Grant Auth
Documentation
Connect services once, choose an agent access profile, and use ordinary provider prompts through Grant.
Last updated July 15, 2026
Quick start
- Sign in and connect services. Open the dashboard and authorize each provider you want Grant to broker. Provider credentials remain server-side.
- Create an agent connection. Choose the agent client, trusted profile, provider capabilities, and resources the agent may use.
- Run the generated setup command once. Grant shows the exact command for the selected client and displays its agent token only at creation or rotation time.
- Start a fresh agent session. Ask ordinary questions such as “list my latest Vercel deployments.” The client can discover the selected Grant tools and route supported provider work without requiring Grant-specific wording.
Supported providers
Grant currently brokers selected native read and write capabilities for GitHub, Vercel, Convex, Clerk, PostHog, Google Search Console, Slack, Linear, and Supabase. The dashboard is authoritative for the capabilities and resources selectable on a specific connection.
Supported agents
The setup flow includes Codex, Claude Code, Cursor, OpenCode, Hermes, OpenClaw, Grok Build, and other remote MCP clients. Each client receives the same Grant MCP contract, client-appropriate provider-routing setup, and a separate revocable identity.
Permissions
Choose a read-only, full, or custom trusted profile. Custom profiles select the native provider capabilities and resources Grant can enforce. A profile is the one-time approval boundary for that agent; requests outside it are denied before Grant calls the provider.
Audit, rotation, and revocation
The dashboard records broker decisions without returning downstream credentials to the agent. Rotate an agent to stop its previous Grant token, or revoke it to deny future broker calls. Disconnect a provider to stop all Grant access through that connection; some providers also require upstream revocation in their own application settings, which the dashboard calls out.
Help
See support for access problems and security reports. Never send provider credentials, Grant agent tokens, private keys, passwords, or recovery codes in a support request.