Feegrant runtime
Two Terp keys, never the same:
| Role | Does |
|---|---|
| Runtime | Long-lived. Grants authz to HashMerchant for MsgGrantAllowance / MsgRevokeAllowance only. Never fee.granter for a customer. |
| HashMerchant | Temporary. Signs one-time customer feegrants via MsgExec. |
The customer allowance is gas for MsgAddAuthenticator only, spend limit 25000 uthiol, plus a separate 1 THIOL MsgSend for runway (not inside AllowedMsgAllowance).
POST /onboard/v1/mint-grant is 404. DREGG mints; HashMerchant does not pay the NFT.