Usually, the grantRequest will be exactly identical to the body received by the custom security backend. In the security backend, you merely decide which grant requests to forward and which not to forward.
If you want to revoke the grant at a later point in time, you can do this using: