Trust live demo · read-only

Access & Grants

Access & Grants

Grants decide who (an API key, agent, module, or role) may call which tools (a glob like booking_*) up to a ceiling (read / write / destructive). External callers are default-deny: with no matching grant, the gateway refuses. Destructive tools always require an explicit grant.

Grants (demo)
CallerTool patternMax effectsRate tier
receptionist@v3 (agent)booking_*writeagent
support (api-key)*_list_*readsupport
client_owner (role)*destructiveowner