Capabilities

Capability tokens replace API keys + OAuth scopes. Each one is a DID-signed grant scoped to a path pattern in your data — revoke any one and the holder is locked out instantly.

How scopes work: capability tokens scope by path pattern (per Data-Sovereignty-and-Grid-Auth.md §4.3) — not by flat application names. prefix grants access under a path; exact grants a single row; schema grants any row of a Grid-standard schema. Examples below.

Active capabilities4
CAPKINDSCOPEGRANTED TOISSUEDEXPIRES
cap_8f4e2aprefixdid:grid:mk/services/blog.grid/*did:grid:nora2026-03-122026-06-12
cap_92ab10prefixdid:grid:mk/services/comments-store/*did:grid:nora2026-03-28never
cap_110c3dexactdid:grid:mk/services/summarizer/invokedid:grid:agent-7f3e2026-04-022026-05-02
cap_2fae88prefixdid:grid:mk/services/app-api/*did:grid:bcamp2026-02-18never
Apps you've connected from the Store hold their own capability tokens — manage those at Connected apps →.