--- id: KEY-WP-0014 type: workplan title: "Review native login and client credential lane handoffs" domain: infotech repo: key-cape status: proposed owner: codex topic_slug: native-credential-lane-handoff created: "2026-09-05" updated: "2026-09-05" state_hub_workstream_id: "0d003df3-f7d3-5063-8ca0-e1e33f7df74a" --- Source: ops-warden inbox message 0dd9c7bd-0ecd-42d1-806f-7cc4ba9730ed. The issuer supports client_secret_basic exchange, but has no native exchange or rotation CLI. Existing machine issuance ownership does not complete this handoff. ## Design owner command and custody boundaries ```task id: KEY-WP-0014-T01 status: todo priority: medium state_hub_task_id: "0c0a0b61-c19e-5631-9cda-8b2dc0f47d8f" ``` Review ops-warden's existing key-cape-oidc-login proxy and rapp-qonto-keycape-client route contracts. Specify the native interactive login and bounded exchange commands, token delivery, renewal and custody-mediated rotation before implementation. Keep secret custody with OpenBao and avoid retiring the proxy until replacement commands have equivalent verification. ## Verify handoff delivery evidence ```task id: KEY-WP-0014-T02 status: todo priority: low state_hub_task_id: "d9a5de97-b7d5-5599-98c2-eaab32f51495" ``` Ops-warden reports KEY-WP-0009-T04's claimed reply did not arrive. Verify prior receipts for all four named recipients before claiming successful notification. No outbound coordination messages were sent during the 2026-09-05 repo review.