OACP Artifact Authority
Canonical end-to-end flow: OACP authority overview.
Grantex authority is exposed through POST /v1/commerce/oacp/c6z/authority-requests. The route accepts an AgenticOrg seller authority request and public-safe connector evidence, validates scope, and returns issued artifacts or a refusal.
Artifact Families
Verification Rules
Artifacts must carry issuer, issuer key, artifact type, issued/expires timestamps, payload hash, signature algorithm, source refs, freshness metadata, revocation posture, risk tier, and no_checkout_payment_enablement behavior. Payloads must not contain raw connector payloads, tokens, provider secrets, card or bank data, checkout URLs, payment URLs, executable targets, or private merchant data.
Pending Runtime Gap
Detached signature verification and key governance are implemented internally, but external public key distribution, rotation policy publication, and partner acceptance remain approval work before external program launch.Last modified on June 22, 2026