#100 FTX-100: last_used_at is never written — the API reports a permanently-null field operators use to triage keys
Description
EditEARS SPEC:
- When an API key successfully authenticates a request, Futex shall record the time of use on that key.
- The Futex API key listings shall report a last_used_at that reflects actual use.
- If the last-used bookkeeping write fails, then authentication shall still succeed.
CAUSE: app/models.py declares ApiKey.last_used_at and app/main.py returns it in both the tenant and platform key listings, but no code path ever assigns it. It is NULL for every key ever issued.
WHY IT MATTERS: an operator deciding which of several platform-admin keys is safe to revoke has exactly one signal in the API, and it is dead. Worse, it reads as 'never used' for a key that IS in use — inviting revocation of the only working credential. Found while triaging 10 active platform-admin keys on prod (9 minted by an audit-harness run on 2026-07-30).
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...