>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #85
Update issue details
Title *
Description
EARS SPEC: - The platform shall expose GET /v1/platform/api-keys listing platform-scoped (tenant-less) API keys (metadata only, never key material) to platform principals holding hitl:platform:admin. - When a platform principal DELETEs /v1/platform/api-keys/{key_id}, the platform shall mark the key revoked, audit the revocation under the 'platform' scope, and purge the authn cache so the revocation is immediate. - If a non-platform principal calls either route, then the platform shall return 403. - If the revoked key is used after revocation, then the API shall return 401. Found during FTX-81 deploy: smoke verification required minting platform keys via scripts/bootstrap_platform_key.py, and one raw key was exposed in terminal trace output — with no product path to revoke it (DELETE /v1/tenants/{id}/api-keys is tenant-scoped; platform keys have tenant_id NULL). Recovery from revoking the last platform key remains scripts/bootstrap_platform_key.py (master client key).
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel