Skip to main content

Overview

grantex enforce test lets you dry-run scope enforcement against a real grant token without writing any code. Pass a token, connector, and tool name to see whether the call would be allowed or denied, and why.
Prefer a secret-safe token source for agent automation:
Use --token-file <path> or --token-stdin as alternatives. Allowed decisions exit 0; denied or invalid decisions exit non-zero, including with --json.

grantex enforce test

Test whether a grant token permits a specific tool call.

Allowed Example

Denied Example


Capped Scopes

Use the --amount flag to test enforcement against capped scopes. From the next SDK release, a capped scope denies a test without --amount (amount_missing):
When within the cap:

Grant Token Audience

Available in @grantex/cli@0.4.0 with SDK 0.8.0. Node.js 22.12+ is required; audience binding and default online revocation are breaking changes.
A grant token requested with an audience carries it in the aud claim, and enforce() denies it unless the relying party expects that audience (see Grant token audience). Pass the audience your service is issued tokens for with --audience:
Without --audience, a token that carries aud is reported as denied with token_invalid / audience_unconfigured; a token whose aud does not contain the --audience value is denied with token_invalid / audience_mismatch. --audience-check off ignores aud, as earlier releases did:
--audience-check takes on (the default) or off; any other value is refused. --audience cannot be empty or combined with --audience-check off, and both options are refused when the installed @grantex/sdk does not check the audience, instead of being ignored.

JSON Output

Use --json for machine-readable output, useful for scripting and CI pipelines:
Allowed result:

Options


Exit Codes


Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 28, 2026