# Grantex > Documentation and API reference for Grantex AI agent authorization, delegated OAuth grants, agent identity, scoped permissions, MCP authorization, verification, and audit. Grantex is owned by Orchestrum Technologies LLP; inventor and owner: Sanjeev Kumar. - [Grantex AI Agent Authorization](https://docs.grantex.dev/introduction.md): Learn how Grantex provides delegated authorization, verifiable identity, scoped permissions, human consent, and audit records for AI agents. - [Ownership](https://docs.grantex.dev/ownership.md): Legal ownership and inventor contact information for Grantex. - [AI Agent Authorization Quickstart](https://docs.grantex.dev/quickstart.md): Implement AI agent authorization with Grantex: register an agent, request consent, exchange a code, verify a JWT grant, and write audit records. - [Release Status](https://docs.grantex.dev/release-status.md): Choose the current Grantex CLI, TypeScript, Python, Go, or MCP package with exact versions, runtime requirements, limitations, and reproducible install commands. - [Local Development](https://docs.grantex.dev/local-development.md): Run the full Grantex stack locally with Docker Compose. - [How It Works](https://docs.grantex.dev/concepts/how-it-works.md): The three primitives that make up the Grantex protocol. - [Grant Token](https://docs.grantex.dev/concepts/grant-token.md): Grantex grant tokens are RS256-signed JWTs with agent-specific claims. - [Scopes](https://docs.grantex.dev/concepts/scopes.md): Grantex scopes use the resource:action[:constraint] naming convention. - [Scope Registry](https://docs.grantex.dev/concepts/scope-registry.md): Standard scope definitions for common domains, plus guidelines for custom scopes. - [Multi-Agent Delegation](https://docs.grantex.dev/concepts/delegation.md): How Grantex handles authorization chains across multi-agent pipelines. - [Grantex vs OAuth 2.0](https://docs.grantex.dev/concepts/vs-oauth.md): How Grantex compares to OAuth 2.0 and when to use each. - [Tool Manifests](https://docs.grantex.dev/concepts/tool-manifests.md): How tool manifests map every tool to a permission level, enabling precise scope enforcement for AI agent tool calls. - [Trust Registry](https://docs.grantex.dev/features/trust-registry.md): Public organization directory with DID identity and DNS ownership verification. - [FIDO2 / WebAuthn](https://docs.grantex.dev/features/fido-webauthn.md): Passkey-based human presence verification for agent authorization. Cryptographic proof that a real human approved the grant. - [Verifiable Credentials](https://docs.grantex.dev/features/verifiable-credentials.md): W3C Verifiable Credentials issued alongside grant tokens. Portable, tamper-proof proof of agent authorization for any verifier. - [SD-JWT (Selective Disclosure)](https://docs.grantex.dev/features/sd-jwt.md): Selective Disclosure JWTs let agents present only the claims needed for a given transaction, enabling privacy-preserving authorization and Verifiable Intent compatibility. - [DID Infrastructure](https://docs.grantex.dev/features/did-infrastructure.md): W3C Decentralized Identifier (DID) infrastructure for independent credential verification. Resolve did:web:grantex.dev to verify any Grantex-issued credential. - [MPP Agent Passport](https://docs.grantex.dev/features/mpp-agent-passport.md): W3C Verifiable Credential for agent identity in machine-to-machine payments via the Machine Payments Protocol (MPP). - [Anomaly Detection](https://docs.grantex.dev/features/anomaly-detection.md): Real-time detection and alerting for unusual AI agent grant activity. - [Offline Authorization](https://docs.grantex.dev/features/offline-authorization.md): How Grantex enables offline authorization for on-device AI agents. Architecture, security model, and limitations. - [Consent Bundles](https://docs.grantex.dev/features/consent-bundles.md): Consent bundles package a grant token, JWKS snapshot, and audit signing key for offline-capable authorization. - [Agent Prepaid Wallets](https://docs.grantex.dev/features/prepaid-wallets.md): Principal-controlled prepaid balances, multi-wallet assignment, spend policy, reload approval, and emergency blocking for AI agents. - [Agent Wallet Governance](https://docs.grantex.dev/guides/agent-wallet-governance.md): Responsibility boundaries, layered spend controls, exact payment approvals, reload governance, and deployment gaps for AI-agent prepaid wallets. - [Prepaid Wallet Production Readiness](https://docs.grantex.dev/guides/prepaid-wallet-production.md): External dependencies, deployment boundaries, routing, notification delivery, merchant recovery, and release checks for self-hosted Grantex prepaid wallets and x402 v2. - [Base USDC Custody](https://docs.grantex.dev/guides/base-usdc-custody.md): Governed x402 EIP-3009 signing, verified funding, safe retries and finalized-chain reconciliation. - [x402 Architecture](https://docs.grantex.dev/features/x402-architecture.md): Official x402 v2 payment messages backed by principal-controlled Grantex prepaid-wallet reservations. - [GDT Specification](https://docs.grantex.dev/features/x402-gdt-spec.md): Specification of the Grantex Delegation Token (GDT) — a W3C Verifiable Credential 2.0 for agent spend authorization. - [MCP Auth Server](https://docs.grantex.dev/features/mcp-auth-server.md): OAuth 2.1 + PKCE endpoint package for MCP servers, including current v2.0.2 limitations. - [OACP Authority Overview](https://docs.grantex.dev/guides/oacp/overview.md): The canonical Grantex overview for Open Agentic Commerce Protocol authority, artifacts, policy, and adapter governance. - [OACP Truth Inventory](https://docs.grantex.dev/guides/oacp/truth-inventory.md): Evidence-backed inventory of what is implemented, gated, missing, or stale across the current OACP split. - [OACP Architecture](https://docs.grantex.dev/guides/oacp/architecture.md): The Grantex view of the OACP four-party architecture. - [OACP Artifact Authority](https://docs.grantex.dev/guides/oacp/artifact-authority.md): How Grantex issues, refuses, and verifies OACP artifacts for AgenticOrg. - [OACP Merchant Self-Service Config Boundary](https://docs.grantex.dev/guides/oacp/merchant-self-service-config.md): What AgenticOrg merchant configuration owns, what Grantex signs, and how future connectors and bank providers stay non-executing until approved. - [OACP Protocol Adapter Authority](https://docs.grantex.dev/guides/oacp/protocol-adapter.md): How Grantex maps canonical OACP artifacts to compatibility payloads. - [OACP Policy And Governance](https://docs.grantex.dev/guides/oacp/policy-governance.md): Policy, freshness, source, revocation, and adapter governance for Grantex OACP authority. - [OACP Merchant Source Of Record](https://docs.grantex.dev/guides/oacp/merchant-source-of-record.md): Why Shopify and merchant systems remain authoritative in OACP. - [OACP Buyer Safety And Freshness](https://docs.grantex.dev/guides/oacp/buyer-safety-freshness.md): How source, freshness, cache, and refusal behavior keep buyer agents grounded. - [OACP Provider And Payment Boundary](https://docs.grantex.dev/guides/oacp/provider-payment-boundary.md): How OACP treats Pine Labs Plural/P3P and other payment rails. - [OACP Offline POS Bridge Boundary](https://docs.grantex.dev/guides/oacp/pos-bridge-boundary.md): How Grantex treats Offline POS handoff evidence without owning POS transactions. - [OACP Integration Guide For AgenticOrg](https://docs.grantex.dev/guides/oacp/agenticorg-integration.md): How AgenticOrg requests and consumes Grantex OACP authority artifacts. - [OACP Operator Runbook](https://docs.grantex.dev/guides/oacp/operator-runbook.md): Grantex operator runbook for authority requests, cache safety, launch checks, and rollback. - [OACP Launch Readiness](https://docs.grantex.dev/guides/oacp/launch-readiness.md): Launch readiness gates, rollback criteria, and remaining gaps for Grantex OACP authority. - [Move Your Shopify Store To Agentic Commerce](https://docs.grantex.dev/guides/oacp/explainers/shopify-to-agentic-commerce.md): Merchant explainer for bringing Shopify into AgenticOrg with Grantex OACP authority. - [How Buyer Agents Shop Safely With OACP](https://docs.grantex.dev/guides/oacp/explainers/buyer-agent-safety.md): Buyer explainer for OACP source, freshness, and refusal behavior. - [Build Against OACP Artifacts And Bridges](https://docs.grantex.dev/guides/oacp/explainers/developer-artifacts-bridges.md): Developer explainer for OACP artifacts, AgenticOrg bridges, and adapter payloads. - [How OACP Maps To Schema.org, UCP, ACP, AP2, A2A, And MCP](https://docs.grantex.dev/guides/oacp/explainers/protocol-partner-mappings.md): Protocol partner explainer for OACP compatibility mappings. - [Provider-Owned Mandate And Payment Evidence In OACP](https://docs.grantex.dev/guides/oacp/explainers/provider-owned-payment-evidence.md): Payment and fintech partner explainer for OACP evidence boundaries. - [Launch And Rollback Runbook](https://docs.grantex.dev/guides/oacp/explainers/launch-rollback-runbook.md): Operator explainer for OACP launch, smoke tests, monitoring, and rollback. - [Commerce V1 Overview](https://docs.grantex.dev/guides/commerce-v1-overview.md): Start here for Grantex Agentic Commerce architecture, readiness, safety gates, and audience-specific paths. - [Agentic Commerce PRD](https://docs.grantex.dev/guides/commerce-v1-agentic-commerce-prd.md): Canonical product requirements document for Grantex Commerce and AgenticOrg agentic commerce implementation. - [Agentic Commerce Implementation PRD](https://docs.grantex.dev/guides/commerce-v1-agentic-commerce-implementation-prd.md): Merchant-readable product requirements and gap plan for making Grantex Commerce and AgenticOrg ready for self-serve agentic commerce. - [End-To-End Agentic Commerce Flow](https://docs.grantex.dev/guides/commerce-v1-end-to-end-agentic-commerce-flow.md): Plain-language buyer and seller flow for OACP agentic commerce with AgenticOrg agents and Grantex trust authority. - [Merchant Guide To Agentic Commerce](https://docs.grantex.dev/guides/commerce-v1-merchant-agentic-commerce-user-guide.md): A detailed merchant-facing guide for using Grantex Commerce V1 safely with AI agents, read-only discovery, consent, approvals, launch readiness, operations, and support workflows. - [Commerce V1 Developer Guide](https://docs.grantex.dev/guides/commerce-v1-developer-guide.md): Grantex Commerce REST/MCP model, consent/passport sequence, idempotency, webhooks, Shopify live-pilot usage, and provider boundaries. - [Commerce V1 Merchant And Operator Guide](https://docs.grantex.dev/guides/commerce-v1-merchant-operator-guide.md): Merchant onboarding, catalog, policy, audit, webhook, emergency control, and production no-go guidance for Grantex Commerce V1. - [Commerce V1 Operations](https://docs.grantex.dev/guides/commerce-v1-operations.md): Sandbox operations, import columns, and runbooks for Grantex Commerce V1. - [DPDP & GDPR Compliance Module](https://docs.grantex.dev/features/dpdp-compliance.md): Structured consent records, purpose limitation, right to withdrawal, and audit-ready exports for AI agent deployments. - [DPDP Act 2023 Compliance](https://docs.grantex.dev/compliance/dpdp-act-2023.md): How Grantex maps to India's Digital Personal Data Protection Act 2023 for AI agent deployments. - [EU AI Act Compliance](https://docs.grantex.dev/compliance/eu-ai-act.md): How Grantex technical controls can support EU AI Act readiness across the regulation's phased implementation timeline. - [Sub processors](https://docs.grantex.dev/compliance/sub-processors.md) - [Data residency](https://docs.grantex.dev/compliance/data-residency.md) - [Dpa](https://docs.grantex.dev/compliance/dpa.md) - [Privacy policy](https://docs.grantex.dev/compliance/privacy-policy.md) - [Terms of service](https://docs.grantex.dev/compliance/terms-of-service.md) - [Cookie policy](https://docs.grantex.dev/compliance/cookie-policy.md) - [Rate Limits](https://docs.grantex.dev/guides/rate-limits.md): Understand and work with Grantex API rate limits. - [Webhooks](https://docs.grantex.dev/guides/webhooks.md): Receive real-time notifications for grant lifecycle events. - [Self-Hosting](https://docs.grantex.dev/guides/self-hosting.md): Run your own Grantex auth service — from local dev to production Kubernetes. - [Dependency Updates and Validation](https://docs.grantex.dev/guides/dependency-updates.md): Validate dependency upgrades locally before deploying Grantex. - [Security Hardening](https://docs.grantex.dev/guides/security-hardening.md): Enterprise-grade security controls built into the Grantex auth service — headers, rate limiting, CORS, input validation, and more. - [Supply Chain and License Security](https://docs.grantex.dev/guides/supply-chain-security.md): Audit Grantex npm, Python, Go, container, GitHub Action, and third-party license dependencies before deploying or redistributing it. - [OAuth Agent Grants Profile](https://docs.grantex.dev/guides/oauth-agent-grants.md): Implement the Grantex OAuth agent-grants profile with PAR, PKCE, DPoP, consent, rotating refresh tokens, token exchange, and revocation. - [Operations](https://docs.grantex.dev/guides/operations.md): Run Grantex in production — health checks, required configuration, graceful shutdown, connection management, and webhook delivery. - [Security Best Practices](https://docs.grantex.dev/guides/security-best-practices.md): Harden your Grantex integration with token storage strategies, scope design, revocation handling, and more. - [Token Verification Strategy](https://docs.grantex.dev/guides/token-verification.md): Choose between offline, online, and hybrid token verification strategies. - [Troubleshooting](https://docs.grantex.dev/guides/troubleshooting.md): Common issues and solutions when working with the Grantex API and SDKs. - [End-User Permission Dashboard](https://docs.grantex.dev/guides/end-user-permissions.md): Give your users a self-service page to view and revoke agent access. - [Migration Guide](https://docs.grantex.dev/guides/migration.md): Step-by-step guides for migrating to Grantex from API keys or raw OAuth 2.0. - [Metrics & Observability](https://docs.grantex.dev/guides/metrics-observability.md): Monitor your Grantex deployment with Prometheus metrics, Grafana dashboards, alerting rules, and structured logging. - [OpenTelemetry Tracing](https://docs.grantex.dev/guides/opentelemetry.md): Instrument your Grantex auth service with OpenTelemetry for distributed tracing and APM. - [Event Streaming](https://docs.grantex.dev/guides/event-streaming.md): Stream Grantex authorization events in real time via SSE or WebSocket, and forward them to external systems with @grantex/destinations. - [Datadog Integration](https://docs.grantex.dev/guides/siem-datadog.md): Forward Grantex authorization events to Datadog for centralized logging, dashboards, and anomaly detection monitors. - [Splunk Integration](https://docs.grantex.dev/guides/siem-splunk.md): Forward Grantex authorization events to Splunk via the HTTP Event Collector for search, alerting, and compliance dashboards. - [S3 & BigQuery Archival](https://docs.grantex.dev/guides/siem-s3-bigquery.md): Archive Grantex authorization events to Amazon S3 and Google BigQuery for compliance, auditing, and long-term analytics. - [Budget & Spending Controls](https://docs.grantex.dev/guides/budget-controls.md): Allocate budgets to grants and track spending with per-transaction debit, threshold alerts, and JWT budget claims. - [Terraform Provider](https://docs.grantex.dev/guides/terraform.md): Manage Grantex resources as infrastructure with the official Terraform provider. - [Pulumi](https://docs.grantex.dev/guides/pulumi.md): Use the Grantex Terraform provider with Pulumi via the Terraform bridge. - [Interactive Playground](https://docs.grantex.dev/guides/playground.md): Try the full Grantex authorization flow in your browser — no signup required. - [OPA Integration](https://docs.grantex.dev/guides/opa-integration.md): Use Open Policy Agent as your Grantex policy backend - [Cedar Integration](https://docs.grantex.dev/guides/cedar-integration.md): Use AWS Cedar as your Grantex policy backend - [Policy-as-Code](https://docs.grantex.dev/guides/policy-as-code.md): Manage Grantex policies in Git with automated sync - [Usage Metering](https://docs.grantex.dev/guides/usage-metering.md): Track and monitor API usage across your Grantex deployment - [Custom Domains](https://docs.grantex.dev/guides/custom-domains.md): Use your own domain for Grantex API endpoints (Enterprise) - [Trust Registry Setup](https://docs.grantex.dev/guides/trust-registry-setup.md): Register a did:web organization and complete DNS TXT ownership verification. - [MPP Integration Guide](https://docs.grantex.dev/guides/mpp-integration.md): Step-by-step guide to adding Grantex agent identity to MPP payment flows — for both agents and merchants. - [MCP Certification Applications](https://docs.grantex.dev/guides/mcp-certification.md): Register an MCP server and submit a Bronze, Silver, or Gold certification application. - [Enterprise SSO](https://docs.grantex.dev/guides/enterprise-sso.md): Set up OIDC and SAML single sign-on, plus the current LDAP direct-bind preview, with multi-IdP routing and JIT provisioning. - [Compliance Matrix](https://docs.grantex.dev/guides/compliance-matrix.md): How Grantex maps to OWASP Agentic Top 10, EU AI Act, and NIST AI RMF requirements for AI agent security and authorization. - [Anomaly Detection Setup](https://docs.grantex.dev/guides/anomaly-detection-setup.md): Configure anomaly detection rules and notification channels for your AI agents. - [Raspberry Pi Guide](https://docs.grantex.dev/guides/raspberry-pi.md): Run Grantex-authorized Gemma agents on Raspberry Pi 5 with offline token verification, scope enforcement, local audit records, and later synchronization. - [Android + Gemma 4 Guide](https://docs.grantex.dev/guides/android-gemma4.md): Integrate Grantex offline authorization into Android apps running Gemma 4 agents. - [iOS + Gemma 4 Guide](https://docs.grantex.dev/guides/ios-gemma4.md): Integrate Grantex offline authorization into iOS apps running Gemma 4 agents using Swift and CryptoKit. - [Scope Enforcement](https://docs.grantex.dev/guides/scope-enforcement.md): Enforce per-tool permissions on every AI agent tool call using manifests, the enforce() API, and framework integrations. - [Custom Manifests](https://docs.grantex.dev/guides/custom-manifests.md): Define tool manifests for any connector — internal APIs, new SaaS tools, proprietary services. No dependency on Grantex. - [AgenticOrg Case Study](https://docs.grantex.dev/case-studies/agenticorg.md): How AgenticOrg enforces scope on 35 AI agents, 53+ connectors, and 339+ tools using Grantex tool manifests. - [Quickstart (TypeScript)](https://docs.grantex.dev/examples/quickstart-ts.md): End-to-end authorization lifecycle with the TypeScript SDK. - [Quickstart (Python)](https://docs.grantex.dev/examples/quickstart-py.md): End-to-end authorization lifecycle with the Python SDK. - [Next.js Starter](https://docs.grantex.dev/examples/nextjs-starter.md): Interactive Next.js app showing the full Grantex consent flow. - [LangChain Agent](https://docs.grantex.dev/examples/langchain-agent.md): Scoped tools with automatic audit logging using LangChain. - [Vercel AI Chatbot](https://docs.grantex.dev/examples/vercel-ai-chatbot.md): Scope-enforced tools with audit logging using Vercel AI SDK. - [CrewAI Agent](https://docs.grantex.dev/examples/crewai-agent.md): Scoped tools with audit logging using CrewAI. - [OpenAI Agents SDK](https://docs.grantex.dev/examples/openai-agents.md): Scope-enforced tools using the OpenAI Agents SDK. - [Google ADK](https://docs.grantex.dev/examples/google-adk.md): Scope-enforced tools using Google Agent Development Kit. - [Anthropic SDK Tool Use](https://docs.grantex.dev/examples/anthropic-tool-use.md): Scope-enforced tool use with audit logging using the Anthropic SDK. - [Multi-Agent Email Flow](https://docs.grantex.dev/examples/multi-agent-email-flow.md): Multi-agent delegation with failure handling, cascade revocation, and audit trail. - [Token Refresh & Rotation](https://docs.grantex.dev/examples/token-expiry-refresh.md): Active-grant refresh rotation, lost-response recovery, and the expired-grant re-authorization boundary. - [Audit Dashboard](https://docs.grantex.dev/examples/audit-dashboard.md): Query, filter, and analyze the Grantex audit trail with metrics and hash chain verification. - [Quickstart: Gemma 4 Offline Auth](https://docs.grantex.dev/examples/quickstart-gemma.md): Get offline authorization working with Gemma 4 agents in under 5 minutes. Install @grantex/gemma, create a consent bundle, and verify tokens offline. - [TypeScript SDK](https://docs.grantex.dev/sdks/typescript/overview.md): Install, configure, and get started with the @grantex/sdk TypeScript SDK. - [Authorization](https://docs.grantex.dev/sdks/typescript/authorization.md): Initiate the delegated authorization flow to request user consent for your agent. - [Tokens](https://docs.grantex.dev/sdks/typescript/tokens.md): Exchange authorization codes for grant tokens, verify tokens online, and revoke them. - [Offline Verification](https://docs.grantex.dev/sdks/typescript/offline-verification.md): Verify grant tokens locally with published JWKS keys, without a per-token Grantex verification API call. - [PKCE](https://docs.grantex.dev/sdks/typescript/pkce.md): Protect the authorization flow with Proof Key for Code Exchange (PKCE) using S256 challenges. - [Agents](https://docs.grantex.dev/sdks/typescript/agents.md): Register, list, update, and delete AI agents with the Grantex TypeScript SDK. - [Grants](https://docs.grantex.dev/sdks/typescript/grants.md): Manage grants, delegate authorization to sub-agents, and verify tokens via the API. - [Audit](https://docs.grantex.dev/sdks/typescript/audit.md): Log agent actions and query the tamper-evident audit trail. - [Webhooks](https://docs.grantex.dev/sdks/typescript/webhooks.md): Receive real-time notifications for grant and token lifecycle events. - [Policies](https://docs.grantex.dev/sdks/typescript/policies.md): Define allow/deny authorization policies to control agent access. - [Compliance](https://docs.grantex.dev/sdks/typescript/compliance.md): Generate compliance summaries, export grants and audit data, and produce evidence packs for SOC 2 and GDPR. - [Anomaly Detection](https://docs.grantex.dev/sdks/typescript/anomalies.md): Detect, list, and acknowledge anomalous agent behavior patterns. - [Billing](https://docs.grantex.dev/sdks/typescript/billing.md): Manage subscriptions and access Stripe checkout and billing portal sessions. - [SCIM 2.0](https://docs.grantex.dev/sdks/typescript/scim.md): Provision and manage users via the SCIM 2.0 protocol, and manage SCIM bearer tokens. - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/typescript/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, with multi-IdP connections and domain enforcement. - [Principal Sessions](https://docs.grantex.dev/sdks/typescript/principal-sessions.md): Generate session tokens for end-users to view and manage their agent permissions. - [WebAuthn](https://docs.grantex.dev/sdks/typescript/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users. - [Credentials](https://docs.grantex.dev/sdks/typescript/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures. - [Credential Vault](https://docs.grantex.dev/sdks/typescript/vault.md): Store encrypted upstream credentials and exchange grant tokens for scoped access. - [Budgets](https://docs.grantex.dev/sdks/typescript/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history. - [Events](https://docs.grantex.dev/sdks/typescript/events.md): Subscribe to real-time authorization events via Server-Sent Events. - [Usage](https://docs.grantex.dev/sdks/typescript/usage.md): Track current UTC API usage metrics and view daily usage history. - [Domains](https://docs.grantex.dev/sdks/typescript/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/typescript/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity. - [Commerce V1](https://docs.grantex.dev/sdks/typescript/commerce.md): Use the @grantex/sdk Commerce V1 client for OACP merchant discovery, catalog grounding, consent, Commerce Passport, payment intent, checkout, webhook, and ops flows. - [Enforce](https://docs.grantex.dev/sdks/typescript/enforce.md): Check whether an agent's grant token permits a specific tool call. Load manifests, call enforce(), and wrap LangChain tools. - [Error Handling](https://docs.grantex.dev/sdks/typescript/errors.md): Understand the error hierarchy and handle API, authentication, token, and network errors. - [Python SDK](https://docs.grantex.dev/sdks/python/overview.md): Install and configure the Grantex Python SDK for delegated authorization of AI agents. - [Authorization](https://docs.grantex.dev/sdks/python/authorization.md): Initiate the delegated authorization flow to request permissions from a user on behalf of an AI agent. - [Tokens](https://docs.grantex.dev/sdks/python/tokens.md): Exchange authorization codes for grant tokens, verify tokens online, and revoke tokens. - [Offline Verification](https://docs.grantex.dev/sdks/python/offline-verification.md): Verify signatures and claims locally with a remote JWKS request per standalone call, without online token introspection. - [PKCE](https://docs.grantex.dev/sdks/python/pkce.md): Use Proof Key for Code Exchange (PKCE) to secure the authorization flow against code interception attacks. - [Agents](https://docs.grantex.dev/sdks/python/agents.md): Register, retrieve, update, list, and delete AI agents using the Grantex Python SDK. - [Grants](https://docs.grantex.dev/sdks/python/grants.md): Retrieve, list, revoke, delegate, and verify grants using the Grantex Python SDK. - [Audit](https://docs.grantex.dev/sdks/python/audit.md): Log, query, and retrieve tamper-evident audit entries for agent actions using the Grantex Python SDK. - [Webhooks](https://docs.grantex.dev/sdks/python/webhooks.md): Register webhook endpoints, receive event notifications, and verify webhook signatures with the Grantex Python SDK. - [Policies](https://docs.grantex.dev/sdks/python/policies.md): Create, manage, and enforce authorization policies for fine-grained access control with the Grantex Python SDK. - [Compliance](https://docs.grantex.dev/sdks/python/compliance.md): Generate compliance summaries, export grants and audit data, and produce SOC 2/GDPR evidence packs with the Grantex Python SDK. - [Anomaly Detection](https://docs.grantex.dev/sdks/python/anomalies.md): Detect, list, and acknowledge authorization anomalies using the Grantex Python SDK. - [Billing](https://docs.grantex.dev/sdks/python/billing.md): Manage subscriptions, create checkout sessions, and access the billing portal with the Grantex Python SDK. - [SCIM 2.0](https://docs.grantex.dev/sdks/python/scim.md): Provision and manage users via SCIM 2.0, and manage SCIM bearer tokens with the Grantex Python SDK. - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/python/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, using the Grantex Python SDK. - [Principal Sessions](https://docs.grantex.dev/sdks/python/principal-sessions.md): Generate session tokens for end-users to view and manage their agent permissions. - [WebAuthn](https://docs.grantex.dev/sdks/python/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users. - [Credentials](https://docs.grantex.dev/sdks/python/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures. - [Budgets](https://docs.grantex.dev/sdks/python/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history. - [Events](https://docs.grantex.dev/sdks/python/events.md): Subscribe to real-time authorization events via Server-Sent Events. - [Usage](https://docs.grantex.dev/sdks/python/usage.md): Track current UTC-date API usage metrics and view daily usage history. - [Domains](https://docs.grantex.dev/sdks/python/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/python/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity. - [Commerce V1](https://docs.grantex.dev/sdks/python/commerce.md): Use the Grantex Python SDK Commerce V1 client for OACP merchant discovery, catalog grounding, consent, payment, webhook, and ops flows. - [Vault](https://docs.grantex.dev/sdks/python/vault.md): Store, retrieve, and exchange encrypted service credentials through the Grantex credential vault. - [Enforce](https://docs.grantex.dev/sdks/python/enforce.md): Check whether an agent's grant token permits a specific tool call. Load manifests, call enforce(), and wrap LangChain tools. - [Error Handling](https://docs.grantex.dev/sdks/python/errors.md): Handle API errors, authentication failures, token verification errors, and network issues in the Grantex Python SDK. - [Go SDK](https://docs.grantex.dev/sdks/go/overview.md): Official Go SDK for the Grantex delegated authorization protocol - [Authorization](https://docs.grantex.dev/sdks/go/authorization.md): Create authorization requests and manage the consent flow - [Tokens](https://docs.grantex.dev/sdks/go/tokens.md): Exchange, refresh, verify, and revoke grant tokens - [Offline Verification](https://docs.grantex.dev/sdks/go/offline-verification.md): Verify signatures and claims locally with a remote JWKS request per standalone call - [PKCE](https://docs.grantex.dev/sdks/go/pkce.md): Proof Key for Code Exchange (S256) for enhanced security - [Agents](https://docs.grantex.dev/sdks/go/agents.md): Register and manage AI agents - [Grants](https://docs.grantex.dev/sdks/go/grants.md): Manage authorization grants and delegation - [Audit](https://docs.grantex.dev/sdks/go/audit.md): Log and query tamper-evident audit entries - [Webhooks](https://docs.grantex.dev/sdks/go/webhooks.md): Manage webhook endpoints and verify signatures - [Policies](https://docs.grantex.dev/sdks/go/policies.md): Create and manage access policies - [Compliance](https://docs.grantex.dev/sdks/go/compliance.md): Generate compliance reports and evidence packs - [Anomalies](https://docs.grantex.dev/sdks/go/anomalies.md): Detect and manage security anomalies - [Billing](https://docs.grantex.dev/sdks/go/billing.md): Manage subscriptions and billing - [SCIM](https://docs.grantex.dev/sdks/go/scim.md): SCIM 2.0 user provisioning - [SSO (OIDC + SAML + LDAP)](https://docs.grantex.dev/sdks/go/sso.md): Enterprise OIDC and SAML single sign-on, plus the LDAP direct-bind preview, using the Grantex Go SDK. - [Principal Sessions](https://docs.grantex.dev/sdks/go/principal-sessions.md): Create end-user dashboard sessions - [WebAuthn](https://docs.grantex.dev/sdks/go/webauthn.md): Register and manage FIDO2/WebAuthn passkey credentials for end-users - [Credentials](https://docs.grantex.dev/sdks/go/credentials.md): Retrieve, verify, and present W3C Verifiable Credentials and SD-JWT selective disclosures - [Budgets](https://docs.grantex.dev/sdks/go/budgets.md): Allocate per-grant spending budgets, debit usage, check balances, and view transaction history - [Events](https://docs.grantex.dev/sdks/go/events.md): Subscribe to real-time authorization events via Server-Sent Events - [Usage](https://docs.grantex.dev/sdks/go/usage.md): Track current UTC-date API usage metrics and view daily usage history - [Domains](https://docs.grantex.dev/sdks/go/domains.md): Register and verify custom domains for your Grantex account via DNS TXT records. - [Passports](https://docs.grantex.dev/sdks/go/passports.md): Issue, retrieve, revoke, and list AgentPassportCredentials for MPP agent identity - [Commerce V1](https://docs.grantex.dev/sdks/go/commerce.md): Use the Grantex Go SDK Commerce V1 client for OACP merchant discovery, catalog grounding, consent, payment, webhook, and ops flows. - [Vault](https://docs.grantex.dev/sdks/go/vault.md): Store, retrieve, and exchange encrypted service credentials through the Grantex credential vault - [Error Handling](https://docs.grantex.dev/sdks/go/errors.md): Error types and handling patterns - [AI Agent Framework Integrations](https://docs.grantex.dev/integrations/overview.md): Choose Grantex integrations for Hermes, OpenClaw, Agent Skills, OpenAI Agents, Anthropic, LangChain, CrewAI, Google ADK, AutoGen, MCP, and service frameworks. - [Service Provider Adapters](https://docs.grantex.dev/integrations/adapters.md): Pre-built integrations that translate Grantex grants into real API calls. - [Grantex Gateway](https://docs.grantex.dev/integrations/gateway.md): Zero-code reverse-proxy that enforces grant tokens in front of any API. - [MCP Auth Server](https://docs.grantex.dev/integrations/mcp-auth.md): OAuth 2.1 + PKCE endpoint package for MCP servers, with v2.0.2 limitations. - [Trust Registry](https://docs.grantex.dev/integrations/registry.md): Public organization directory with DID identity and DNS ownership verification. - [Agent CLIs & Skills](https://docs.grantex.dev/integrations/agent-cli.md): Give Hermes, OpenClaw, and other shell-capable agents a portable Grantex skill bundle and a stable JSON CLI contract. - [Hermes Agent](https://docs.grantex.dev/integrations/hermes.md): Install Grantex Agent Skills into Hermes and operate delegated authorization through the JSON CLI. - [OpenClaw](https://docs.grantex.dev/integrations/openclaw.md): Install Grantex Agent Skills in an OpenClaw workspace and use the JSON CLI for delegated authorization. - [Express.js](https://docs.grantex.dev/integrations/express.md): Grant token verification and scope-based authorization middleware for Express.js. - [FastAPI](https://docs.grantex.dev/integrations/fastapi.md): Grant token verification and scope-based authorization for FastAPI using dependency injection. - [MCP Server](https://docs.grantex.dev/integrations/mcp.md): Use Grantex from Claude Desktop, Cursor, or Windsurf via the Model Context Protocol. - [LangChain](https://docs.grantex.dev/integrations/langchain.md): Scope-enforced tools and automatic audit logging for LangChain agents. - [Vercel AI SDK](https://docs.grantex.dev/integrations/vercel-ai.md): Scope-enforced tools and audit logging for Vercel AI SDK agents. - [AutoGen / OpenAI](https://docs.grantex.dev/integrations/autogen.md): Scope-enforced function calling and registry for OpenAI-style agents. - [CrewAI](https://docs.grantex.dev/integrations/crewai.md): Scope-enforced, audited agent tools for CrewAI. - [OpenAI Agents SDK](https://docs.grantex.dev/integrations/openai-agents.md): Scope-enforced FunctionTool wrappers for the OpenAI Agents SDK. - [Google ADK](https://docs.grantex.dev/integrations/google-adk.md): Scope-enforced plain function tools for Google Agent Development Kit. - [Anthropic SDK](https://docs.grantex.dev/integrations/anthropic.md): Scope-enforced tool use, registry, and audit logging for Claude models. - [Strands Agents SDK](https://docs.grantex.dev/integrations/strands.md): Scope-enforced tools for Strands Agents SDK in TypeScript and Python. - [Gemma 4 SDK](https://docs.grantex.dev/sdks/gemma.md): Complete API reference for @grantex/gemma — offline authorization for Gemma 4 on-device agents. TypeScript and Python. - [Gemma 4 (On-Device)](https://docs.grantex.dev/integrations/gemma.md): Offline authorization for Gemma 4 on-device AI agents — consent bundles, JWT verification, and tamper-evident audit logging without network calls. - [DPDP & GDPR Compliance](https://docs.grantex.dev/integrations/dpdp.md): India DPDP Act 2023 and EU GDPR compliance module for AI agent deployments — consent records, purpose limitation, grievances, and audit exports. - [A2A Protocol Bridge (TypeScript)](https://docs.grantex.dev/integrations/a2a.md): Inject Grantex grant tokens into Google A2A agent-to-agent communication - [A2A Protocol Bridge (Python)](https://docs.grantex.dev/integrations/a2a-py.md): Inject Grantex grant tokens into Google A2A agent-to-agent communication from Python - [x402 Prepaid Wallets](https://docs.grantex.dev/integrations/x402.md): Assign one or more prepaid wallets to an AI agent and enforce principal-controlled spend policy through official x402 v2 payment messages. - [CLI](https://docs.grantex.dev/integrations/cli.md): Manage agents, grants, audit logs, and more from your terminal. - [grantex verify](https://docs.grantex.dev/cli/verify.md): Inspect any Grantex grant token from the command line. See scopes, expiry, delegation chain, and revocation status. Works offline — no account needed. - [grantex manifest](https://docs.grantex.dev/cli/manifest.md): Browse, generate, and validate tool manifests — define your own or use 53 pre-built ones. - [grantex enforce](https://docs.grantex.dev/cli/enforce.md): Dry-run scope enforcement from the command line. Test whether a grant token permits a specific tool call before deploying. - [Conformance Suite](https://docs.grantex.dev/integrations/conformance.md): Validate that your Grantex server implementation is spec-compliant with automated black-box testing. - [Conformance Status](https://docs.grantex.dev/integrations/conformance-results.md): How to obtain current, reproducible Grantex conformance results. - [API Reference](https://docs.grantex.dev/api-reference/introduction.md): Complete REST API reference for the Grantex Auth Service - [Health check](https://docs.grantex.dev/api-reference/system/health-check.md) - [Json web key set](https://docs.grantex.dev/api-reference/system/json-web-key-set.md) - [Developer dashboard](https://docs.grantex.dev/api-reference/system/developer-dashboard.md) - [Principal permissions dashboard](https://docs.grantex.dev/api-reference/system/principal-permissions-dashboard.md) - [Register a new developer account](https://docs.grantex.dev/api-reference/authentication/register-a-new-developer-account.md) - [Get current developer profile](https://docs.grantex.dev/api-reference/authentication/get-current-developer-profile.md) - [Rotate api key](https://docs.grantex.dev/api-reference/authentication/rotate-api-key.md) - [Send verification](https://docs.grantex.dev/api-reference/signup/send-verification.md) - [Verify token](https://docs.grantex.dev/api-reference/signup/verify-token.md) - [Register a new agent](https://docs.grantex.dev/api-reference/agents/register-a-new-agent.md) - [List all agents](https://docs.grantex.dev/api-reference/agents/list-all-agents.md) - [Get agent by id](https://docs.grantex.dev/api-reference/agents/get-agent-by-id.md) - [Update an agent](https://docs.grantex.dev/api-reference/agents/update-an-agent.md) - [Delete an agent](https://docs.grantex.dev/api-reference/agents/delete-an-agent.md) - [Create an authorization request](https://docs.grantex.dev/api-reference/authorization/create-an-authorization-request.md) - [Approve an authorization request](https://docs.grantex.dev/api-reference/authorization/approve-an-authorization-request.md) - [Deny an authorization request](https://docs.grantex.dev/api-reference/authorization/deny-an-authorization-request.md) - [Exchange authorization code for grant token](https://docs.grantex.dev/api-reference/tokens/exchange-authorization-code-for-grant-token.md) - [Refresh a grant token](https://docs.grantex.dev/api-reference/tokens/refresh-a-grant-token.md) - [Verify a grant token online](https://docs.grantex.dev/api-reference/tokens/verify-a-grant-token-online.md) - [Revoke a grant token](https://docs.grantex.dev/api-reference/tokens/revoke-a-grant-token.md) - [Stream](https://docs.grantex.dev/api-reference/events/stream.md) - [Websocket](https://docs.grantex.dev/api-reference/events/websocket.md) - [List grants](https://docs.grantex.dev/api-reference/grants/list-grants.md) - [Get grant by id](https://docs.grantex.dev/api-reference/grants/get-grant-by-id.md) - [Revoke a grant](https://docs.grantex.dev/api-reference/grants/revoke-a-grant.md) - [Verify a grant tokens revocation status](https://docs.grantex.dev/api-reference/grants/verify-a-grant-tokens-revocation-status.md) - [Delegate a grant to a sub agent](https://docs.grantex.dev/api-reference/grants/delegate-a-grant-to-a-sub-agent.md) - [Log an audit entry](https://docs.grantex.dev/api-reference/audit/log-an-audit-entry.md) - [List audit entries](https://docs.grantex.dev/api-reference/audit/list-audit-entries.md) - [Get audit entry by id](https://docs.grantex.dev/api-reference/audit/get-audit-entry-by-id.md) - [Create an access policy](https://docs.grantex.dev/api-reference/policies/create-an-access-policy.md) - [List access policies](https://docs.grantex.dev/api-reference/policies/list-access-policies.md) - [Get policy by id](https://docs.grantex.dev/api-reference/policies/get-policy-by-id.md) - [Update a policy](https://docs.grantex.dev/api-reference/policies/update-a-policy.md) - [Delete a policy](https://docs.grantex.dev/api-reference/policies/delete-a-policy.md) - [Sync policy bundle](https://docs.grantex.dev/api-reference/policies/sync-policy-bundle.md) - [List bundles](https://docs.grantex.dev/api-reference/policies/list-bundles.md) - [Active bundle](https://docs.grantex.dev/api-reference/policies/active-bundle.md) - [Sync webhook](https://docs.grantex.dev/api-reference/policies/sync-webhook.md) - [Register a webhook](https://docs.grantex.dev/api-reference/webhooks/register-a-webhook.md) - [List webhooks](https://docs.grantex.dev/api-reference/webhooks/list-webhooks.md) - [Delete a webhook](https://docs.grantex.dev/api-reference/webhooks/delete-a-webhook.md) - [Get current subscription](https://docs.grantex.dev/api-reference/billing/get-current-subscription.md) - [Create a stripe checkout session](https://docs.grantex.dev/api-reference/billing/create-a-stripe-checkout-session.md) - [Create a stripe billing portal session](https://docs.grantex.dev/api-reference/billing/create-a-stripe-billing-portal-session.md) - [Stripe webhook handler](https://docs.grantex.dev/api-reference/billing/stripe-webhook-handler.md) - [Run anomaly detection](https://docs.grantex.dev/api-reference/anomalies/run-anomaly-detection.md) - [List detected anomalies](https://docs.grantex.dev/api-reference/anomalies/list-detected-anomalies.md) - [Acknowledge an anomaly](https://docs.grantex.dev/api-reference/anomalies/acknowledge-an-anomaly.md) - [List alerts](https://docs.grantex.dev/api-reference/anomalies/list-alerts.md) - [Acknowledge alert](https://docs.grantex.dev/api-reference/anomalies/acknowledge-alert.md) - [Resolve alert](https://docs.grantex.dev/api-reference/anomalies/resolve-alert.md) - [Get metrics](https://docs.grantex.dev/api-reference/anomalies/get-metrics.md) - [List rules](https://docs.grantex.dev/api-reference/anomalies/list-rules.md) - [Create rule](https://docs.grantex.dev/api-reference/anomalies/create-rule.md) - [Delete rule](https://docs.grantex.dev/api-reference/anomalies/delete-rule.md) - [List channels](https://docs.grantex.dev/api-reference/anomalies/list-channels.md) - [Create channel](https://docs.grantex.dev/api-reference/anomalies/create-channel.md) - [Delete channel](https://docs.grantex.dev/api-reference/anomalies/delete-channel.md) - [Get compliance summary](https://docs.grantex.dev/api-reference/compliance/get-compliance-summary.md) - [Export grants for compliance](https://docs.grantex.dev/api-reference/compliance/export-grants-for-compliance.md) - [Export audit entries for compliance](https://docs.grantex.dev/api-reference/compliance/export-audit-entries-for-compliance.md) - [Generate compliance evidence pack](https://docs.grantex.dev/api-reference/compliance/generate-compliance-evidence-pack.md) - [Create a scim provisioning token](https://docs.grantex.dev/api-reference/scim/create-a-scim-provisioning-token.md) - [List scim tokens](https://docs.grantex.dev/api-reference/scim/list-scim-tokens.md) - [Delete a scim token](https://docs.grantex.dev/api-reference/scim/delete-a-scim-token.md) - [Scim service provider configuration](https://docs.grantex.dev/api-reference/scim/scim-service-provider-configuration.md) - [List scim users](https://docs.grantex.dev/api-reference/scim/list-scim-users.md) - [Create a scim user](https://docs.grantex.dev/api-reference/scim/create-a-scim-user.md) - [Get scim user by id](https://docs.grantex.dev/api-reference/scim/get-scim-user-by-id.md) - [Replace a scim user](https://docs.grantex.dev/api-reference/scim/replace-a-scim-user.md) - [Patch a scim user](https://docs.grantex.dev/api-reference/scim/patch-a-scim-user.md) - [Delete a scim user](https://docs.grantex.dev/api-reference/scim/delete-a-scim-user.md) - [Configure oidc sso](https://docs.grantex.dev/api-reference/sso/configure-oidc-sso.md) - [Get sso configuration](https://docs.grantex.dev/api-reference/sso/get-sso-configuration.md) - [Remove sso configuration](https://docs.grantex.dev/api-reference/sso/remove-sso-configuration.md) - [Initiate sso login](https://docs.grantex.dev/api-reference/sso/initiate-sso-login.md) - [Sso callback](https://docs.grantex.dev/api-reference/sso/sso-callback.md) - [Create sso connection](https://docs.grantex.dev/api-reference/sso/create-sso-connection.md) - [List sso connections](https://docs.grantex.dev/api-reference/sso/list-sso-connections.md) - [Update sso connection](https://docs.grantex.dev/api-reference/sso/update-sso-connection.md) - [Delete sso connection](https://docs.grantex.dev/api-reference/sso/delete-sso-connection.md) - [Test sso connection](https://docs.grantex.dev/api-reference/sso/test-sso-connection.md) - [Set sso enforcement](https://docs.grantex.dev/api-reference/sso/set-sso-enforcement.md) - [List sso sessions](https://docs.grantex.dev/api-reference/sso/list-sso-sessions.md) - [Revoke sso session](https://docs.grantex.dev/api-reference/sso/revoke-sso-session.md) - [Oidc callback](https://docs.grantex.dev/api-reference/sso/oidc-callback.md) - [Saml callback](https://docs.grantex.dev/api-reference/sso/saml-callback.md) - [LDAP Callback](https://docs.grantex.dev/api-reference/sso/ldap-callback.md): Authenticate with the LDAP direct-bind preview and create an SSO session; directory, attribute, and group search are not performed. - [Create principal session](https://docs.grantex.dev/api-reference/principal-sessions/create-principal-session.md) - [List principal grants](https://docs.grantex.dev/api-reference/principal-sessions/list-principal-grants.md) - [Get principal audit](https://docs.grantex.dev/api-reference/principal-sessions/get-principal-audit.md) - [Revoke principal grant](https://docs.grantex.dev/api-reference/principal-sessions/revoke-principal-grant.md) - [Consent ui page](https://docs.grantex.dev/api-reference/consent/consent-ui-page.md) - [Get consent request details](https://docs.grantex.dev/api-reference/consent/get-consent-request-details.md) - [Approve consent end user action](https://docs.grantex.dev/api-reference/consent/approve-consent-end-user-action.md) - [Deny consent end user action](https://docs.grantex.dev/api-reference/consent/deny-consent-end-user-action.md) - [Generate registration options](https://docs.grantex.dev/api-reference/webauthn/generate-registration-options.md) - [Verify registration](https://docs.grantex.dev/api-reference/webauthn/verify-registration.md) - [List credentials](https://docs.grantex.dev/api-reference/webauthn/list-credentials.md) - [Delete credential](https://docs.grantex.dev/api-reference/webauthn/delete-credential.md) - [Generate assertion options](https://docs.grantex.dev/api-reference/webauthn/generate-assertion-options.md) - [Verify assertion](https://docs.grantex.dev/api-reference/webauthn/verify-assertion.md) - [Allocate Budget](https://docs.grantex.dev/api-reference/budgets/allocate.md): Create a budget allocation for a grant, setting a spending cap for the agent. - [Debit Budget](https://docs.grantex.dev/api-reference/budgets/debit.md): Debit an amount from a grant's budget allocation. Returns 402 if the budget is insufficient. - [Get Budget Balance](https://docs.grantex.dev/api-reference/budgets/balance.md): Retrieve the current budget balance for a grant. - [List Budget Transactions](https://docs.grantex.dev/api-reference/budgets/transactions.md): Retrieve paginated transaction history for a grant's budget. - [List Budget Allocations](https://docs.grantex.dev/api-reference/budgets/allocations.md): List all budget allocations for the authenticated developer. - [Register Custom Domain](https://docs.grantex.dev/api-reference/domains/create.md): Register a custom domain on your Grantex account. Returns a token to add as a DNS TXT record. Requires Enterprise plan. Runtime traffic routing on your domain is on the roadmap; today endpoints still resolve under *.grantex.dev. - [List Custom Domains](https://docs.grantex.dev/api-reference/domains/list.md): List all custom domains registered by the authenticated developer. - [Verify Domain DNS](https://docs.grantex.dev/api-reference/domains/verify.md): Trigger DNS verification for a registered custom domain. - [Delete Custom Domain](https://docs.grantex.dev/api-reference/domains/delete.md): Remove a custom domain registration. - [Get Current Usage](https://docs.grantex.dev/api-reference/usage/current.md): Retrieve usage metrics for the current UTC date. - [Get Usage History](https://docs.grantex.dev/api-reference/usage/history.md): Retrieve daily usage breakdown over a specified number of days. - [Store Vault Credential](https://docs.grantex.dev/api-reference/vault/store.md): Store an encrypted service credential in the Grantex Vault for a principal. - [List Vault Credentials](https://docs.grantex.dev/api-reference/vault/list.md): List vault credential metadata for the authenticated developer. Does not return raw tokens. - [Get Vault Credential](https://docs.grantex.dev/api-reference/vault/get.md): Retrieve metadata for a specific vault credential. Does not return raw tokens. - [Delete Vault Credential](https://docs.grantex.dev/api-reference/vault/delete.md): Permanently delete a vault credential. - [Exchange Grant Token for Service Credential](https://docs.grantex.dev/api-reference/vault/exchange.md): Exchange a valid Grantex grant token for a stored upstream service credential. - [Consent Bundles API](https://docs.grantex.dev/api-reference/consent-bundles.md): API reference for offline consent bundle endpoints: create, list, revoke, and check revocation status. - [Offline Sync API](https://docs.grantex.dev/api-reference/offline-sync.md): API reference for syncing offline audit log entries to the Grantex cloud. - [Get credential](https://docs.grantex.dev/api-reference/credentials/get-credential.md) - [List credentials](https://docs.grantex.dev/api-reference/credentials/list-credentials.md) - [Verify credential](https://docs.grantex.dev/api-reference/credentials/verify-credential.md) - [Status list](https://docs.grantex.dev/api-reference/credentials/status-list.md) - [Create Consent Record](https://docs.grantex.dev/api-reference/dpdp/create-consent-record.md): Create a DPDP-compliant consent record linking a grant to a data principal with explicit purpose limitation. - [Get Consent Record](https://docs.grantex.dev/api-reference/dpdp/get-consent-record.md): Retrieve a single DPDP consent record by ID. Increments the access counter for audit purposes. - [List Consent Records](https://docs.grantex.dev/api-reference/dpdp/list-consent-records.md): List all DPDP consent records for the developer, with optional filtering by data principal. - [Withdraw Consent](https://docs.grantex.dev/api-reference/dpdp/withdraw-consent.md): Withdraw a DPDP consent record. Optionally revokes the underlying grant and deletes processed data. - [List Principal Records](https://docs.grantex.dev/api-reference/dpdp/list-principal-records.md): Retrieve all consent records for a specific data principal. Implements the right to access under DPDP Section 11. - [Request Erasure](https://docs.grantex.dev/api-reference/dpdp/request-erasure.md): Exercise the right to erasure for a data principal. Marks all consent records as erased, revokes associated grants, and anonymizes audit entries (DPDP Section 11). - [Create Consent Notice](https://docs.grantex.dev/api-reference/dpdp/create-consent-notice.md): Register a versioned consent notice. Required before creating consent records — the notice content is hashed and linked to each record. - [File Grievance](https://docs.grantex.dev/api-reference/dpdp/file-grievance.md): File a grievance on behalf of a data principal. Implements the grievance mechanism required by DPDP Section 13(6). - [Get Grievance](https://docs.grantex.dev/api-reference/dpdp/get-grievance.md): Retrieve the status and details of a DPDP grievance by ID. - [Create Export](https://docs.grantex.dev/api-reference/dpdp/create-export.md): Generate a compliance export for DPDP, GDPR Article 15, or EU AI Act conformance. Bundles consent records, audit logs, and grievances into a single report. - [Get Export](https://docs.grantex.dev/api-reference/dpdp/get-export.md): Retrieve a previously generated compliance export by ID. - [Did document](https://docs.grantex.dev/api-reference/did/did-document.md) - [Protocol Specification](https://docs.grantex.dev/protocol/specification.md): Grantex Protocol Specification v1.0 — the full normative document. - [Changelog and Release History](https://docs.grantex.dev/protocol/changelog.md): How to find current Grantex releases, package compatibility, and the canonical project changelog. - [Security Policy](https://docs.grantex.dev/security/overview.md): Supported versions, vulnerability reporting, and coordinated disclosure. - [Security Audit Report](https://docs.grantex.dev/security/audit-report.md): Third-party security assessment by Vestige Security Labs (February 2026). - [SOC 2 Readiness Control Mapping](https://docs.grantex.dev/security/soc2-report.md): Internal SOC 2 readiness control mapping for the Grantex Delegated Authorization Platform. - [Contributing](https://docs.grantex.dev/community/contributing.md): How to contribute to the Grantex project. - [IETF Internet-Draft](https://docs.grantex.dev/community/ietf-draft.md): Delegated Agent Authorization Protocol (DAAP) — active individual Internet-Draft with revision 02 published and revision 03 under review. - [Draft NIST NCCoE Public Comment](https://docs.grantex.dev/community/nist-comment.md): Grantex response to NIST NCCoE AI challenge areas — mapping DAAP to the AI Risk Management Framework. - [OpenID AuthZEN Mapping](https://docs.grantex.dev/community/authzen-mapping.md): How Grantex maps to the OpenID AuthZEN Authorization API for interoperable policy evaluation. - [How A Shopify Merchant Becomes An Agentic Commerce Seller](https://docs.grantex.dev/blog/oacp-shopify-merchant-agentic-commerce-seller.md): The Grantex authority view of Shopify onboarding through AgenticOrg and OACP artifacts. - [Merchant Self-Service Config Without Moving Commerce Truth Into Grantex](https://docs.grantex.dev/blog/oacp-merchant-self-service-config.md): How AgenticOrg lets merchants configure sources, channels, provider rails, public publishing, and Offline POS while Grantex remains OACP authority. - [Why OACP Keeps Buyer Agents Honest](https://docs.grantex.dev/blog/oacp-keeps-buyer-agents-honest.md): Why source, freshness, revocation, and non-enablement fields keep buyer agents from inventing commerce facts. - [How ChatGPT, Claude, Gemini, Perplexity, WhatsApp, And Telegram Can Shop Through Seller Agents](https://docs.grantex.dev/blog/oacp-buyer-surfaces-chatgpt-claude-gemini-perplexity-whatsapp-telegram.md): The buyer-surface bridge model for OACP-backed AgenticOrg seller agents. - [How OACP Maps To Schema.org, UCP, ACP, AP2, A2A, And MCP](https://docs.grantex.dev/blog/oacp-maps-to-protocols.md): A compatibility-mapping guide for protocol partners. - [Why Grantex Is Not A Transaction Toll Booth](https://docs.grantex.dev/blog/grantex-not-transaction-toll-booth.md): Why OACP authority signs artifacts without relaying every buyer and seller interaction. - [How Pine Labs Plural/P3P Mandate Capability Fits Into Agentic Commerce](https://docs.grantex.dev/blog/pine-labs-plural-p3p-oacp.md): The provider-owned mandate capability boundary in the OACP model. - [Source, Freshness, And Trust In AI Commerce](https://docs.grantex.dev/blog/source-freshness-trust-ai-commerce.md): How OACP makes source and freshness visible to buyer agents. - [The Buyer Journey From Question To Prepared Purchase Handoff](https://docs.grantex.dev/blog/buyer-journey-prepared-purchase-handoff.md): How OACP moves from discovery to prepared handoff without faking execution. - [Shopify, Grantex Commerce, And OACP: Current Boundary](https://docs.grantex.dev/blog/shopify-oacp-commerce-live-flow.md): Separates the Grantex Commerce payment-control pilot from the blocked AgenticOrg C6Z OACP runtime artifact vertical. - [Why OACP Commerce Needs A Readiness Gate](https://docs.grantex.dev/blog/commerce-live-readiness-gate.md): How Grantex separates OACP authority evidence from live payment, provider, POS, and merchant execution. - [DPDP Act 2023 and AI Agents: What Your Engineering Team Must Know](https://docs.grantex.dev/blog/dpdp-act-ai-agents.md): India's DPDP Act creates specific obligations for AI agent deployments. Here's what engineering teams need to implement. - [4 Agent Security Breaches That Should Change How You Think About API Keys](https://docs.grantex.dev/blog/agent-security-breaches-2025-2026.md): Shai-Hulud, SANDWORM_MODE, OpenClaw, and CVE-2026-21852 — the 2025-2026 incidents that proved AI agents need their own authorization layer, not shared secrets. - [OWASP Agentic Top 10: What It Means for Your AI Security Stack](https://docs.grantex.dev/blog/owasp-agentic-top-10-compliance.md): OWASP published the Agentic Security Top 10 in December 2025. The EU AI Act applies in phases, and NIST AI RMF is active now. Here is how the controls map to Grantex. - [From Copilot to Autonomous: Why Authorization Must Evolve with AI](https://docs.grantex.dev/blog/from-copilot-to-autonomous-agents.md): AI went from autocomplete to autonomous in three years. Authorization did not keep up. Here is why the shift from assisted to agentic AI demands a new security model. - [Agent Identity for Machine Payments: Why MPP Needs a Passport Layer](https://docs.grantex.dev/blog/mpp-agent-identity.md): Grantex adds verifiable agent and principal credential context that merchants can validate alongside independent payment and risk controls. - [Introducing Grantex: OAuth 2.0 for AI Agents](https://docs.grantex.dev/blog/introducing-grantex.md): Grantex is an open delegated authorization protocol that brings human-approved, scoped, revocable permissions to AI agents. - [Why AI Agents Need Their Own Authorization Protocol](https://docs.grantex.dev/blog/why-ai-agents-need-authorization.md): OAuth 2.0 was built for human users. AI agents have fundamentally different requirements -- here's why they need a purpose-built protocol. - [AI Agent Authorization Guide for 2026: Scopes, Consent, and Revocation](https://docs.grantex.dev/blog/ai-agent-authorization-guide.md): Implement AI agent authorization with scoped grants, consent, JWT verification, current revocation checks, and TypeScript and Python examples. - [How to Add Permissions to LangChain Agent Tools](https://docs.grantex.dev/blog/langchain-agent-permissions.md): Add scoped permissions to configured LangChain tools with verified Grantex JWTs, manifest enforcement, and optional grant-aware audit callbacks. - [MCP Server Authorization with OAuth 2.1 and Grantex](https://docs.grantex.dev/blog/mcp-server-oauth-authentication.md): Current MCP HTTP authorization, the OAuth 2.1 draft profile, and safe evaluation limits for @grantex/mcp-auth 2.0.2. - [Grantex v0.1: What's Included](https://docs.grantex.dev/blog/grantex-v0-1-whats-included.md): A complete tour of everything shipping in the Grantex v0.1 release -- SDKs, integrations, CLI, enterprise features, and more. - [Grantex v2.2: Policy Engines, A2A, and the Managed Cloud](https://docs.grantex.dev/blog/grantex-v2-2.md): v2.2 brings OPA and Cedar policy backends, Google A2A agent-to-agent bridging, a managed cloud offering, and SDK 0.2.0 across all three languages. - [Gemma 4 Just Shipped Offline AI Agents. Here's How to Secure Them.](https://docs.grantex.dev/blog/gemma-4-offline-agents-security.md): Gemma 4 enables offline agentic workflows on-device. But offline agents with no auth story are a security gap. Here's how @grantex/gemma closes it. ## OpenAPI Specs - [grantex-commerce-v1.openapi](/api/grantex-commerce-v1.openapi.yaml) - [openapi](/openapi.yaml)