docs auth feat/durable-agent-auth-phase-c #4 / 4
aaronrene · 42 days ago · Jul 27, 2026 · Diff

docs(auth): clear Phase C freeze for scoped REST agent credentials

Thinking freeze for DURABLE-AGENT-AUTH-C (kt_agent_ + agent_access JWT, Netlify mint/list/revoke/rotate/exchange, propose-scope REST). Freeze-review pass; boards point NEXT at C-b Auto. Trend-agent wiring remains follow-on.

sha256:e81978a957c8e61ce6916b2848fbe96b4f6428d358c57314e51768feb1af146b sha
+62 ~4 −5 symbols
sha256:145fe53cd11fb00376cd2e265533516faa8741e560b77a3b6f740eab66fe58da snapshot
+62
symbols added
~4
symbols modified
−5
symbols removed
0
dead code introduced
Semantic Changes 71 symbols
+ Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials section Durable Agent Auth Phase C — frozen spec: scoped REST agent credentials L1–479
+ Plain-language summary section 1. Plain-language summary L53–65
+ Technical summary section Technical summary L59–65
+ Docs amendments (same PR as Auto) section 10. Docs amendments (same PR as Auto) L391–405
+ table section table L393–400
+ Test matrix (seven tiers — Aaron standard) section 11. Test matrix (seven tiers — Aaron standard) L405–421
+ table section table L407–416
+ Fail-closed rules (checklist) section 12. Fail-closed rules (checklist) L421–436
+ Implementation map (Auto; no redesign) section 13. Implementation map (Auto; no redesign) L436–451
+ table section table L438–448
+ Tier-3 gates (do not execute in Auto) section 14. Tier-3 gates (do not execute in Auto) L451–459
+ Review record section 15. Review record L459–468
+ table section table L461–465
+ Definition of Done (Phase C Auto) — after this freeze passes review section 16. Definition of Done (Phase C Auto) — after this freeze passes review L468–479
+ Ground truth — what the code does today (file+line) section 2. Ground truth — what the code does today (file+line) L65–94
+ table section table L71–89
+ Incident diagnosis — why the trend-agent path dies section 3. Incident diagnosis — why the trend-agent path dies L94–126
+ 1 Error classes (server) class section 3.1 Error classes (server) L96–105
+ table section table L98–104
+ 2 Why Phase A/B cannot fix this consumer section 3.2 Why Phase A/B cannot fix this consumer L105–112
+ 3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip section 3.3 Reliability follow-on (server) — in scope for diagnosis, Tier-3 for prod flip L112–126
+ table section table L116–121
+ Frozen product goal section 4. Frozen product goal L126–140
+ Token shape (frozen) section 5. Token shape (frozen) L140–185
+ 1 Opaque agent credential (long-lived secret) section 5.1 Opaque agent credential (long-lived secret) L142–158
+ table section table L144–154
+ 2 Access JWT (short-lived) section 5.2 Access JWT (short-lived) L158–176
+ table section table L162–173
+ 3 Explicit non-goals for token shape section 5.3 Explicit non-goals for token shape L176–185
+ Hub APIs (frozen) section 6. Hub APIs (frozen) L185–292
+ 1 Mint — POST api/v1/auth/agent/credentials section 6.1 Mint — POST api/v1/auth/agent/credentials L189–240
+ code[json]@L195 variable variable code[json]@L195 L195–203
+ code[json]@L224 variable variable code[json]@L224 L224–235
+ table@L204 section table@L204 L204–210
+ table@L213 section table@L213 L213–219
+ 2 Exchange — POST api/v1/auth/agent/token section 6.2 Exchange — POST api/v1/auth/agent/token L240–264
+ code[json] variable variable code[json] L246–255
+ 3 List — GET api/v1/auth/agent/credentials section 6.3 List — GET api/v1/auth/agent/credentials L264–270
+ 4 Revoke — DELETE api/v1/auth/agent/credentials/:id section 6.4 Revoke — DELETE api/v1/auth/agent/credentials/:id L270–276
+ 5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate section 6.5 Rotate — POST api/v1/auth/agent/credentials/:id/rotate L276–280
+ 6 Store section 6.6 Store L280–292
+ table section table L282–289
+ REST acceptance + scope enforcement (frozen) section 7. REST acceptance + scope enforcement (frozen) L292–350
+ 1 getUserId / authz extensions section 7.1 getUserId / authz extensions L294–307
+ 2 agentScopesPermitMethod(scopes, method, path) method section 7.2 agentScopesPermitMethod(scopes, method, path) L307–316
+ 1 Mint scope defaults section 7.2.1 Mint scope defaults L316–320
+ 3 Propose-create path allowlist (Phase C) section 7.3 Propose-create path allowlist (Phase C) L320–334
+ 4 Vault binding section 7.4 Vault binding L334–340
+ 5 Self-apply / SEC-KN-3 section 7.5 Self-apply / SEC-KN-3 L340–344
+ 6 MCP optional bridge section 7.6 MCP optional bridge L344–350
+ Hub UI (frozen) section 8. Hub UI (frozen) L350–372
+ code[text] variable variable code[text] L359–364
+ Primary consumer contract — VideoFactory-trend-agent (follow-on) section 9. Primary consumer contract — VideoFactory-trend-agent (follow-on) L372–391
+ table section table L376–386
+ Freeze-contract declaration section Freeze-contract declaration L13–53
+ code[yaml] variable variable code[yaml] L15–46
~ docs/KNOWTATION-OVERSEER-HANDOVER.md .md 6 symbols added, 5 symbols removed, 1 symbol modified
NEXT SESSION — build-verification FINISH-COMPLETE-APPLY-KN-b (PRIMARY) section NEXT SESSION — build-verification FINISH-COMPLETE-APPLY-KN-b (PRIMARY) L21–63
Paste-ready prompt — FINISH-COMPLETE-APPLY-KN-b section Paste-ready prompt — FINISH-COMPLETE-APPLY-KN-b L43–63
code[text] variable variable code[text] L45–60
THE ONE NEXT STEP — Model: Thinking section THE ONE NEXT STEP — Model: Thinking L34–43
table section table L36–42
+ NEXT SESSION — DURABLE-AGENT-AUTH-C-b Auto (PRIMARY) section NEXT SESSION — DURABLE-AGENT-AUTH-C-b Auto (PRIMARY) L21–70
+ Parallel / parked — FINISH-COMPLETE-APPLY-KN-b BV section Parallel / parked — FINISH-COMPLETE-APPLY-KN-b BV L63–70
+ Paste-ready prompt — DURABLE-AGENT-AUTH-C-b section Paste-ready prompt — DURABLE-AGENT-AUTH-C-b L44–63
+ code[text] variable variable code[text] L46–62
+ THE ONE NEXT STEP — Model: Auto section THE ONE NEXT STEP — Model: Auto L35–44
+ table section table L37–43

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:e81978a957c8e61ce6916b2848fbe96b4f6428d358c57314e51768feb1af146b --body "your comment"