#103 FTX-103: meter and cap freepass free-tier usage with TokenGate

open high Created 2026-07-31 21:28 · Updated 2026-07-31 21:28

Description

Edit
EARS SPEC: - The Futex free tier shall meter decision creation against a TokenGate quota. - When a freepass tenant is provisioned, Futex shall assign it the free-tier TokenGate plan. - When a decision is created by a freepass tenant, Futex shall consume one unit of the metered resource before the decision is persisted. - If the freepass tenant has exhausted its quota, then Futex shall refuse the decision with HTTP 429 naming the quota and its reset time. - The Futex decision-creation path shall use the caller's idempotency key when consuming, so a retried request is not charged twice. - Where a tenant is not a freepass tenant, Futex shall not call TokenGate on the decision path. - If TokenGate answers that the quota is exceeded or that its backend refused, then Futex shall treat the decision as refused. - If TokenGate cannot be reached at all, then Futex shall allow the decision and record an audit event identifying the unmetered call. CONTEXT: Futex has NO usage metering of any kind. Freepass is a free tier in name only - keys are rate-limited per minute (300 API / 60 web) but have no cap on total usage, ever. Rate limits are also hand-rolled Redis counters (app/security/ratelimit.py:49, app/freepass/guards.py:212) against the standing house rule. This ticket covers the freepass quota; the rate-limiter migration is deliberately NOT in scope.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...