#95 FTX-95: Adopt RunFlow auth-issued (rak_) keys after phase-3 cutover; purge committed RunFlow credential

closed high bug Created 2026-07-31 17:00 · Updated 2026-07-31 18:19

Description

Edit
EARS SPEC: - The Futex RunFlow integration shall authenticate to RunFlow using an auth-issued API key (rak_ prefix) as the bearer credential. - If a RunFlow binding is created with a credential in the legacy bare tenant-UUID form, then the Futex API shall refuse it with HTTP 422 naming the required rak_ form. - If RunFlow rejects a sync call because the presented credential is a legacy tenant-UUID key, then the RunFlow sync worker shall record a distinct audit reason identifying credential migration as the cause, rather than a generic permanent failure. - If a RunFlow reconcile poll is refused for a credential reason, then the reconcile worker shall surface that cause distinctly and shall not withdraw the bound decision. - The Futex repository shall not contain a RunFlow credential in source; e2e tests, examples and audit probes shall read it from the environment. - If the RunFlow credential is absent from the environment, then the RunFlow e2e tests and examples shall skip with an explicit reason rather than authenticate with a default. - The Futex RunFlow gate e2e evidence (AC-6) shall be re-proven live against RunFlow using an auth-issued key.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...