> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cinder.exchange/llms.txt
> Use this file to discover all available pages before exploring further.

# Active grants

> Current Cinder agent terms and accepted-order budget usage.

**Carrier:** `POST /v1/exchange` (encrypted binary).

**Read family:** `grants` · **Permission:** owner or current READ agent.

Current Cinder agent terms and accepted-order budget usage. Results are private to the bound account. The same query is
available over HTTP and [WebSocket](/api/websocket), including subscriptions.

<Note>
  These are signed SDK fields and decoded results, not a plaintext JSON HTTP body.
  The shared carrier accepts encrypted `application/octet-stream`.
</Note>

<RequestExample>
  ```ts SDK request theme={null}
  const response = await client.request({
    id: ctx.id,
    epoch: ctx.epoch,
    expiresAt: ctx.expiresAt,
    command: {
      kind: 'read',
      query: { family: 'grants', limit: 32 },
    },
  });
  ```
</RequestExample>

<ResponseExample>
  ```ts Decoded page theme={null}
  ({
    kind: 'page',
    family: 'grants',
    revision: snapshotRevision,
    next: new Uint8Array(40),
    evaluatedAt: observedAt,
    rows: [
      {
        kind: 'grant',
        grant: {
          key: ctx.agentPublicKey, methods: READ | TRADE | CANCEL,
          market: ctx.market, maximumLots: 2n, maximumFee: 1n,
          maximumOrders: 10n, expiresAt: ctx.agentExpiresAt,
        },
        usedOrders: 1n,
      },
    ],
  })
  ```

  ```ts Stale cursor error theme={null}
  ({ kind: 'error', code: 'conflict' })
  ```
</ResponseExample>

## Request fields

Use the configured [client and envelope](/api/authentication). Each request supplies
`id`, current `epoch` and authentication `expiresAt`, as shown in the example.

<ParamField body="command.kind" type="&#x22;read&#x22;" required>
  Read-command discriminator.
</ParamField>

<ParamField body="command.query.family" type="&#x22;grants&#x22;" required>
  Selects this exact private projection.
</ParamField>

<ParamField body="command.query.limit" type="number" required>
  Integer from 1 to 64 rows. The example requests 32.
</ParamField>

<ParamField body="command.query.cursor" type="Uint8Array (40 bytes)">
  Omit or use all-zero bytes to start. For another page, use the prior page’s `next` under the same snapshot revision.
</ParamField>

## Response fields

Illustrative decoded SDK values are shown at the right; absent optional fields
mean unavailable, not zero. Empty `rows` is valid.

<ResponseField name="kind" type="&#x22;page&#x22;" required>
  Paged-response discriminator.
</ResponseField>

<ResponseField name="family" type="&#x22;grants&#x22;" required>
  The requested family.
</ResponseField>

<ResponseField name="revision" type="Uint8Array (32 bytes)" required>
  Commitment to the permitted snapshot and query identity, not a global activity counter.
</ResponseField>

<ResponseField name="next" type="Uint8Array (40 bytes)" required>
  Next cursor; all-zero means no more retained rows.
</ResponseField>

<ResponseField name="evaluatedAt" type="bigint (u64)" required>
  Qualified Cinder evaluation time, in milliseconds.
</ResponseField>

<ResponseField name="rows" type="ReadRow[]" required>
  At most the requested limit.

  <Expandable title="Active grants row fields">
    <ResponseField name="kind" type="&#x22;grant&#x22;" required>
      Grant-row discriminator.
    </ResponseField>

    <ResponseField name="grant" type="Grant" required>
      Active current-epoch agent terms.

      <Expandable title="grant fields">
        <ResponseField name="key" type="Uint8Array (32 bytes)" required>
          Agent Ed25519 public key.
        </ResponseField>

        <ResponseField name="methods" type="number" required>
          Permission mask: READ=1, TRADE=2, CANCEL=4.
        </ResponseField>

        <ResponseField name="market" type="Uint8Array (32 bytes)" required>
          One permitted market.
        </ResponseField>

        <ResponseField name="maximumLots" type="bigint (u64)" required>
          Maximum absolute lots per accepted order.
        </ResponseField>

        <ResponseField name="maximumFee" type="bigint (i128)" required>
          Maximum fee per lot, in quote atoms.
        </ResponseField>

        <ResponseField name="maximumOrders" type="bigint (u64)" required>
          Lifetime accepted-order budget for this epoch.
        </ResponseField>

        <ResponseField name="expiresAt" type="bigint (u64)" required>
          Agent expiry in milliseconds.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="usedOrders" type="bigint (u64)" required>
      Accepted-order budget consumed; exact retries do not consume another unit.
    </ResponseField>
  </Expandable>
</ResponseField>

## Behavior

The owner sees active grants; a READ agent sees only its own. Expired or revoked grants and other-agent directories are excluded. These terms are Cinder permissions, not native venue credentials.

## Paging and errors

Read queries do not change financial state or consume order budgets.
Permissions filter rows **before** paging. Changed permitted rows return encrypted
`conflict`; restart at zero instead of combining revisions. End-of-pages covers
retained rows, not complete external venue history.

See [paging](/api/reads/paging), [errors](/api/errors), [limits](/api/limits)
and [availability](/status). A disconnected subscription needs fresh attestation,
current authority and a replacement snapshot.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.