Close remaining in-repo APPROVAL-WP-0002 gaps: drive GH-DEC-2026-003 against the real HTTP surface, fail closed on JWT/human-consume/static-token paths, treat audit 200 duplicates as drained, and ask KeyCape for the production audience and client grants. Assistant: grok Assistant-Session: 01a06253-e557-7971-93d9-4f4c2cfbf455
2.3 KiB
Requested KeyCape registrations
Status: requested by APPROVAL-WP-0002-T01. Non-secret. KeyCape owns issuance,
client disablement, and the exact claim contract. This file is a consumer
request, not a live registration.
Tokens presented to approval-engine MUST use resource-server audience
approval-engine. Do not reuse the OpenBao service-auth pattern that sets
aud to the OAuth clientId.
Required claims remain those in docs/caller-authentication.md: iss, sub,
aud, exp, iat, principal_type, tenant, roles, scope, assurance.
principal_type for consume callers must be service or agent.
Resource server
| Field | Value |
|---|---|
| Audience | approval-engine |
| Issuer | the deployed KeyCape issuer (manifest uses https://auth.netkingdom.local) |
| JWKS | GET /jwks on the KeyCape service |
| Scopes | approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:consume, approval:observe, approval:emit |
Clients
Confidential client secrets stay in OpenBao/operator custody. secretRef
names below are placeholders for that custody path.
clients:
- clientId: secrets-engine-approval
displayName: secrets-engine PEP consume client
audience: approval-engine
allowedScopes: [approval:read, approval:consume]
grantTypes: [client_credentials]
clientType: confidential
secretRef: env:KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
serviceSubject: service:secrets-engine
principal_type: service
tenant: tenant:coulomb
roles: [secrets-engine]
tokenLifetime: 15m
- clientId: approval-engine-operator
displayName: approval-engine lifecycle operator
audience: approval-engine
allowedScopes:
- approval:create
- approval:read
- approval:approve
- approval:revoke
- approval:supersede
- approval:observe
- approval:emit
grantTypes: [client_credentials]
clientType: confidential
secretRef: env:KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
serviceSubject: service:approval-engine-operator
principal_type: service
tenant: tenant:coulomb
roles: [approval-operator]
tokenLifetime: 15m
Human approvers use the existing KeyCape human flow with approval:approve
only, still with aud=approval-engine. They must not receive
approval:consume.