Endpoint
Authentication
Requires a Grantex grant token (not an API key) in the Authorization header. This is a public endpoint — no developer API key is needed.
The grant token must also carry the explicit, exactly-matched exchange scope for the requested service:
vault:<service>:exchange (for example vault:github:exchange)
Rollout note (2026-09-13, security sweep). Releasing the raw upstream token is strictly more powerful than a <service>:read grant, so exchange no longer accepts wildcard or read-style scopes (*, <service>:*, <service>:read, <service>:credentials:read, vault:<service>:*, vault:<service>:read, vault:credentials:exchange). Grants issued with only those scopes will receive 403 FORBIDDEN from this endpoint after the rollout; re-issue them with vault:<service>:exchange. In addition, key-bound grant tokens (those carrying cnf.jkt) must now be presented with a DPoP proof (Authorization: DPoP <grant_token> plus a DPoP header whose htu is this endpoint and whose ath hashes the token); a bare Bearer presentation of a key-bound token is rejected with 401.
Request Body
Example Request
Response — 200 OK
Response — 200 OK (delivery: "reference")
No accessToken is returned. The reference is bound to the grant that obtained it,
expires after VAULT_CREDENTIAL_REFERENCE_TTL_SECONDS (300 by default), never later than the
grant token that obtained it, and is refused once the grant is revoked, stopped or expired. The agent presents it to the gateway as the
Grantex-Credential-Ref request header.
Response Fields
This endpoint returns the raw access token. The grant token’s sub (principal), dev (developer), and scp (scopes) claims are enforced before decrypting a credential. Keep grant scopes and expiry narrow.
Rate Limits
This endpoint is limited to 20 requests per minute per grant token.
Error Responses
How It Works
- The agent presents its Grantex grant token.
- The server verifies the JWT signature and extracts the
sub (principal ID), dev (developer ID), and scp (scopes) claims.
- The requested
service must match one of the token credential scopes listed above.
- The server looks up the vault credential matching
(developerId, principalId, service).
- If found, the encrypted access token is decrypted and returned.
This allows agents to access upstream services without ever seeing the raw credentials at configuration time — credentials are stored once by the developer and retrieved at runtime by authorized agents.
SDK Examples
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.