flex-auth/docs/railiance-platform-action-vocabulary.md
tegwick acbaa4a7c9
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 37s
feat(policy): add credential grant authorization package
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e47-6aac-7ee1-914d-0584c75d3c81
2026-08-23 13:59:03 +02:00

798 B

Railiance Platform credential-grant action vocabulary

flex-auth uses one protected-system action for the credential broker:

Action Resource type Meaning
issue credential-grant Authorize issuance of one bounded credential lease from a registered grant.

The request subject is the requesting actor. context.bound_subject is the identity to which the resulting credential is bound. Grant id, credential type, issuer, audience, TTL ceiling, permitted actor classes, purposes, and delivery modes are registry-owned resource attributes, not caller assertions.

context.requested_ttl_seconds is numeric seconds. Parsing the broker's source duration string happens once in the selected wire translator; the policy rejects strings to prevent unit ambiguity.