-developer-profile.md) - [Rotate api key](https://docs.grantex.dev/api-reference/authentication/rotate-api-key.md) - [Send verification](https://docs.grantex.dev/api-reference/signup/send-verification.md) - [Verify token](https://docs.grantex.dev/api-reference/signup/verify-token.md) - [Register a new agent](https://docs.grantex.dev/api-reference/agents/register-a-new-agent.md) - [List all agents](https://docs.grantex.dev/api-reference/agents/list-all-agents.md) - [Get agent by id](https://docs.grantex.dev/api-reference/agents/get-agent-by-id.md) - [Update an agent](https://docs.grantex.dev/api-reference/agents/update-an-agent.md) - [Delete an agent](https://docs.grantex.dev/api-reference/agents/delete-an-agent.md) - [Create an authorization request](https://docs.grantex.dev/api-reference/authorization/create-an-authorization-request.md) - [Approve an authorization request](https://docs.grantex.dev/api-reference/authorization/approve-an-authorization-request.md) - [Deny an authorization request](https://docs.grantex.dev/api-reference/authorization/deny-an-authorization-request.md) - [Exchange authorization code for grant token](https://docs.grantex.dev/api-reference/tokens/exchange-authorization-code-for-grant-token.md) - [Refresh a grant token](https://docs.grantex.dev/api-reference/tokens/refresh-a-grant-token.md) - [Verify a grant token online](https://docs.grantex.dev/api-reference/tokens/verify-a-grant-token-online.md) - [Revoke a grant token](https://docs.grantex.dev/api-reference/tokens/revoke-a-grant-token.md) - [Stream](https://docs.grantex.dev/api-reference/events/stream.md) - [Websocket](https://docs.grantex.dev/api-reference/events/websocket.md) - [List grants](https://docs.grantex.dev/api-reference/grants/list-grants.md) - [Get grant by id](https://docs.grantex.dev/api-reference/grants/get-grant-by-id.md) - [Revoke a grant](https://docs.grantex.dev/api-reference/grants/revoke-a-grant.md) - [Verify a grant tokens revocation status](https://docs.grantex.dev/api-reference/grants/verify-a-grant-tokens-revocation-status.md) - [Delegate a grant to a sub agent](https://docs.grantex.dev/api-reference/grants/delegate-a-grant-to-a-sub-agent.md) - [Log an audit entry](https://docs.grantex.dev/api-reference/audit/log-an-audit-entry.md) - [List audit entries](https://docs.grantex.dev/api-reference/audit/list-audit-entries.md) - [Get audit entry by id](https://docs.grantex.dev/api-reference/audit/get-audit-entry-by-id.md) - [Create an access policy](https://docs.grantex.dev/api-reference/policies/create-an-access-policy.md) - [List access policies](https://docs.grantex.dev/api-reference/policies/list-access-policies.md) - [Get policy by id](https://docs.grantex.dev/api-reference/policies/get-policy-by-id.md) - [Update a policy](https://docs.grantex.dev/api-reference/policies/update-a-policy.md) - [Delete a policy](https://docs.grantex.dev/api-reference/policies/delete-a-policy.md) - [Sync policy bundle](https://docs.grantex.dev/api-reference/policies/sync-policy-bundle.md) - [List bundles](https://docs.grantex.dev/api-reference/policies/list-bundles.md) - [Active bundle](https://docs.grantex.dev/api-reference/policies/active-bundle.md) - [Sync webhook](https://docs.grantex.dev/api-reference/policies/sync-webhook.md) - [Register a webhook](https://docs.grantex.dev/api-reference/webhooks/register-a-webhook.md) - [List webhooks](https://docs.grantex.dev/api-reference/webhooks/list-webhooks.md) - [Delete a webhook](https://docs.grantex.dev/api-reference/webhooks/delete-a-webhook.md) - [Get current subscription](https://docs.grantex.dev/api-reference/billing/get-current-subscription.md) - [Create a stripe checkout session](https://docs.grantex.dev/api-reference/billing/create-a-stripe-checkout-session.md) - [Create a stripe billing portal session](https://docs.grantex.dev/api-reference/billing/create-a-stripe-billing-portal-session.md) - [Stripe webhook handler](https://docs.grantex.dev/api-reference/billing/stripe-webhook-handler.md) - [Run anomaly detection](https://docs.grantex.dev/api-reference/anomalies/run-anomaly-detection.md) - [Response policy](https://docs.grantex.dev/api-reference/anomalies/response-policy.md) - [List detected anomalies](https://docs.grantex.dev/api-reference/anomalies/list-detected-anomalies.md) - [Acknowledge an anomaly](https://docs.grantex.dev/api-reference/anomalies/acknowledge-an-anomaly.md) - [List alerts](https://docs.grantex.dev/api-reference/anomalies/list-alerts.md) - [Acknowledge alert](https://docs.grantex.dev/api-reference/anomalies/acknowledge-alert.md) - [Resolve alert](https://docs.grantex.dev/api-reference/anomalies/resolve-alert.md) - [Get metrics](https://docs.grantex.dev/api-reference/anomalies/get-metrics.md) - [List rules](https://docs.grantex.dev/api-reference/anomalies/list-rules.md) - [Create rule](https://docs.grantex.dev/api-reference/anomalies/create-rule.md) - [Delete rule](https://docs.grantex.dev/api-reference/anomalies/delete-rule.md) - [List channels](https://docs.grantex.dev/api-reference/anomalies/list-channels.md) - [Create channel](https://docs.grantex.dev/api-reference/anomalies/create-channel.md) - [Delete channel](https://docs.grantex.dev/api-reference/anomalies/delete-channel.md) - [Get compliance summary](https://docs.grantex.dev/api-reference/compliance/get-compliance-summary.md) - [Export grants for compliance](https://docs.grantex.dev/api-reference/compliance/export-grants-for-compliance.md) - [Export audit entries for compliance](https://docs.grantex.dev/api-reference/compliance/export-audit-entries-for-compliance.md) - [Generate compliance evidence pack](https://docs.grantex.dev/api-reference/compliance/generate-compliance-evidence-pack.md) - [Create a scim provisioning token](https://docs.grantex.dev/api-reference/scim/create-a-scim-provisioning-token.md) - [List scim tokens](https://docs.grantex.dev/api-reference/scim/list-scim-tokens.md) - [Delete a scim token](https://docs.grantex.dev/api-reference/scim/delete-a-scim-token.md) - [Scim service provider configuration](https://docs.grantex.dev/api-reference/scim/scim-service-provider-configuration.md) - [List scim users](https://docs.grantex.dev/api-reference/scim/list-scim-users.md) - [Create a scim user](https://docs.grantex.dev/api-reference/scim/create-a-scim-user.md) - [Get scim user by id](https://docs.grantex.dev/api-reference/scim/get-scim-user-by-id.md) - [Replace a scim user](https://docs.grantex.dev/api-reference/scim/replace-a-scim-user.md) - [Patch a scim user](https://docs.grantex.dev/api-reference/scim/patch-a-scim-user.md) - [Delete a scim user](https://docs.grantex.dev/api-reference/scim/delete-a-scim-user.md) - [Configure oidc sso](https://docs.grantex.dev/api-reference/sso/configure-oidc-sso.md) - [Get sso configuration](https://docs.grantex.dev/api-reference/sso/get-sso-configuration.md) - [Remove sso configuration](https://docs.grantex.dev/api-reference/sso/remove-sso-configuration.md) - [Initiate sso login](https://docs.grantex.dev/api-reference/sso/initiate-sso-login.md) - [Sso callback](https://docs.grantex.dev/api-reference/sso/sso-callback.md) - [Create sso connection](https://docs.grantex.dev/api-reference/sso/create-sso-connection.md) - [List sso connections](https://docs.grantex.dev/api-reference/sso/list-sso-connections.md) - [Update sso connection](https://docs.grantex.dev/api-reference/sso/update-sso-connection.md) - [Delete sso connection](https://docs.grantex.dev/api-reference/sso/delete-sso-connection.md) - [Test sso connection](https://docs.grantex.dev/api-reference/sso/test-sso-connection.md) - [Set sso enforcement](https://docs.grantex.dev/api-reference/sso/set-sso-enforcement.md) - [List sso sessions](https://docs.grantex.dev/api-reference/sso/list-sso-sessions.md) - [Revoke sso session](https://docs.grantex.dev/api-reference/sso/revoke-sso-session.md) - [Oidc callback](https://docs.grantex.dev/api-reference/sso/oidc-callback.md) - [Saml callback](https://docs.grantex.dev/api-reference/sso/saml-callback.md) - [LDAP Callback](https://docs.grantex.dev/api-reference/sso/ldap-callback.md): Authenticate with the LDAP direct-bind preview and create an SSO session; directory, attribute, and group search are not performed. - [Create principal session](https://docs.grantex.dev/api-reference/principal-sessions/create-principal-session.md) - [List principal grants](https://docs.grantex.dev/api-reference/principal-sessions/list-principal-grants.md) - [Get principal audit](https://docs.grantex.dev/api-reference/principal-sessions/get-principal-audit.md) - [Revoke principal grant](https://docs.grantex.dev/api-reference/principal-sessions/revoke-principal-grant.md) - [Consent ui page](https://docs.grantex.dev/api-reference/consent/consent-ui-page.md) - [Get consent request details](https://docs.grantex.dev/api-reference/consent/get-consent-request-details.md) - [Approve consent end user action](https://docs.grantex.dev/api-reference/consent/approve-consent-end-user-action.md) - [Deny consent end user action](https://docs.grantex.dev/api-reference/consent/deny-consent-end-user-action.md) - [Generate registration options](https://docs.grantex.dev/api-reference/webauthn/generate-registration-options.md) - [Create enrollment session](https://docs.grantex.dev/api-reference/webauthn/create-enrollment-session.md) - [Hosted enrollment](https://docs.grantex.dev/api-reference/webauthn/hosted-enrollment.md) - [Verify registration](https://docs.grantex.dev/api-reference/webauthn/verify-registration.md) - [List credentials](https://docs.grantex.dev/api-reference/webauthn/list-credentials.md) - [Delete credential](https://docs.grantex.dev/api-reference/webauthn/delete-credential.md) - [Generate assertion options](https://docs.grantex.dev/api-reference/webauthn/generate-assertion-options.md) - [Verify assertion](https://docs.grantex.dev/api-reference/webauthn/verify-assertion.md) - [Allocate Budget](https://docs.grantex.dev/api-reference/budgets/allocate.md): Create a budget allocation for a grant, setting a spending cap for the agent. - [Debit Budget](https://docs.grantex.dev/api-reference/budgets/debit.md): Debit an amount from a grant's budget allocation. Returns 402 if the budget is insufficient. - [Get Budget Balance](https://docs.grantex.dev/api-reference/budgets/balance.md): Retrieve the current budget balance for a grant. - [List Budget Transactions](https://docs.grantex.dev/api-reference/budgets/transactions.md): Retrieve paginated transaction history for a grant's budget. - [List Budget Allocations](https://docs.grantex.dev/api-reference/budgets/allocations.md): List all budget allocations for the authenticated developer. - [Register Custom Domain](https://docs.grantex.dev/api-reference/domains/create.md): Register a custom domain on your Grantex account. Returns a token to add as a DNS TXT record. Requires Enterprise plan. Runtime traffic routing on your domain is on the roadmap; today endpoints still resolve under *.grantex.dev. - [List Custom Domains](https://docs.grantex.dev/api-reference/domains/list.md): List all custom domains registered by the authenticated developer. - [Verify Domain DNS](https://docs.grantex.dev/api-reference/domains/verify.md): Trigger DNS verification for a registered custom domain. - [Delete Custom Domain](https://docs.grantex.dev/api-reference/domains/delete.md): Remove a custom domain registration. - [Get Current Usage](https://docs.grantex.dev/api-reference/usage/current.md): Retrieve usage metrics for the current UTC date. - [Get Usage History](https://docs.grantex.dev/api-reference/usage/history.md): Retrieve daily usage breakdown over a specified number of days. - [Store Vault Credential](https://docs.grantex.dev/api-reference/vault/store.md): Store an encrypted service credential in the Grantex Vault for a principal. - [List Vault Credentials](https://docs.grantex.dev/api-reference/vault/list.md): List vault credential metadata for the authenticated developer. Does not return raw tokens. - [Get Vault Credential](https://docs.grantex.dev/api-reference/vault/get.md): Retrieve metadata for a specific vault credential. Does not return raw tokens. - [Delete Vault Credential](https://docs.grantex.dev/api-reference/vault/delete.md): Permanently delete a vault credential. - [Exchange Grant Token for Service Credential](https://docs.grantex.dev/api-reference/vault/exchange.md): Exchange a valid Grantex grant token for a stored upstream service credential. - [Resolve a Credential Reference](https://docs.grantex.dev/api-reference/vault/resolve.md): Redeem a short-lived credential reference for the stored upstream credential; for the relying party that injects credentials on the agent's behalf. - [Consent Bundles API](https://docs.grantex.dev/api-reference/consent-bundles.md): API reference for offline consent bundle endpoints: create, list, revoke, and check revocation status. - [Offline Sync API](https://docs.grantex.dev/api-reference/offline-sync.md): API reference for syncing offline audit log entries to the Grantex cloud. - [Get credential](https://docs.grantex.dev/api-reference/credentials/get-credential.md) - [List credentials](https://docs.grantex.dev/api-reference/credentials/list-credentials.md) - [Verify credential](https://docs.grantex.dev/api-reference/credentials/verify-credential.md) - [Status list](https://docs.grantex.dev/api-reference/credentials/status-list.md) - [Create Consent Record](https://docs.grantex.dev/api-reference/dpdp/create-consent-record.md): Record a data principal's consent against an active grant and a versioned consent notice, with a signed proof the Data Fiduciary can keep as evidence (DPDP Act s.6(10)). - [Get Consent Record](https://docs.grantex.dev/api-reference/dpdp/get-consent-record.md): Retrieve a single DPDP consent record by ID. A developer read has no side effects. - [List Consent Records](https://docs.grantex.dev/api-reference/dpdp/list-consent-records.md): List all DPDP consent records for the developer, with optional filtering by data principal. - [Withdraw Consent](https://docs.grantex.dev/api-reference/dpdp/withdraw-consent.md): Withdraw a DPDP consent record. Optionally revokes the underlying grant, and asks the developer to delete processed data. - [List Principal Records](https://docs.grantex.dev/api-reference/dpdp/list-principal-records.md): List the consent records held about one data principal. Supports a response to an access request under DPDP Act s.11. - [Request Erasure](https://docs.grantex.dev/api-reference/dpdp/request-erasure.md): Act on a data principal's erasure request (DPDP Act s.12): revokes active grants, marks consent records erased, and reports what is retained and why; with expanded erasure enabled it also redacts grievances and deletes stored exports. - [Get Erasure Request](https://docs.grantex.dev/api-reference/dpdp/get-erasure-request.md): Read a completed DPDP erasure request: what was erased, what was revoked, and what was retained and why. - [Create Consent Notice](https://docs.grantex.dev/api-reference/dpdp/create-consent-notice.md): Register a version of a consent notice (DPDP Act s.5, DPDP Rules 2025 r.3). Consent records name the version shown; its content hash is bound into the record's signed proof. - [List Consent Notices](https://docs.grantex.dev/api-reference/dpdp/list-consent-notices.md): List the developer's DPDP consent notice versions, newest first, one page at a time. - [Get Consent Notice](https://docs.grantex.dev/api-reference/dpdp/get-consent-notice.md): Read every version of one DPDP consent notice, with its content, newest first. - [Consent Notice Content](https://docs.grantex.dev/api-reference/dpdp/consent-notice-content.md): The structured fields of a DPDP consent notice, the r.3 validation block, and the languages a notice may use. - [File Grievance](https://docs.grantex.dev/api-reference/dpdp/file-grievance.md): Record a grievance from a data principal, with the response period the Data Fiduciary publishes (DPDP Act s.13; DPDP Rules 2025 r.14(3): at most 90 days). - [List Grievances](https://docs.grantex.dev/api-reference/dpdp/list-grievances.md): List the developer's DPDP grievances, newest first, filtered by status or data principal. - [Get Grievance](https://docs.grantex.dev/api-reference/dpdp/get-grievance.md): Retrieve the status and details of a DPDP grievance by ID. - [Update Grievance](https://docs.grantex.dev/api-reference/dpdp/update-grievance.md): Move a DPDP grievance through review: submitted to in_review, then resolved or rejected with a resolution. - [Record Breach](https://docs.grantex.dev/api-reference/dpdp/record-breach.md): Record a personal data breach in the DPDP breach register, with the Board and Data Principal deadlines computed. - [List Breaches](https://docs.grantex.dev/api-reference/dpdp/list-breaches.md): List the breaches in the DPDP breach register, newest first, optionally by status. - [Get Breach](https://docs.grantex.dev/api-reference/dpdp/get-breach.md): Read one breach from the DPDP breach register, with its deadlines and the principal intimations recorded against it. - [Update Breach](https://docs.grantex.dev/api-reference/dpdp/update-breach.md): Record the detailed report to the Board, the Board intimation times, an extension, and move a breach through its statuses. - [Record Principal Intimation](https://docs.grantex.dev/api-reference/dpdp/record-breach-intimation.md): Record that the Data Fiduciary informed affected Data Principals of a breach: who, by which channel, when, and with which content. - [Create Export](https://docs.grantex.dev/api-reference/dpdp/create-export.md): Generate a compliance export: a DPDP audit, a GDPR Article 15 access report for one person, or an EU AI Act evidence pack. - [EU AI Act Evidence Pack](https://docs.grantex.dev/api-reference/dpdp/eu-ai-act-evidence.md): An export that maps what Grantex records to the record-keeping, human oversight, deployer, transparency and incident articles of the EU AI Act. - [Get Export](https://docs.grantex.dev/api-reference/dpdp/get-export.md): Retrieve a previously generated compliance export by ID. - [Did document](https://docs.grantex.dev/api-reference/did/did-document.md) - [Protocol Specification](https://docs.grantex.dev/protocol/specification.md): Grantex Protocol Specification v1.0 — the full normative document. - [Changelog and Release History](https://docs.grantex.dev/protocol/changelog.md): How to find current Grantex releases, package compatibility, and the canonical project changelog. - [Security Policy](https://docs.grantex.dev/security/overview.md): Supported versions, vulnerability reporting, and coordinated disclosure. - [Security Audit Report](https://docs.grantex.dev/security/audit-report.md): Third-party security assessment by Vestige Security Labs (February 2026). - [SOC 2 Readiness Control Mapping](https://docs.grantex.dev/security/soc2-report.md): Internal SOC 2 readiness control mapping for the Grantex Delegated Authorization Platform. - [Contributing](https://docs.grantex.dev/community/contributing.md): How to contribute to the Grantex project. - [IETF Internet-Draft](https://docs.grantex.dev/community/ietf-draft.md): Delegated Agent Authorization Protocol (DAAP) — active individual Internet-Draft with revision 02 published and revision 03 under review. - [Draft NIST NCCoE Public Comment](https://docs.grantex.dev/community/nist-comment.md): Grantex response to NIST NCCoE AI challenge areas — mapping DAAP to the AI Risk Management Framework. - [OpenID AuthZEN Mapping](https://docs.grantex.dev/community/authzen-mapping.md): How Grantex maps to the OpenID AuthZEN Authorization API for interoperable policy evaluation. - [How A Shopify Merchant Becomes An Agentic Commerce Seller](https://docs.grantex.dev/blog/oacp-shopify-merchant-agentic-commerce-seller.md): The Grantex authority view of Shopify onboarding through AgenticOrg and OACP artifacts. - [Merchant Self-Service Config Without Moving Commerce Truth Into Grantex](https://docs.grantex.dev/blog/oacp-merchant-self-service-config.md): How AgenticOrg lets merchants configure sources, channels, provider rails, public publishing, and Offline POS while Grantex remains OACP authority. - [Why OACP Keeps Buyer Agents Honest](https://docs.grantex.dev/blog/oacp-keeps-buyer-agents-honest.md): Why source, freshness, revocation, and non-enablement fields keep buyer agents from inventing commerce facts. - [How ChatGPT, Claude, Gemini, Perplexity, WhatsApp, And Telegram Can Shop Through Seller Agents](https://docs.grantex.dev/blog/oacp-buyer-surfaces-chatgpt-claude-gemini-perplexity-whatsapp-telegram.md): The buyer-surface bridge model for OACP-backed AgenticOrg seller agents. - [How OACP Maps To Schema.org, UCP, ACP, AP2, A2A, And MCP](https://docs.grantex.dev/blog/oacp-maps-to-protocols.md): A compatibility-mapping guide for protocol partners. - [Why Grantex Is Not A Transaction Toll Booth](https://docs.grantex.dev/blog/grantex-not-transaction-toll-booth.md): Why OACP authority signs artifacts without relaying every buyer and seller interaction. - [How Pine Labs Plural/P3P Mandate Capability Fits Into Agentic Commerce](https://docs.grantex.dev/blog/pine-labs-plural-p3p-oacp.md): The provider-owned mandate capability boundary in the OACP model. - [Source, Freshness, And Trust In AI Commerce](https://docs.grantex.dev/blog/source-freshness-trust-ai-commerce.md): How OACP makes source and freshness visible to buyer agents. - [The Buyer Journey From Question To Prepared Purchase Handoff](https://docs.grantex.dev/blog/buyer-journey-prepared-purchase-handoff.md): How OACP moves from discovery to prepared handoff without faking execution. - [Shopify, Grantex Commerce, And OACP: Current Boundary](https://docs.grantex.dev/blog/shopify-oacp-commerce-live-flow.md): Separates the Grantex Commerce payment-control pilot from the blocked AgenticOrg C6Z OACP runtime artifact vertical. - [Why OACP Commerce Needs A Readiness Gate](https://docs.grantex.dev/blog/commerce-live-readiness-gate.md): How Grantex separates OACP authority evidence from live payment, provider, POS, and merchant execution. - [DPDP Act 2023 and AI Agents: What Your Engineering Team Must Know](https://docs.grantex.dev/blog/dpdp-act-ai-agents.md): India's DPDP Act creates specific obligations for AI agent deployments. Here's what engineering teams need to implement. - [4 Agent Security Breaches That Should Change How You Think About API Keys](https://docs.grantex.dev/blog/agent-security-breaches-2025-2026.md): Shai-Hulud, SANDWORM_MODE, OpenClaw, and CVE-2026-21852 — the 2025-2026 incidents that proved AI agents need their own authorization layer, not shared secrets. - [OWASP Agentic Top 10: What It Means for Your AI Security Stack](https://docs.grantex.dev/blog/owasp-agentic-top-10-compliance.md): OWASP published the Agentic Security Top 10 in December 2025. The EU AI Act applies in phases, and NIST AI RMF is active now. Here is how the controls map to Grantex. - [From Copilot to Autonomous: Why Authorization Must Evolve with AI](https://docs.grantex.dev/blog/from-copilot-to-autonomous-agents.md): AI went from autocomplete to autonomous in three years. Authorization did not keep up. Here is why the shift from assisted to agentic AI demands a new security model. - [Agent Identity for Machine Payments: Why MPP Needs a Passport Layer](https://docs.grantex.dev/blog/mpp-agent-identity.md): Grantex adds verifiable agent and principal credential context that merchants can validate alongside independent payment and risk controls. - [Introducing Grantex: OAuth 2.0 for AI Agents](https://docs.grantex.dev/blog/introducing-grantex.md): Grantex is an open delegated authorization protocol that brings human-approved, scoped, revocable permissions to AI agents. - [Why AI Agents Need Their Own Authorization Protocol](https://docs.grantex.dev/blog/why-ai-agents-need-authorization.md): OAuth 2.0 was built for human users. AI agents have fundamentally different requirements -- here's why they need a purpose-built protocol. - [AI Agent Authorization Guide for 2026: Scopes, Consent, and Revocation](https://docs.grantex.dev/blog/ai-agent-authorization-guide.md): Implement AI agent authorization with scoped grants, consent, JWT verification, current revocation checks, and TypeScript and Python examples. - [How to Add Permissions to LangChain Agent Tools](https://docs.grantex.dev/blog/langchain-agent-permissions.md): Add scoped permissions to configured LangChain tools with verified Grantex JWTs, manifest enforcement, and optional grant-aware audit callbacks. - [MCP Server Authorization with OAuth 2.1 and Grantex](https://docs.grantex.dev/blog/mcp-server-oauth-authentication.md): Current MCP HTTP authorization, the OAuth 2.1 draft profile, and safe evaluation limits for @grantex/mcp-auth 2.0.2. - [Grantex v0.1: What's Included](https://docs.grantex.dev/blog/grantex-v0-1-whats-included.md): A complete tour of everything shipping in the Grantex v0.1 release -- SDKs, integrations, CLI, enterprise features, and more. - [Grantex v2.2: Policy Engines, A2A, and the Managed Cloud](https://docs.grantex.dev/blog/grantex-v2-2.md): v2.2 brings OPA and Cedar policy backends, Google A2A agent-to-agent bridging, a managed cloud offering, and SDK 0.2.0 across all three languages. - [Gemma 4 Just Shipped Offline AI Agents. Here's How to Secure Them.](https://docs.grantex.dev/blog/gemma-4-offline-agents-security.md): Gemma 4 enables offline agentic workflows on-device. But offline agents with no auth story are a security gap. Here's how @grantex/gemma closes it. ## OpenAPI Specs - [grantex-commerce-v1.openapi](/api/grantex-commerce-v1.openapi.yaml) - [openapi](/openapi.yaml) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.