Skip to main content

Current releases

The current primary SDKs are TypeScript 0.8.2, Python 0.7.2, and Go v0.4.3. MCP Auth is 4.1.0; the independently versioned CLI remains 0.4.2. The October 4 release added DPDP clients and republished the changed gateway, MCP, MPP, Gemma, conformance, and Python framework integrations. See the compatibility matrix for every package and the migration guide for runtime requirements, revocation, trusted amounts, and integration limits. Latest registry publication verified: October 4, 2026. The npm archives match the validated CI tarballs, the PyPI wheels and sdists match the validated CI distributions, and the public Go proxy resolves the reviewed merge commit. A clean public-index Python SDK install and downloaded Go-module tests passed on the workstation. This publication is not a new hosted-service deployment; hosted evidence retains its original verification dates. Server feature availability is deployment-specific; confirm the rollout with the authenticated policy endpoint and an enrollment test on the public origin. The Grantex-hosted service enabled portable WebAuthn evidence on September 27, 2026 and passed its production consent, delegation, and revocation E2E. This does not change the default-off setting for self-hosted installations. The hosted service also has PASSKEY_ENROLLMENT_ENABLED=true with the production origin and RP ID; SDK installation alone does not enable either feature. TypeScript @grantex/sdk@0.8.2 and x402 @grantex/x402@0.4.1 are published on npm. Python grantex==0.7.2 is published on PyPI and the Go SDK v0.4.3 resolves through the public Go proxy. Each exact artifact was verified against its registry before this page was updated. TypeScript 0.8.2, Python 0.7.2, and Go v0.4.3 include hosted passkey enrollment and the account irregularity response policy. Their server routes are default-off for self-hosted deployments (PASSKEY_ENROLLMENT_ENABLED and IRREGULARITY_RESPONSE_POLICY_ENABLED). The Grantex-hosted service has both enabled. A deployed server may enable these flags independently of SDK publication. Portable assertion evidence requires PORTABLE_WEBAUTHN_EVIDENCE_ENABLED, IRREGULARITY_CASCADE_REVOCATION_ENABLED, and PORTABLE_WEBAUTHN_EVIDENCE_STATUS_CHECK_ENABLED on the server. Keep the latter two safety flags enabled if issuance is rolled back. The registry versions listed here expose typed portable-evidence references and updated VC attestations. A custom assertion UI still uses the REST endpoints directly. For principal identity binding, one-use links, and the live-consent ceremony, see FIDO2 / WebAuthn. The released SDKs issue hosted enrollment links; custom assertion UIs use the REST endpoints directly. Grantex packages are versioned independently. There is no single version number that represents every SDK, integration, service, and protocol artifact in this repository.
TypeScript 0.8.2, Python 0.7.2, Go v0.4.3, and x402 0.4.1 are published and registry verified. Installing any SDK does not provision external custody, principal notification delivery, or merchant idempotency storage; see Prepaid Wallet Production Readiness.
The SDK versions differ because each language package is released on its own schedule. A newer package version does not imply a newer protocol or API contract version.

Published and source-only changes

On October 4, 2026, TypeScript 0.8.2, Python 0.7.2, Go v0.4.3, DPDP 0.2.0, MCP Auth 4.1.0, gateway 0.3.0, MCP 0.1.11, MPP 0.1.3, Gemma TypeScript 0.1.2, and conformance 0.1.9 were published. Python A2A 0.1.6, ADK 0.1.8, CrewAI 0.1.9, FastAPI 0.1.7, Gemma 0.1.2, OpenAI Agents 0.1.8, and Strands 0.2.2 were also published. The release verification job passed with Postgres and Redis, but registry-side trusted-publisher records remain unconfigured; publication used the maintainer’s authenticated CLI and browser approval. The local workstation Docker daemon was unavailable for this release, so no new Docker E2E claim is made. See the October 4 registry audit for package-by-package versions, test evidence, and the remaining publishing automation setup. On September 29, 2026, TypeScript 0.8.1 and MCP Auth 4.0.0 were published from the audited release checkout. Registry hashes match the tested archives, and a fresh Docker consumer installed the exact registry versions and passed the human-consent, token exchange, refresh, authority, revocation and outage checks. MCP Auth also passed 396 unit, 63 database/restart and 9 Chromium tests, with two existing unit-test skips. See the publication receipt. This was package publication, not a hosted-service deployment. At that date, Python 0.7.1, the audited Go changes, and changed execution integrations were still unpublished source candidates; the October 4 releases above close that specific publication gap. See execution authority. On September 28, 2026, TypeScript 0.7.1, Python 0.6.1, and Go v0.4.2 were built and tested from merged main snapshot a919ea8a. Their registry artifacts were independently installed or downloaded and checked against the release artifacts. These updates expose typed portable WebAuthn grant evidence and VC attestations; they do not alter the server-side enrollment or evidence rollout flags. The primary-SDK release workflow verified and packed the artifacts, but registry publication required the maintainer’s authenticated workstation because trusted-publisher setup is not yet complete. On September 27, 2026, TypeScript 0.7.1 and x402 0.4.1 were installed together in a clean npm consumer. Their registry SHA-512 integrity values exactly match the verified main-branch tarballs, and the passkey, irregularity policy, and x402 public exports were present. Python 0.6.0 was installed from the public PyPI index in a clean environment. Its published wheel and sdist SHA-256 values match the verified main-branch release artifacts. Go v0.4.1 was tagged from the synced, tested SDK source; the public Go proxy resolved the tag and the downloaded module’s full test suite passed. These packages include hosted passkey enrollment and account irregularity response policy clients. Neither SDK install enables the default-off server flags. The release workflow verified the artifacts but could not publish them automatically because the npm and PyPI trusted-publisher records and Go release token are not configured. Python was uploaded with the maintainer’s authenticated Twine CLI, the npm packages with the maintainer’s CLI plus browser write approval, and Go was tagged from the tested public SDK repository. Automated publication remains an operator setup task; it must not be inferred from the verification job. The September 7 dependency integration updates repository test tooling to Vitest 5 and the auth service to SimpleWebAuthn 14. Use Node.js 24 LTS when building or testing this checkout. These maintenance changes do not publish new SDK versions; the registry versions above remain authoritative. Python 0.5.1 was published on September 15, 2026. It is a patch release: enforce() applies the tightest budget cap and denies malformed, negative, or non-finite caps and amounts; the FastAPI enforcer reads the Authorization header; grant-token verification caches the JWKS and runs off the event loop; resource ids are percent-encoded; single-use authorization codes are never retried; and event streams bound connect time. The PyPI wheel and sdist hashes match the tested artifacts, and the installed PyPI wheel passed all 623 tests in a clean environment. Python 0.5.0 and Go v0.3.0 were published on September 7, 2026. Both add EVM payment responses and authenticated principal/agent reconciliation and retain bounded refresh recovery. Full tests passed against a clean PyPI wheel and the public Go module, including Go race tests. Neither language adds an automatic x402 HTTP payment-and-retry wrapper. TypeScript 0.6.0 and x402 0.4.1 were published on September 7, 2026. Both registry integrity hashes match the tested tarballs. A clean npm install passed public-export, license/notice, Base safety, and authenticated reconciliation checks with zero reported consumer vulnerabilities. The x402 adapter provides opt-in request-bound Base USDC 402/sign/retry. See Base USDC Custody for the custody and RPC prerequisites.
As of August 10, 2026, published @grantex/cli@0.3.0 includes the Hermes, OpenClaw, and portable Agent Skills installer. Repository source on main includes corrected Go Agent/Audit read/write contracts and layered prepaid wallet clients across TypeScript, Python, and Go. TypeScript 0.7.1, Python 0.6.0, and Go v0.4.1 include matching bounded refresh-recovery behavior. Standard developer API-key plan throughput and custom-auth quotas remain separate from SDK publication.

Which Grantex package should I use?

  • Hermes, OpenClaw, or another shell-capable agent: use published @grantex/cli@0.4.2; install its bundled skills with grantex agent install. No agent-specific SDK is required.
  • TypeScript application: use npm-verified @grantex/sdk@0.8.2 for hosted passkey enrollment, account irregularity response policy, bounded refresh recovery, layered prepaid-wallet governance, and OAuth Agent Grants.
  • x402 prepaid-wallet application: use published @grantex/x402@0.4.1 with published @grantex/sdk@0.8.2; keep external custody disabled until an operator adapter passes review.
  • Python application: use PyPI-verified grantex==0.7.2 for hosted passkey enrollment, account-level irregularity response policy, bounded refresh recovery, layered prepaid-wallet governance, and fail-closed enforce() budget checks.
  • Go application: use public-proxy-verified github.com/mishrasanjeev/grantex-go@v0.4.3 for hosted passkey enrollment, account-level irregularity response policy, bounded refresh recovery, corrected Agent/Audit contracts, and layered prepaid-wallet governance.
  • MCP HTTP transport authorization: use an established MCP-compatible authorization server and maintained MCP SDK that implement the current MCP authorization specification.
  • Agent-specific MCP tool enforcement: configure MCP Auth 4.1 durable state, a required authenticated human-principal resolver, resource binding and trusted current-grant verification. Host login and WebAuthn remain separate responsibilities.
  • Current revocation: local JWT verification is insufficient by itself; perform an online state check or synchronize revocation data.
  • AgenticOrg governed cases: see the integration boundary; the last verified AgenticOrg integration does not wire token-level case purpose or per-case caps, regardless of the newer published Python package.

Known limitations in the current published artifacts

TypeScript 0.8.2 and Python 0.7.2: enforce() binds the expected audience, denies capped calls without trusted amounts, and checks current revocation online by default. Configure the service audience and agent’s resource servers, and keep the status/feed service operational. Plain token verification is still not current-state enforcement. Legacy aliases remain enabled unless explicitly disabled. See migration.
MCP Auth 4.1.0: configure durable shared storage, authenticated human-principal resolution, resource binding and trusted current-grant verification. The host must provide login; rendered consent does not replace passkeys. Memory storage and explicitly disabled current-grant checks remain evaluation-only. Version 2.0.2’s six limitations are preserved in its historical guide, not attributed to 4.1.0.

Reproducible installation

Pin exact versions in applications, examples, CI, and deployment manifests:
Unpinned npm install, pip install, and go get commands resolve according to their registries and module proxy. Use the pinned commands above when the build must be repeatable.

How to read release information

Upgrade checklist

  1. Read the package-specific notes in the compatibility matrix and changelog.
  2. Confirm the required Node.js, Python, or Go toolchain version.
  3. Update the exact dependency version and regenerate the relevant lockfile.
  4. Run your authorization, token-verification, scope-enforcement, and revocation tests before deployment.
  5. For self-hosted environments, verify the API contract used by your service; an SDK-only patch does not upgrade the service automatically.
Do not infer publication from a repository manifest or marketing page alone. Confirm the exact artifact on its public registry before promoting a release.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on October 4, 2026