> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Release Status

> Choose the current Grantex CLI, TypeScript, Python, Go, or MCP package with exact versions, runtime requirements, limitations, and reproducible install commands.

## Current releases

The current primary SDKs are TypeScript `0.8.2`, Python `0.7.2`, and Go
`v0.4.3`. MCP Auth is `4.1.0`; the independently versioned CLI remains
`0.4.2`. The October 4 release added DPDP clients and republished the changed
gateway, MCP, MPP, Gemma, conformance, and Python framework integrations.
See [the compatibility matrix](https://github.com/mishrasanjeev/grantex/blob/main/COMPATIBILITY.md)
for every package and [the migration guide](/migration-enforcement) for
runtime requirements, revocation, trusted amounts, and integration limits.

Latest registry publication verified: **October 4, 2026**. The npm archives
match the validated CI tarballs, the PyPI wheels and sdists match the validated
CI distributions, and the public Go proxy resolves the reviewed merge commit.
A clean public-index Python SDK install and downloaded Go-module tests passed
on the workstation. This publication is not a new hosted-service deployment;
hosted evidence retains its original verification dates.

Server feature availability is deployment-specific; confirm the rollout with
the authenticated policy endpoint and an enrollment test on the public origin.
The Grantex-hosted service enabled portable WebAuthn evidence on September 27,
2026 and passed its production consent, delegation, and revocation E2E. This
does not change the default-off setting for self-hosted installations. The
hosted service also has `PASSKEY_ENROLLMENT_ENABLED=true` with the production
origin and RP ID; SDK installation alone does not enable either feature.

TypeScript `@grantex/sdk@0.8.2` and x402 `@grantex/x402@0.4.1` are published
on npm. Python `grantex==0.7.2` is published on PyPI and the Go SDK `v0.4.3`
resolves through the public Go proxy. Each exact artifact was verified against
its registry before this page was updated.

TypeScript `0.8.2`, Python `0.7.2`, and Go `v0.4.3` include hosted passkey
enrollment and the account irregularity response policy. Their server routes are default-off
for self-hosted deployments (`PASSKEY_ENROLLMENT_ENABLED` and
`IRREGULARITY_RESPONSE_POLICY_ENABLED`). The Grantex-hosted service has both
enabled. A deployed server may enable these flags independently of SDK publication.
Portable assertion evidence requires `PORTABLE_WEBAUTHN_EVIDENCE_ENABLED`,
`IRREGULARITY_CASCADE_REVOCATION_ENABLED`, and
`PORTABLE_WEBAUTHN_EVIDENCE_STATUS_CHECK_ENABLED` on the server. Keep the latter
two safety flags enabled if issuance is rolled back. The registry versions
listed here expose typed portable-evidence references and updated VC
attestations. A custom assertion UI still uses the REST endpoints directly.
For principal identity binding, one-use links, and the live-consent ceremony,
see [FIDO2 / WebAuthn](/features/fido-webauthn). The released SDKs issue hosted
enrollment links; custom assertion UIs use the REST endpoints directly.

Grantex packages are versioned independently. There is no single version number
that represents every SDK, integration, service, and protocol artifact in this
repository.

| Surface | Release | Verification | Runtime requirement |
| - | - | - | - |
| CLI | `@grantex/cli@0.4.2` | Registry integrity and clean install | Node.js 22.12+; ESM |
| TypeScript SDK | `@grantex/sdk@0.8.2` | CI tarball and npm integrity match; source tests passed | Node.js 22.12+; ESM |
| Python SDK | `grantex==0.7.2` | CI wheel/sdist and PyPI hashes match; clean public-index install passed | Python 3.9+ |
| MCP Auth | `@grantex/mcp-auth@4.1.0` | CI tarball and npm integrity match; release tests passed | Node.js 22.12+; ESM |
| Gateway | `@grantex/gateway@0.3.0` | CI tarball and npm integrity match; release tests passed | Node.js 22.12+; SDK 0.8+ |
| Adapters | `@grantex/adapters@0.2.1` | Registry integrity and installed adapter invocation | Node.js 22.12+; SDK 0.8+ |
| Strands TypeScript | `@grantex/strands@0.2.1` | Registry integrity and installed tool invocation | Node.js 22.12+; SDK 0.8+ |
| Strands Python | `grantex-strands==0.2.2` | CI wheel/sdist and PyPI hashes match | Python 3.11+; grantex 0.7+ |
| x402 | `@grantex/x402@0.4.1` | Unchanged, compatibility-tested; custody remains external | Node.js 20+ standalone; 22.12+ with SDK 0.8 |
| Go SDK | `github.com/mishrasanjeev/grantex-go@v0.4.3` | Public proxy and downloaded-module tests/vet passed | Go 1.26.1+ |
| OpenAPI | `0.5.0` | Repository contract, independently versioned | Independent of SDK versions |
| Terraform provider | Source only | Public registry returned 404 on September 7, 2026; [local evaluation](/guides/terraform) | Provider module toolchain |

<Note>
  TypeScript `0.8.2`, Python `0.7.2`, Go `v0.4.3`, and x402 `0.4.1` are
  published and registry verified. Installing any SDK does not provision external
  custody, principal notification delivery, or merchant idempotency storage; see
  [Prepaid Wallet Production Readiness](/guides/prepaid-wallet-production).
</Note>

<Info>
  The SDK versions differ because each language package is released on its
  own schedule. A newer package version does not imply a newer protocol or API
  contract version.
</Info>

## Published and source-only changes

On October 4, 2026, TypeScript `0.8.2`, Python `0.7.2`, Go `v0.4.3`,
DPDP `0.2.0`, MCP Auth `4.1.0`, gateway `0.3.0`, MCP `0.1.11`,
MPP `0.1.3`, Gemma TypeScript `0.1.2`, and conformance `0.1.9`
were published. Python A2A `0.1.6`, ADK `0.1.8`, CrewAI `0.1.9`,
FastAPI `0.1.7`, Gemma `0.1.2`, OpenAI Agents `0.1.8`, and Strands
`0.2.2` were also published. The release verification job passed with
Postgres and Redis, but registry-side trusted-publisher records remain
unconfigured; publication used the maintainer's authenticated CLI and
browser approval. The local workstation Docker daemon was unavailable for
this release, so no new Docker E2E claim is made. See the
[October 4 registry audit](https://github.com/mishrasanjeev/grantex/blob/main/docs/reports/sdk-registry-sync-2026-10-04.md)
for package-by-package versions, test evidence, and the remaining publishing
automation setup.

On September 29, 2026, TypeScript `0.8.1` and MCP Auth `4.0.0` were published
from the audited release checkout. Registry hashes match the tested archives,
and a fresh Docker consumer installed the exact registry versions and passed
the human-consent, token exchange, refresh, authority, revocation and outage
checks. MCP Auth also passed 396 unit, 63 database/restart and 9 Chromium tests,
with two existing unit-test skips. See the
[publication receipt](https://github.com/mishrasanjeev/grantex/blob/main/docs/reports/npm-release-verification-2026-09-29.md).
This was package publication, not a hosted-service deployment. At that date,
Python `0.7.1`, the audited Go changes, and changed execution integrations
were still unpublished source candidates; the October 4 releases above close
that specific publication gap. See [execution authority](/guides/sdk-execution-authority).

On September 28, 2026, TypeScript `0.7.1`, Python `0.6.1`, and Go `v0.4.2`
were built and tested from merged `main` snapshot `a919ea8a`. Their registry artifacts were
independently installed or downloaded and checked against the release
artifacts. These updates expose typed portable WebAuthn grant evidence and VC
attestations; they do not alter the server-side enrollment or evidence rollout
flags. The primary-SDK release workflow verified and packed the artifacts,
but registry publication required the maintainer's authenticated workstation
because trusted-publisher setup is not yet complete.

On September 27, 2026, TypeScript `0.7.1` and x402 `0.4.1` were installed
together in a clean npm consumer. Their registry SHA-512 integrity values
exactly match the verified main-branch tarballs, and the passkey, irregularity
policy, and x402 public exports were present. Python `0.6.0` was installed from the public PyPI index
in a clean environment. Its published wheel and sdist SHA-256 values match the
verified main-branch release artifacts. Go `v0.4.1` was tagged from the synced,
tested SDK source; the public Go proxy resolved the tag and the downloaded
module's full test suite passed. These packages include hosted passkey
enrollment and account irregularity response policy clients. Neither SDK
install enables the default-off server flags.

The [release workflow](https://github.com/mishrasanjeev/grantex/actions/runs/36288990463)
verified the artifacts but could not publish them automatically because the
npm and PyPI trusted-publisher records and Go release token are not configured.
Python was uploaded with the maintainer's authenticated Twine CLI, the npm
packages with the maintainer's CLI plus browser write approval, and Go was
tagged from the tested public SDK repository. Automated publication remains
an operator setup task; it must not be inferred from the verification job.

The September 7 dependency integration updates repository test tooling to
Vitest 5 and the auth service to SimpleWebAuthn 14. Use Node.js 24 LTS when
building or testing this checkout. These maintenance changes do not publish
new SDK versions; the registry versions above remain authoritative.

Python `0.5.1` was published on September 15, 2026. It is a patch release:
`enforce()` applies the tightest budget cap and denies malformed, negative, or
non-finite caps and amounts; the FastAPI enforcer reads the `Authorization`
header; grant-token verification caches the JWKS and runs off the event loop;
resource ids are percent-encoded; single-use authorization codes are never
retried; and event streams bound connect time. The PyPI wheel and sdist hashes
match the tested artifacts, and the installed PyPI wheel passed all 623 tests in
a clean environment.

Python `0.5.0` and Go `v0.3.0` were published on September 7, 2026. Both add
EVM payment responses and authenticated principal/agent reconciliation and
retain bounded refresh recovery. Full tests passed against a clean PyPI wheel
and the public Go module, including Go race tests. Neither language adds an
automatic x402 HTTP payment-and-retry wrapper.

TypeScript `0.6.0` and x402 `0.4.1` were published on September 7, 2026.
Both registry integrity hashes match the tested tarballs. A clean npm install
passed public-export, license/notice, Base safety, and authenticated reconciliation
checks with zero reported consumer vulnerabilities. The x402 adapter provides
opt-in request-bound Base USDC 402/sign/retry. See [Base USDC
Custody](/guides/base-usdc-custody) for the custody and RPC prerequisites.

<Info>
  As of August 10, 2026, published `@grantex/cli@0.3.0` includes the Hermes,
  OpenClaw, and portable Agent Skills installer. Repository source on `main`
  includes corrected Go Agent/Audit read/write contracts and layered prepaid
  wallet clients across TypeScript, Python, and Go. TypeScript `0.7.1`, Python
  `0.6.0`, and Go `v0.4.1` include matching bounded refresh-recovery behavior.
  Standard developer API-key plan throughput and custom-auth quotas
  remain separate from SDK publication.
</Info>

## Which Grantex package should I use?

* **Hermes, OpenClaw, or another shell-capable agent:** use published `@grantex/cli@0.4.2`; install its bundled skills with `grantex agent install`. No agent-specific SDK is required.
* **TypeScript application:** use npm-verified `@grantex/sdk@0.8.2` for hosted passkey enrollment, account irregularity response policy, bounded refresh recovery, layered prepaid-wallet governance, and OAuth Agent Grants.
* **x402 prepaid-wallet application:** use published `@grantex/x402@0.4.1` with published `@grantex/sdk@0.8.2`; keep external custody disabled until an operator adapter passes review.
* **Python application:** use PyPI-verified `grantex==0.7.2` for hosted passkey enrollment, account-level irregularity response policy, bounded refresh recovery, layered prepaid-wallet governance, and fail-closed `enforce()` budget checks.
* **Go application:** use public-proxy-verified `github.com/mishrasanjeev/grantex-go@v0.4.3` for hosted passkey enrollment, account-level irregularity response policy, bounded refresh recovery, corrected Agent/Audit contracts, and layered prepaid-wallet governance.
* **MCP HTTP transport authorization:** use an established MCP-compatible authorization server and maintained MCP SDK that implement the current MCP authorization specification.
* **Agent-specific MCP tool enforcement:** configure MCP Auth 4.1 durable state, a required authenticated human-principal resolver, resource binding and trusted current-grant verification. Host login and WebAuthn remain separate responsibilities.
* **Current revocation:** local JWT verification is insufficient by itself; perform an online state check or synchronize revocation data.
* **AgenticOrg governed cases:** see [the integration boundary](/guides/agenticorg-governed-cases); the last verified AgenticOrg integration does not wire token-level case purpose or per-case caps, regardless of the newer published Python package.

## Known limitations in the current published artifacts

<Warning>
  **TypeScript `0.8.2` and Python `0.7.2`:** `enforce()` binds the expected
  audience, denies capped calls without trusted amounts, and checks current
  revocation online by default. Configure the service audience and agent's
  resource servers, and keep the status/feed service operational. Plain token
  verification is still not current-state enforcement. Legacy aliases remain
  enabled unless explicitly disabled. See [migration](/migration-enforcement).
</Warning>

<Warning>
  **MCP Auth `4.1.0`:** configure durable shared storage, authenticated
  human-principal resolution, resource binding and trusted current-grant
  verification. The host must provide login; rendered consent does not replace
  passkeys. Memory storage and explicitly disabled current-grant checks remain
  evaluation-only. Version 2.0.2's six limitations are preserved
  in [its historical guide](/legacy/mcp-auth-server-2), not attributed to 4.1.0.
</Warning>

## Reproducible installation

Pin exact versions in applications, examples, CI, and deployment manifests:

<CodeGroup>
  ```bash CLI theme={null}
  npm install -g @grantex/cli@0.4.2
  ```

  ```bash TypeScript theme={null}
  npm install @grantex/sdk@0.8.2
  ```

  ```bash x402 theme={null}
  npm install @grantex/x402@0.4.1 @grantex/sdk@0.8.2
  ```

  ```bash Python theme={null}
  python -m pip install grantex==0.7.2
  ```

  ```bash Go theme={null}
  go get github.com/mishrasanjeev/grantex-go@v0.4.3
  ```

  ```bash MCP Auth theme={null}
  npm install @grantex/mcp-auth@4.1.0 @grantex/sdk@0.8.2
  ```
</CodeGroup>

Unpinned `npm install`, `pip install`, and `go get` commands resolve according to
their registries and module proxy. Use the pinned commands above when the build
must be repeatable.

## How to read release information

* [Public machine-readable release status](https://grantex.dev/release-status.json)
  is the canonical retrieval URL for tools and agents. The same file is versioned
  in the [GitHub repository](https://github.com/mishrasanjeev/grantex/blob/main/release-status.json) and drives automated cross-surface checks.
* [Compatibility matrix](https://github.com/mishrasanjeev/grantex/blob/main/COMPATIBILITY.md)
  maps repository packages to artifact names, versions, and publication status.
* [Repository changelog](https://github.com/mishrasanjeev/grantex/blob/main/CHANGELOG.md)
  records cross-project work. Its latest numbered entry can trail independently
  published SDK patches.
* Package registries are authoritative for public availability:
  [npm (`@grantex/cli`)](https://www.npmjs.com/package/@grantex/cli),
  [npm (`@grantex/sdk`)](https://www.npmjs.com/package/@grantex/sdk),
  [PyPI (`grantex`)](https://pypi.org/project/grantex/),
  [Go Packages](https://pkg.go.dev/github.com/mishrasanjeev/grantex-go), and
  [npm (`@grantex/mcp-auth`)](https://www.npmjs.com/package/@grantex/mcp-auth).

## Upgrade checklist

1. Read the package-specific notes in the compatibility matrix and changelog.
2. Confirm the required Node.js, Python, or Go toolchain version.
3. Update the exact dependency version and regenerate the relevant lockfile.
4. Run your authorization, token-verification, scope-enforcement, and revocation
   tests before deployment.
5. For self-hosted environments, verify the API contract used by your service;
   an SDK-only patch does not upgrade the service automatically.

<Warning>
  Do not infer publication from a repository manifest or marketing page alone.
  Confirm the exact artifact on its public registry before promoting a release.
</Warning>

## Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: [sanjeev@orchestrum.in](mailto:sanjeev@orchestrum.in) or [mishra.sanjeev@gmail.com](mailto:mishra.sanjeev@gmail.com).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.