90-second demo grant

No auth — this is the keyless trial. Mints a 90-second grant, but only for verb: "demo_write" on a target starting with demo-. Anything else is a 400. Use it to prove the intercept loop (check → grant → check → ALLOW) without signing up; switch to POST /v1/keys for real verbs. Sandbox grants are not tenant-scoped.

Request

This endpoint expects an object.
sponsorIdstringRequired

The human sponsor on whose behalf the agent acts (e.g. s_42).

agentIdstringRequired

The agent performing the write (e.g. support-agent-07).

verbstringRequired

The consequential action (e.g. refund, provision, admit).

targetstringRequired

What the action applies to (e.g. order #88412).

purposestringRequired

Why — the stated intent, bound into the auth token (e.g. Refund order #88412, close ticket #2210).

ttlSecondsintegerOptional

Grants only: how long the grant lives. Default 90, min 1, max 3600.

Response

Sandbox grant created. Use it with POST /v1/check within 90 seconds.

Errors

400
Bad Request Error