Merge pull request 'Designs 36 and 39: the manager's verb is public-key' (#363) from fix/the-verb-is-public-key into main

This commit was merged in pull request #363.
This commit is contained in:
2026-10-04 13:41:32 +00:00
2 changed files with 3 additions and 3 deletions
@@ -161,7 +161,7 @@ decides it and [ADR 0206](../../02-DECISIONS/0206-a-node-reports-the-anthropic-g
any change; for the API-key licence sets the key-helper in the managed settings to a small program that
prints the key from the module's state, so no file under the home is touched;
- **adds an API key from this node** (*ADR 0209*): `claude_code_add_api_key` reads the key from a file
here, seals it to the manager's `public_key`, hands it to the seat's `adopt`, removes the file once
here, seals it to the manager's `public-key`, hands it to the seat's `adopt`, removes the file once
taken, and on request switches this node to the new licence;
- **follows a login made here**: a login to another account is adopted and moves this node to it (ADR
0209) — nothing for this module to do beyond reporting it;
@@ -146,7 +146,7 @@ report, and adopted by refreshing it.
- **The identity guard** files a grant under the identity the node read; where the vendor's refresh
answer names the account too, a mismatch is refused and notified. Which source decided is audited.
- **An API key** enters from any node (*ADR 0209*): the agent module there reads it from a file on its own
node, seals it to the manager's key (the seat's `public_key` verb) and hands it to `adopt`, removing the
node, seals it to the manager's key (the seat's `public-key` verb) and hands it to `adopt`, removing the
file once taken — or `adopt` reads a file on the manager's node. Never an argument, never on a stream.
An API key is a licence of its own and moves a node only through `bind` or `switch`.
@@ -161,7 +161,7 @@ gone; a rotation or a switch is a new generation in the `bindings` state.
**The seat's verbs**, the contract every future holder must serve: `licences` (each with kind,
identity, expiry, failures, who is bound), `bindings`, `bind`, `switch`, `release`, `refresh` (now, one
or all), `usage` (current and history), `adopt` (a file on the manager's node, or a key sealed to its
`public_key` — ADR 0209), `public_key`, and `current` (a consumer's token, sealed to the key the
`public-key` — ADR 0209), `public-key`, and `current` (a consumer's token, sealed to the key the
consumer sends — ADR 0206). The manager asks a node for a candidate grant by the agent module's own tool.
## 8. Settings