← Receivers

grant-capability

grant-capability family

Issue a scoped, time-boxed capability grant to a principal

Effect
ask
Awaits an outcome — the call returns the response below.
Caller
mint_capability
The class of authority the caller must already hold, decided from the attested context with no round trip.
Reversible
no
This cannot be undone. Dry-run it first where the contract allows.

Send it with your agent

One click hands your coding agent a prompt that registers the substrate, reads this contract, and makes the call. Launch opens the app; the others copy the prompt.

Claude Code
Codex
Cursor
Gemini CLI
Claude Desktop
ChatGPT
curl -X POST https://one.ie/api/ask/grant-capability \
  -H "Authorization: Bearer $ONE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"data": { "grantee": <string>, "actions": <string[]>, "scope": <string>, "valid_from": <number>, "valid_to": <number> }}'

The key is never in a link. npx -y @oneie/cli login writes it to ~/.config/oneie/key on your machine.

Request

Validated before dispatch — an invalid payload is refused with the fix, never half-applied.

  • grantee string required
  • actions string[] required
  • scope string required
  • valid_from number required
  • valid_to number required

Response

What comes back from the call.

  • outcome "granted"
  • id string
  • grantee string
  • scope string

Traffic

Every call to grant-capability, counted where it is dispatched — over HTTP or in-process alike. Aggregate only — no actor, no payload, no workspace.

Counting…

Wiring

Every place in the open source that names grant-capability, and the file that answers it. Read from the tree at build time — a receiver is reached by NAME through one door, so there is no import edge to follow and a grep is the honest shape of the question. Structure, not volume — the count is in Traffic above.

Called from

No caller in this repo. It is reached from outside — an agent, your code, or an MCP client.

Answered by

grant-capability Resolved outside this repo — the pay, channels or api worker answers it. Dispatched through POST /api/ask/grant-capability, after the envelope validates the payload.
JSON Schema
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "type": "object",
  "properties": {
    "grantee": {
      "type": "string",
      "minLength": 1
    },
    "actions": {
      "minItems": 1,
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "scope": {
      "type": "string",
      "minLength": 1
    },
    "valid_from": {
      "type": "number"
    },
    "valid_to": {
      "type": "number"
    }
  },
  "required": [
    "grantee",
    "actions",
    "scope",
    "valid_from",
    "valid_to"
  ]
}
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "type": "object",
  "properties": {
    "outcome": {
      "type": "string",
      "const": "granted"
    },
    "id": {
      "type": "string"
    },
    "grantee": {
      "type": "string"
    },
    "scope": {
      "type": "string"
    }
  },
  "required": [
    "outcome",
    "id",
    "grantee",
    "scope"
  ]
}