Overview
grantex enforce test lets you dry-run scope enforcement against a real grant token without writing any code. Pass a token, connector, and tool name to see whether the call would be allowed or denied, and why.
Prefer a secret-safe token source for agent automation:
Use --token-file <path> or --token-stdin as alternatives. Allowed decisions exit 0; denied or invalid decisions exit non-zero, including with --json.
grantex enforce test
Test whether a grant token permits a specific tool call.
Allowed Example
Denied Example
Capped Scopes
Use the --amount flag to test enforcement against capped scopes. From the
next SDK release, a capped scope denies a test without --amount
(amount_missing):
When within the cap:
Grant Token Audience
Available in @grantex/cli@0.4.0 with SDK 0.8.0. Node.js 22.12+
is required; audience binding and default online revocation are breaking changes.
A grant token requested with an audience carries it in the aud claim, and
enforce() denies it unless the relying party expects that audience (see
Grant token audience). Pass
the audience your service is issued tokens for with --audience:
Without --audience, a token that carries aud is reported as denied with
token_invalid / audience_unconfigured; a token whose aud does not contain
the --audience value is denied with token_invalid / audience_mismatch.
--audience-check off ignores aud, as earlier releases did:
--audience-check takes on (the default) or off; any other value is
refused. --audience cannot be empty or combined with --audience-check off,
and both options are refused when the installed @grantex/sdk does not check
the audience, instead of being ignored.
JSON Output
Use --json for machine-readable output, useful for scripting and CI pipelines:
Allowed result:
Options
Exit Codes
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.Last modified on September 28, 2026