HomeIntegrations › Add authorization to an Express API
Integration

Add authorization to an Express API

One Node-native middleware protects any Express or Connect route with warrant-based authorization.

Why authorize Express tools?

When an AI agent calls your HTTP API, an API key says who but not what they may do right now. A warrant says exactly what: which routes, which methods, how much spend, until when. httpEnforcer is a plain (req, res, next) middleware — it extracts the warrant, checks it, and 403s with reasons on deny.

Add the middleware

import { httpEnforcer, createClient } from 'liceat';
const client = createClient({ gateway: 'https://liceat.com' });
const method = { GET: 'read', POST: 'write', PUT: 'write', DELETE: 'write' };

app.use(httpEnforcer({
  decide: client.decider(),
  map: (req) => ({ resource: 'api:myservice' + req.url.split('?')[0], action: method[req.method] }),
}));
// Denied → 403 {error, reasons}. Allowed → next().

What you get

Frequently asked

What is Liceat?

Liceat is permission infrastructure for AI agents. You issue a warrant — a scoped, spend-capped, revocable token — that grants an agent narrow authority; the agent presents it at the point of action; Liceat enforces it (scope, spend, rate, holder-binding, revocation) and records every decision in a tamper-evident log. It is open source with a zero-dependency SDK for TypeScript and Python.

Is it free?

The SDK and self-hosted gateway are free and open source. The hosted gateway at liceat.com gives 10,000 free decisions with no card, then meters at fractions of a cent per decision — payable by card or USDC.

Give your agents permission, not your keys.

Free to self-host. 10,000 free decisions on the hosted gateway — no card.

Get an API key Read the docs