--- id: KEY-WP-0013 type: workplan title: "Approval-engine resource audience and client registrations" domain: infotech repo: key-cape status: blocked owner: codex topic_slug: approval-engine-resource-audience created: "2026-09-05" updated: "2026-09-05" state_hub_workstream_id: "6e815d88-b0e3-5ce0-be5d-13ab15917f7f" --- Source: approval-engine inbox request 5583e896-52f2-45bd-895f-02f227b7e836, reviewed against its local registration and caller-authentication contracts. ## Implement static resource audiences ```task id: KEY-WP-0013-T01 status: done priority: high state_hub_task_id: "a92432a2-4e92-5b90-be2b-d82b784bf8f0" ``` Added optional static audience configuration for access tokens in both grants; ID tokens retain the relying-party audience. Added human access-token scope. Published bounded approval service fragments and the human registration contract. Regression tests cover the default audience, request override resistance, JWKS signature validation, ID-token separation and service registration scope isolation. Browser requests and token exchanges now enforce the client scope allow-list, including grants removed after authorization. ## Provision and prove live registrations ```task id: KEY-WP-0013-T02 status: wait priority: high state_hub_task_id: "607897c5-bad9-55e5-86df-7802f592d6e8" ``` Needs deployment-owned custody for both new secret references and an exact human callback registration. Deploy the implementation and registrations together, then prove live JWKS verification and denied excess scopes without logging values. Local signature proof is not live rollout evidence. See docs/approval-engine-auth-contract.md.