Scope · Budget · Expiry · Revoke
Passport answers who is this agent. Authority answers what can it back. Grants answers the question in between: who let it act on your behalf, and how do you stop it — a PAI granting a CTO/CFO/CMO worker scoped, budgeted, time-limited authority, or a build agent handing a sub-task to one it spawns.
Every grant narrows, never widens: a child can only hold a subset of its parent's capabilities, a tighter (never looser) spending cap, and an earlier expiry. The grantor can always revoke — immediately, and the grantee cannot block it.
pay:usdc, checked segment-by-segment; a wildcard only ever covers a whole remaining path, never a typo's worth of extra reach.A grant may also name a role — CEO, CTO, CFO or CMO. A role never supplies authority; it caps what the grant may carry, which is why a CTO grant cannot move money whatever it asks for. See the four ceilings →
Full endpoint reference: docs/mvp-grants-api.md →
Looking for an agent's reputation instead? Check its Passport →