Skip to main content

Current published releases

Last verified: July 12, 2026 Grantex packages are versioned independently. There is no single version number that represents every SDK, integration, service, and protocol artifact in this repository.
The SDK patch versions differ because each language package is released on its own schedule. A newer package version does not imply a newer protocol or API contract version.

Repository changes awaiting publication

As of July 14, 2026, repository source on main corrects the documented Go Agent/Audit read/write contracts, removes unsupported audit filters and list metadata, and URL-encodes query values. No corrected Go module tag is published. Standard developer API-key plan throughput is also source-only; custom-auth quotas and managed rollout remain separate.

Which Grantex package should I use?

  • TypeScript application: use @grantex/sdk@0.3.13.
  • Python application: use grantex==0.3.14.
  • Go application: use github.com/mishrasanjeev/grantex-go@v0.1.10 with the published-version workarounds, including the REST/CLI audit-write workaround.
  • MCP HTTP transport authorization: use an established MCP-compatible authorization server and maintained MCP SDK that implement the current MCP authorization specification.
  • Agent-specific MCP tool enforcement: after transport authorization, use a primary Grantex SDK or direct JWKS validation at each tool boundary. Treat @grantex/mcp-auth@2.0.2 as single-process evaluation software.
  • Current revocation: local JWT verification is insufficient by itself; perform an online state check or synchronize revocation data.

Known limitations in the current published artifacts

Go SDK v0.1.10: registration responses use agentId, but Agent.ID expects id; derive the ID from did:grantex:<agentId>. Registration also sends optional zero values, while updates cannot set status or clear scopes; provide registration fields and use REST for those updates.LogAuditParams lacks required agentDid and principalId; use REST or CLI for audit writes. AuditEntry omits DeveloperID, and Since, Until, Page, and PageSize list filters are ignored by the API; use the four supported filters and raw REST responses when developerId is required.Agent and audit list metadata is not returned; use slice lengths. List helpers also fail to URL-encode reserved filter characters; avoid those values or issue a net/url-encoded REST request. These workarounds remain required until a corrected module release is published.
MCP Auth 2.0.2: use a single process for evaluation only. Authorization codes are always process-local, consentUi does not create a page, onTokenIssued is not called, allowedRedirectUris is not a server-wide allowlist, middleware/introspection do not check current revocation state, and the Grantex authorization code is not persisted for the token handler. See MCP Auth Server for the detailed endpoint and deployment matrix.

Reproducible installation

Pin exact versions in applications, examples, CI, and deployment manifests:
Unpinned npm install, pip install, and go get commands resolve according to their registries and module proxy. Use the pinned commands above when the build must be repeatable.

How to read release information

Upgrade checklist

  1. Read the package-specific notes in the compatibility matrix and changelog.
  2. Confirm the required Node.js, Python, or Go toolchain version.
  3. Update the exact dependency version and regenerate the relevant lockfile.
  4. Run your authorization, token-verification, scope-enforcement, and revocation tests before deployment.
  5. For self-hosted environments, verify the API contract used by your service; an SDK-only patch does not upgrade the service automatically.
Do not infer publication from a repository manifest or marketing page alone. Confirm the exact artifact on its public registry before promoting a release.
Last modified on July 14, 2026