diff --git a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md index cc9188e..3fd9ba0 100644 --- a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md +++ b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md @@ -148,6 +148,14 @@ reset delivery. First-password handoff, MFA enrollment, and final human-token claim/denial evidence remain. No operator-set password or raw credential was used as a shortcut. +2026-07-28 update: the reusable password handoff is now live at the canonical +KeyCape host and is issued/renewed through the user-engine administration UI. +Links are opaque, expire after 15 minutes, are single use, and older links are +revoked on renewal. A disposable-user live test proved password registration, +directory login, replay denial, and cleanup. This task now awaits only the +Binky user's own password choice, MFA enrollment, and final scoped-token +acceptance. + ## Task: Register a workload-identity OIDC client for the qonto runtime ```task