- Holder
- An agent, for minutes — not a standing key
- Audience
- One named tool or gateway
- Scope
- Only the capabilities on this slip
- Afterward
- Revoke the ticket. Keep the receipt.
Not a vault. Not a login. A thin issuer.
Checking issuer… Live issuer status
mint → verify → revoke → receipts in one thin issuer
Short-lived tickets that prove what an agent is allowed to do — without handing it a long-lived secret. Built for gateways and tool hosts. No dashboard yet.
Contact: Grantslip@proton.me
Agents mint free. Gateways and tool hosts try hosted verify 2 weeks free, then $199/mo per gateway team.
Not a vault. Not a login. A thin issuer.
Grantslip is a thin issuer of capability tickets. An agent mints a short-lived ticket for a specific tool and a specific scope, presents that ticket on the call, and your gateway asks Grantslip whether the ticket still stands. When the job is done — or if something looks wrong — you revoke it. Successful uses can leave an immutable receipt.
That is the whole product today: mint → verify → revoke → receipts. One issuer, no console, no identity product wrapped around it.
Gateways and tool hosts that let AI agents call real tools — and need those agents to prove scope without sharing long-lived secrets.
You are opening tools to agents and need a clear yes/no at the door: this agent, this action, this window of time. Grantslip is the ticket, not another control plane for your customers to learn.
You should not paste a production API key into an agent runtime and hope the prompt holds. Tickets expire, revoke, and leave a receipt. That is the story you can tell a design partner in twenty minutes.
Point the SDK at the hosted issuer, mint a ticket, verify on the tool host. The API is small on purpose. Details live in the repo README — without you needing to become a token-format expert first.
Four steps. The issuer stays thin on purpose.
The agent asks Grantslip for a short-lived ticket: who it is, which tool it may call, and what it is allowed to do. Agents mint free through the SDK.
The agent calls your gateway or tool and presents the ticket. No standing secret has to live on the agent for that call.
Your host asks Grantslip: is this ticket valid, in scope, and not revoked? Hosted verify is the paid moment — it sits on the request path.
Pull the ticket when the job ends, or if you need to cut it off. Keep receipts of what was allowed or denied.
Agents mint free. Gateways and tool hosts try hosted verify 2 weeks free, then $199/mo per gateway team.
Agents
An agent can mint a ticket through the SDK at no charge. We want the thing that writes the ticket to be cheap and easy, so design partners can try the loop without a procurement conversation.
Gateways & tool hosts
The check on the request path is the product. Try hosted verify 2 weeks free, then $199/mo per gateway team — not for a vault, not for a login, and not for a dashboard we have not built.
Your own server
$1,500 one-time
Run the issuer on a computer you control. You hold the signing key. No monthly plan and no per-seat fee. Your gateway calls verify on that server. We do not host it for you. Mac build not yet notarized and Windows build unsigned, so your system will warn.
Humans read this page. Agents and gateways talk to the issuer.
Issuer base URL
https://grantslip-issuer.fly.dev
Point the SDK at that Grantslip issuer origin (no trailing slash). Liveness is
GET /health, which returns { ok: true }.
Checking issuer… Open /health
Start a trial, not a spec dive
The repo README walks the loop: mint, verify, revoke, receipts. You do not need to learn token internals to book a design-partner session.
What a refused call looks like
When an agent calls a tool without a valid badge, your gateway refuses the call and tells the agent how to fix it:
Ticket required. Mint a Grantslip visitor badge for this scope, attach it, and retry once.
A retry with a valid badge goes through and leaves a receipt.
A Grantslip teammate will walk you through the mint → verify → revoke loop against the live issuer and answer whether Grantslip fits your gateway. No slideware required.
Email the team — Grantslip@proton.me