#92 Freepass: free-tier API keys via email
Description
EditEARS SPEC:
When a user emails futuex+freepass@mail.rodmena.co.uk, the Futex platform shall create a tenant, provision RBAC, issue a futex_sk_* API key, and reply with the key.
When a user emails futuex+rotate@mail.rodmena.co.uk from the same address, the Futex platform shall revoke the existing key and issue a replacement.
If the sender is unauthenticated (DMARC/SPF fail), then the platform shall reject the request without reply.
If the sender uses a disposable domain, then the platform shall reply with a rejection and not issue a key.
If the rate limit is exceeded, then the platform shall drop the request silently.
While a key is already active for an address, the platform shall report already_active and not issue a duplicate.
The webhook endpoint shall verify the HMAC-SHA256 signature from mail-api before processing.
The webhook endpoint shall always return 200 for decided messages to prevent mail-api retries.
The platform shall store email_hash (not the raw email) for idempotent lookups.
The platform shall send replies via mail-api as transactional emails with Auto-Submitted: auto-replied.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...