Skip to main content

Installation

Published release: grantex==0.7.2. The published wheel and sdist hashes match the validated CI artifacts. A clean pinned public-index installation and import passed on the workstation; see Release Status.
The unpinned python -m pip install grantex command follows PyPI’s current release. Keep the exact version above in reproducible builds. See Release Status before upgrading.

Requirements

Version 0.7.1 adds opt-in current_authority, expected_principal_id and expected_agent_did verification options. Use host-authenticated identity and an uncached trusted-issuer callback; local signature checks alone do not prove current revocation. See SDK execution authority.
  • Python 3.9 or higher
  • httpx (sync HTTP client)
  • PyJWT >= 2.13 with cryptography >= 48.0.1 (for offline token verification)
All dependencies are installed automatically with the SDK. Version 0.6.0 adds client.webauthn.create_enrollment_session() for principal-authenticated hosted passkey registration and client.anomalies.get_response_policy() / set_response_policy() for the account-level irregularity response mode. Both server capabilities are default-off for self-hosted deployments and require explicit operator rollout; both are enabled on the Grantex-hosted service. An SDK install alone does not enable them. Version 0.6.1 adds typed WebAuthnGrantEvidence references to grant and verification responses and the updated VC WebAuthn attestation. It does not enable hosted server flags or add custom assertion UI helper methods.
Version 0.7.0 introduces breaking enforcement defaults: audience binding, denial of capped calls without trusted amounts, and online revocation checks. Register allowed resource servers before audience-bound authorization. Signature-only verification is not current-state enforcement. Python 3.9+ remains supported. Follow the migration guide.
Version 0.5.1 is a patch release. enforce() applies the tightest budget cap and denies malformed, negative, or non-finite caps and amounts (calls that earlier versions allowed with such values are now denied); the FastAPI enforcer reads the Authorization header; grant-token verification caches the JWKS and runs off the event loop; resource ids are percent-encoded in request paths; single-use authorization codes are never retried; and event streams bound connect time.
Version 0.5.0 adds EVM payment responses and authenticated principal/agent reservation reconciliation for Base USDC custody. It retains bounded refresh lost-response recovery from 0.4.1 and the layered policy, exact approval, reload, and ES256 DPoP wallet clients from 0.4.0. It does not add an automatic x402 HTTP payment-and-retry wrapper; applications must implement their merchant HTTP flow. See Agent Wallet Governance.

Quick Start

Configuration

The Grantex client accepts three keyword-only arguments:

API Key Resolution

The client resolves the API key in this order:
  1. The api_key keyword argument passed to the constructor.
  2. The GRANTEX_API_KEY environment variable.
If neither is set, a ValueError is raised.

Context Manager

The Grantex client implements the context manager protocol. Using with ensures the underlying HTTP connection pool is properly closed when you are done:
This is equivalent to calling client.close() manually:

Resource Clients

The Grantex client exposes the following resource clients as attributes:

Standalone Functions

In addition to the client, the SDK exports standalone utility functions:

Data Model Conventions

All response types are frozen dataclasses with snake_case field names. Lists are returned as Python tuple objects for immutability.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on October 4, 2026