Protected device login
The endpoint creates its own Ed25519 identity and PKCE verifier. The QR contains only a one-time HTTPS verification URL and user code.
GrantTap Enterprise
GrantTap adds a managed authorization layer to local Codex, Claude Code, Cursor, Copilot, and Grok workflows—without moving source code, prompts, or model traffic into a GrantTap control service.
Implemented foundation
A managed endpoint validates its enrollment, fresh login receipt, policy signature, tenant, subject, revision, and authorization epoch before local or agent approval can grant authority.
The endpoint creates its own Ed25519 identity and PKCE verifier. The QR contains only a one-time HTTPS verification URL and user code.
Organization policy is pinned to tenant, subject, issuer key, revision, expiry, and authorization epoch.
An invalid, expired, missing, or rolled-back managed policy denies managed capabilities before provider approval.
The same GrantTap installation serves all supported coding agents; adapters attach to that installation instead of creating separate helpers.
Account and sign-in
Scan a one-time QR with GrantTap on iPhone. The encrypted browser workspace supports owner, admin, and approver roles plus one-time invitation links.
Sign in with iPhone →Enterprise machines use a device-bound login receipt issued by the organization's GrantTap Control deployment. Phone pairing and provider credentials remain separate.
Control plane status
Bring your identity provider, device fleet, and policy model. We will map the production control-plane rollout without weakening the endpoint boundary.
Contact Enterprise →