# Non-secret static registration fragments for KeyCape's bounded JWT consumers. Merge these entries into the deployment-owned KeyCape config. # The named environment variables must be materialized by an approved # out-of-repository custody path; this file never contains their values. clients: - clientId: "codex-railiance-platform" displayName: "Railiance platform coding agent" allowedScopes: ["openbao:login"] grantTypes: ["client_credentials"] clientType: "confidential" secretRef: "env:KEYCAPE_CODEX_RAILIANCE_PLATFORM_CLIENT_SECRET" serviceSubject: "service:codex:railiance-platform" tenant: "tenant:coulomb" roles: ["coding-agent"] tokenLifetime: "15m" - clientId: "secrets-engine-openbao" displayName: "secrets-engine OpenBao login" allowedScopes: ["openbao:login"] grantTypes: ["client_credentials"] clientType: "confidential" secretRef: "env:KEYCAPE_SECRETS_ENGINE_OPENBAO_CLIENT_SECRET" serviceSubject: "service:secrets-engine" tenant: "tenant:coulomb" roles: ["secrets-engine"] tokenLifetime: "15m" - clientId: "secrets-engine-approval" displayName: "secrets-engine approval consume client" audience: "approval-engine" allowedScopes: ["approval:read", "approval:consume"] grantTypes: ["client_credentials"] clientType: "confidential" secretRef: "env:KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET" serviceSubject: "service:secrets-engine" # Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6. # Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md. tenant: "tenant:platform" roles: ["secrets-engine"] tokenLifetime: "15m" # WITHDRAWN BY THE REQUESTING OWNER, 2026-09-09. approval-engine asked that this # client not be provisioned: nothing in their repository obtains an OAuth token, # and scope by scope the bundle does not describe a single actor — # approval:approve now belongs to the informed-decision human client, # approval:emit is redundant (the server emits its own heartbeat with no token), # and no requester identity was ever settled for approval:create. It was a # convenience bundle written when a lifecycle operator was assumed to exist. # # Kept rather than deleted at their request: verifier custody CCR-2026-0018 # stands, so the client stays authenticable if a presenter ever appears. It is # already live from the 2026-09-09 attended rollout, so this annotation does not # remove it — see KEY-WP-0013-T02. # # Do not widen it, and do not treat it as a template. When a presenter is named, # approval-engine will re-request NARROWED to that presenter's scopes, and # approval:approve must not travel with the operational scopes. - clientId: "approval-engine-operator" displayName: "approval-engine lifecycle operator (withdrawn: no presenter)" audience: "approval-engine" allowedScopes: ["approval:create", "approval:read", "approval:approve", "approval:revoke", "approval:supersede", "approval:observe", "approval:emit"] grantTypes: ["client_credentials"] clientType: "confidential" secretRef: "env:KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET" serviceSubject: "service:approval-engine-operator" # Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6. # Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md. tenant: "tenant:platform" roles: ["approval-operator"] tokenLifetime: "15m" # Human approver browser client. Submitted by informed-decision 2026-09-10 # (INFD-WP-0001-T07) with the origin already live: both / and /auth/callback # return 200 from 92.205.62.239 on a Let's Encrypt certificate # CN=decisions.coulomb.social valid 2026-09-10 to 2026-12-09, deployed by # railiance-apps. The host is decisions.coulomb.social, NOT the # decide.coulomb.social an earlier draft proposed; register the string verbatim. # # The path currently serves an nginx placeholder while their surface is gated on # APPROVAL-WP-0002-T01. That does not affect this registration: the redirect is # matched as an exact string at /authorize and never fetched. # # No secretRef: this is a public client and authenticates with PKCE alone. No # serviceSubject or roles either — on a browser client both are silently ignored # and config validation rejects them (KEY-WP-0028); the subject and roles come # from the directory user. - clientId: "informed-decision-approver" displayName: "informed-decision approver surface" audience: "approval-engine" redirectUris: - "https://decisions.coulomb.social/auth/callback" allowedScopes: ["openid", "approval:read", "approval:approve"] grantTypes: ["authorization_code"] clientType: "public" # Declared, not inherited. Nothing populates domain.User.Tenant for approver # users, so this reaches the token by the GH-DEC-2026-013 declared-gap route # by construction, and the token says so: tenant_source is "registration", # never "directory". Admissible for approval-engine's store-isolation gate; # NOT admissible for any doctrine turning on this person's membership of the # zone. See docs/tenant-claim-contract.md. tenant: "tenant:platform" # Approval is a human-in-the-loop control, so MFA is required rather than # left to the provider default. mfaRequired: true