# OpenRouter native access contract — 2026-09-14 FLEX-WP-0026 answers intelligence-radar message `a4a4f455-bacd-4172-a45c-2c375a58db12` and ops-warden question `a90672e4-4f5f-4ab8-ac43-455f4da351a7` (WARDEN-WP-0039-T03). The existing caller binding admits representation of a protected system. It contains no delegated credential-read contract for ops-warden to represent railiance-platform. The resolution for this use case is the native secrets-engine lifecycle path. Do not widen ops-warden's binding, rename the credential owner, or treat its planner's `autonomous` verdict as runtime admission. The native CheckRequest addresses `catalog:openrouter-llm-connect`, type `secret-catalog-lane`, system `secrets-engine`, tenant `tenant:platform`, subject `secrets-engine` / `service`. This is the lifecycle resource actually enforced by secrets-engine, not a relabelled railiance-platform credential read. OpenBao custody remains railiance-platform's; llm-connect remains the existing workload owner. Radar is a proposed delivery recipient, not a PDP caller or lifecycle subject. `context.catalog_target` carries the actual non-secret mount/path, owner repo, fields, consumers, delivery/auth specification and workload delivery. Exec also carries the existing exact recipient digest. The evaluator binds this submitted context through FLEX-DEC-2026-012; it does not independently admit an arbitrary KV path. The consumer must join the issuer's exact-action approval to `approval_binding_digest` and CAS-consume before OpenBao. A changed path or owner can produce a new policy allow, but cannot reuse the old approval. Claim validity and declared human control remain the issuer/consumer responsibilities. ## Dedicated pin correction Helm release `flex-auth-secrets-engine`, revision 4, now uses the existing CI-published source `dd8dd517438b876fdadf27770e3f7e7f55ea69cf` image `sha256:05a03a8790c2210c48ea92391441c77ddf640d0cd32f5ec09838f5393171fcbd`. The old September 6 image lacked the consumer's current replay contract. Policy stays `secrets-engine.catalog-lane.lifecycle` / `v2`; caller enforcement and the existing ServiceAccount binding remain in force. The policy rules did not change. Loopback forwarding to the named pod authenticates the responder through the Kubernetes API; plain workstation Service DNS remains unsupported. Validation: full Go race suite, image policy validation (28 tests / 32 fixtures), Helm lint and server dry-run, then 11 live checks. Correct native caller succeeds; missing/wrong callers, foreign system, wrong tenant and recipient-as-subject refuse. Submitted context and approval digest pairing survive the real evaluator; changed path/mount/owner produces a different approval binding. All other PDP Deployment specs were compared before/after and are identical. Ten-minute caller tokens stayed in memory; the temporary named-pod forward was stopped. Receipt: `docs/evidence/2026-09-14-openrouter-live-pdp.json`. It is evaluation-only with a synthetic claim, not real approval or OpenBao evidence. If this pin cannot serve the current contract, stop native execution; rolling back to the prior image restores the replay incompatibility and cannot unblock credential delivery. ## Live handoff SECRETS-WP-0010-T03 holds the unresolved native admission and delivery work, linked to SECRETS-WP-0007-T04/T07 and SECRETS-WP-0006-T05/T06. Approval Engine has no StatefulSet, pod or Service in its declared namespace at inspection. Its production identity/audit and client-reader gates must be completed before native apply. No credential read, AppRole/policy write, ESO change or model spend was performed here. WARDEN-WP-0039-T03 and IR-WP-0004-T02 remain waiting on the native verification; publishing this contract does not retire the proxy.