--- id: RPF-WP-0032 type: workplan title: "Design secrets-engine service JWT login" domain: financials repo: railiance-platform status: finished owner: codex created: "2026-09-05" updated: "2026-09-05" state_hub_workstream_id: "bd036850-e1bf-5b70-bbc3-683dfa4b125c" --- # Design secrets-engine service JWT login ## Prepare the platform design ```task id: RPF-WP-0032-T01 status: done priority: high state_hub_task_id: "166ece0b-840b-54b8-b10c-45f96eda0429" ``` Reviewed owner source and the current platform CCR contract. Delivered `docs/credential-lane-designs/secrets-engine-service-jwt.md` with proposed exact scope, custody, lifecycle, implementation gaps, approval requirements and positive/negative acceptance evidence. This is a completed design deliverable, not a live lane or approval. No secrets accessed, production objects changed or owner messages sent. ## Obtain owner inputs and implement the approved lane ```task id: RPF-WP-0032-T02 status: cancel priority: high state_hub_task_id: "d1f4a9f6-4ea5-5daa-97bb-039856855bc2" ``` Confirm issuer, verification endpoint, actual KeyCape registration and live auth mount survey. Approve the login-only role/self policy, implement reviewed declarative support and prove effective-policy, wrong-claim, expiry and cleanup checks. Native lane execution still requires its separate exact authorization and scoped authority. Review the linked design and pin current source revisions before implementation. Do not interpret this workplan or a proposed coordinate as live authorization. ## Portfolio review — 2026-09-05 The design deliverable is complete. The implementation obligation is preserved in **RPF-WP-0035-T02**, the single credential-lane implementation queue. T02 is `cancel` here only because it is superseded there; it is not implemented, waived or externally accepted. The approved design scope and all existing identifiers remain unchanged. Archived on 2026-09-05 after this consolidation.