# `Accrue.Entitlements.PastDueGrace`
[🔗](https://github.com/szTheory/accrue/blob/accrue-v1.5.1/lib/accrue/entitlements/past_due_grace.ex#L1)

Pure, clock-driven past-due grace-window check (ENT-09, D-17).

`within_grace?/2` answers whether a `:past_due` subscription is still
inside a configured grace window measured from its `past_due_since`
timestamp. The window is `now - past_due_since <= grace_days * 86_400`,
computed against `Accrue.Clock.utc_now/0` (the testable clock, never the
raw BEAM wall-clock) so the check is deterministic under the Fake test
clock.

Fail-closed by construction: a `nil` `past_due_since`, a non-positive
`grace_days`, or a non-DateTime `past_due_since` all return `false`. A
grant is therefore always an affirmative, resolved, configured decision —
never a fail-open (preserving the headline fail-closed contract).

Lives in the entitlements layer (it is config-coupled grace, reading the
`:entitlements`/`:dunning` policy via the caller), never on
`Accrue.Billing.Subscription`, which must not read config — keeping the
one-way dependency entitlements -> billing clean.

# `within_grace?`

```elixir
@spec within_grace?(map(), pos_integer()) :: boolean()
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
