#85 FTX-85: platform API keys cannot be listed or revoked via the product

closed high security Created 2026-07-26 04:17 · Updated 2026-07-26 04:19

Description

Edit
EARS SPEC: - The platform shall expose GET /v1/platform/api-keys listing platform-scoped (tenant-less) API keys (metadata only, never key material) to platform principals holding hitl:platform:admin. - When a platform principal DELETEs /v1/platform/api-keys/{key_id}, the platform shall mark the key revoked, audit the revocation under the 'platform' scope, and purge the authn cache so the revocation is immediate. - If a non-platform principal calls either route, then the platform shall return 403. - If the revoked key is used after revocation, then the API shall return 401. Found during FTX-81 deploy: smoke verification required minting platform keys via scripts/bootstrap_platform_key.py, and one raw key was exposed in terminal trace output — with no product path to revoke it (DELETE /v1/tenants/{id}/api-keys is tenant-scoped; platform keys have tenant_id NULL). Recovery from revoking the last platform key remains scripts/bootstrap_platform_key.py (master client key).

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...