#92 Freepass: free-tier API keys via email

closed high feature Created 2026-07-29 21:13 · Updated 2026-07-29 21:20

Description

Edit
EARS SPEC: When a user emails futuex+freepass@mail.rodmena.co.uk, the Futex platform shall create a tenant, provision RBAC, issue a futex_sk_* API key, and reply with the key. When a user emails futuex+rotate@mail.rodmena.co.uk from the same address, the Futex platform shall revoke the existing key and issue a replacement. If the sender is unauthenticated (DMARC/SPF fail), then the platform shall reject the request without reply. If the sender uses a disposable domain, then the platform shall reply with a rejection and not issue a key. If the rate limit is exceeded, then the platform shall drop the request silently. While a key is already active for an address, the platform shall report already_active and not issue a duplicate. The webhook endpoint shall verify the HMAC-SHA256 signature from mail-api before processing. The webhook endpoint shall always return 200 for decided messages to prevent mail-api retries. The platform shall store email_hash (not the raw email) for idempotent lookups. The platform shall send replies via mail-api as transactional emails with Auto-Submitted: auto-replied.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...