ADR 0050 (proposed) — model access is vendor-agnostic [awaiting ratification] #25

Merged
jschoubben merged 2 commits from feat/adr-0050-vendor-agnostic-model-access into main 2026-09-05 19:42:28 +00:00
Owner

Proposed, not for auto-merge — this is your ratification checkpoint (ADR 0023). Drafted while you were away, from the deep claude/anthropic analysis you asked for.

The finding that shaped it: the vendor-agnostic licence layer already exists in mesh-control/internal/licences (licence(name, vendor, serves) + licence_holder(... sealed)). So this ADR is an additive generalisation, not a rebuild.

What 0050 decides:

  • model-access stays one consumer-facing, vendor-blind provision (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor adapter keyed by licence.vendor — Anthropic becomes one adapter, exactly as cloudflare-dns is one registrar for public-dns.
  • Adapter capabilities are optional (shape static-key|refreshable-grant, accept, refresh, identity, usage, deliver) so a static-key vendor implements almost nothing.
  • The crux — a bounded carve-out: a refreshable OAuth credential can't be both sealed-so-the-mesh-can't-read-it and centrally rotated. For refreshable-grant vendors only, the manager node holds the refresh token encrypted-at-rest (bounded three ways: refreshable-grant only, refresh token only, manager node only); static-key vendors — the majority — keep the full sealing guarantee. Rejected alternatives recorded.
  • vendor field (not "provider", to avoid the provider-pin clash); usage normalised to (licence, consumer, period, metric, value)+raw; explicit per-consumer binding, refuse-if-unchosen; Anthropic first, anthropic-api-key the proving static-key case.

Also amends 03-DESIGN/01-to-be/14-model-access.md with the generalisation (prose + diagram). Checks pass (index current; 50 records). Full analysis: CLAUDE-VENDOR-AGNOSTIC-ANALYSIS.md in the code workspace.

noxflow was skipped per your instruction (needs rethinking).

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

**Proposed, not for auto-merge — this is your ratification checkpoint (ADR 0023).** Drafted while you were away, from the deep claude/anthropic analysis you asked for. **The finding that shaped it:** the vendor-agnostic licence layer *already exists* in `mesh-control/internal/licences` (`licence(name, vendor, serves)` + `licence_holder(... sealed)`). So this ADR is an *additive* generalisation, not a rebuild. **What 0050 decides:** - `model-access` stays one consumer-facing, **vendor-blind** provision (extends 0024/0027); the vendor-specific lifecycle moves into a per-vendor **adapter keyed by `licence.vendor`** — Anthropic becomes one adapter, exactly as `cloudflare-dns` is one registrar for `public-dns`. - Adapter capabilities are optional (`shape` static-key|refreshable-grant, `accept`, `refresh`, `identity`, `usage`, `deliver`) so a static-key vendor implements almost nothing. - **The crux — a bounded carve-out:** a refreshable OAuth credential can't be both sealed-so-the-mesh-can't-read-it *and* centrally rotated. For refreshable-grant vendors only, the manager node holds the refresh token encrypted-at-rest (bounded three ways: refreshable-grant only, refresh token only, manager node only); static-key vendors — the majority — keep the full sealing guarantee. Rejected alternatives recorded. - `vendor` field (not "provider", to avoid the provider-pin clash); usage normalised to `(licence, consumer, period, metric, value)`+raw; explicit per-consumer binding, refuse-if-unchosen; Anthropic first, `anthropic-api-key` the proving static-key case. Also amends `03-DESIGN/01-to-be/14-model-access.md` with the generalisation (prose + diagram). Checks pass (index current; 50 records). Full analysis: `CLAUDE-VENDOR-AGNOSTIC-ANALYSIS.md` in the code workspace. **noxflow** was skipped per your instruction (needs rethinking). https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-05 11:44:19 +00:00
Turn the completed vendor-agnostic analysis into HQ design. The model-access
provision stays one vendor-blind interface (extends 0024/0027); the
vendor-specific lifecycle moves into a per-vendor adapter keyed by the licence's
`vendor` field, mirroring registrar-scoped public-dns providers (0044), named at
the consumer's real coupling per 0040.

The crux is the sealing-vs-central-rotation carve-out: for refreshable-grant
vendors only, the manager node holds the refresh token encrypted at rest (a
bounded, declared exception), access tokens sealed per holder, refresh stripped
on delivery. Static-key vendors keep full sealing.

Amend 03-DESIGN/01-to-be/14-model-access.md with the adapter generalisation as a
proposed section (prose + diagram, no code); regenerate the decision index.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-05 19:42:23 +00:00
Verified and ratified: model-access stays one vendor-blind provision; per-vendor
adapter keyed by licence.vendor (mirrors public-dns registrar providers); the
sealing-vs-central-rotation carve-out bounded to refreshable-grant vendors /
refresh token / manager node only. Status proposed -> accepted; index regenerated
(records + index checks pass); design doc note updated.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit 4430cc1748 into main 2026-09-05 19:42:28 +00:00
jschoubben deleted branch feat/adr-0050-vendor-agnostic-model-access 2026-09-05 19:42:28 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#25