>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #100
Update issue details
Title *
Description
EARS SPEC: - When an API key successfully authenticates a request, Futex shall record the time of use on that key. - The Futex API key listings shall report a last_used_at that reflects actual use. - If the last-used bookkeeping write fails, then authentication shall still succeed. CAUSE: app/models.py declares ApiKey.last_used_at and app/main.py returns it in both the tenant and platform key listings, but no code path ever assigns it. It is NULL for every key ever issued. WHY IT MATTERS: an operator deciding which of several platform-admin keys is safe to revoke has exactly one signal in the API, and it is dead. Worse, it reads as 'never used' for a key that IS in use — inviting revocation of the only working credential. Found while triaging 10 active platform-admin keys on prod (9 minted by an audit-harness run on 2026-07-30).
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel