# Same-host metered request owner Source API: `rein_aharness.messages_owner.MessagesOwner`. The trusted host bootstrap constructs it with an accepted immutable `MessagesPolicy` and an explicitly supplied provider key, then sets `OpsRunConfig.messages_owner`. This is an in-process owner capability, not a queue field, serialized profile or remote sandbox API parameter. The normal claim-loop CLI does not acquire a key or construct an owner. The explicit [metered-once bootstrap](owner-bootstrap.md) now supplies the one-cycle exec-env child path; native delivery still needs admission. Set `AGENT_HARNESS_REQUIRE_REQUEST_ADMISSION=1` in a future admitted service so a missing bootstrap refuses before claiming work. Parent spend admission must also be configured; provision the RequestLedger schema explicitly before dispatch. No live bootstrap or policy is installed by this source increment. `process_one` validates the accepted initial heartbeat's run ID, worker, attempt, claimed state and future lease expiry. It replaces the stale claim expiry with that accepted expiry. `execute_profiled_run` uses the same checked profile catalog and parent reservation, then enters the owner context and gives Glas its bound sandbox manager. The gateway's existing execution, artifact capture and teardown path is retained. Every exit revokes the token before shutting down the listener. Existing worker cancellation invokes revocation too; a deadline timer covers loss of heartbeat connectivity. The route expires at the earlier of the initial accepted lease and policy expiry. Renewal deliberately does not extend it; start another admitted demand only through normal parent admission, never rebind an old run. The socket is mode 0600 in an ephemeral mode 0700 directory next to the private ledger. llm-connect listens on AF_UNIX only. Sand-boxer binds exactly that socket into its isolated namespace and reuses its bounded loopback byte bridge. Only the opaque token reaches `ANTHROPIC_API_KEY`; `ANTHROPIC_BASE_URL` points to that bridge. There is no provider key in workload memory, argv, mounts or public sandbox records. The workload can reuse/encode its own route token, but the owner still enforces its one run, expiry, policy and durable capacity. Host owner code/state must remain trusted. The ephemeral manager accepts one exact bwrap profile/actor/project/run tuple and one sandbox. It refuses nonempty network egress, provider credential routes, setup secrets, extra host mounts and owner-state overlap with source/workspace/runtime. Remote owner transports cannot silently serialize this binding or fall back to provider credential delivery. Existing unconfigured consumers remain unchanged. The existing direct-CONNECT proof profile is incompatible with this metered mode; a separately reviewed empty-egress profile is required for live use. Reconciliation semantics remain conservative: unknown provider outcomes retain child and parent holds; shutdown or a killed socket is not proof of zero charge. Do not automatically reopen, refund or retry from workload accounting. The same existing receipt-backed operator reconciliation remains necessary after uncertainty. Validation: `tests/test_messages_owner.py`, `tests/test_repository_artifact_bwrap.py`, and existing request/native-CLI suites. Enable `REIN_REAL_BWRAP=1` for the kernel proof; `REIN_REAL_CLAUDE=1` retains the separate installed-CLI protocol fixtures. The owner-route proof uses arbitrary Python in the real sandbox, an external fake provider and synthetic key. It is a local confinement proof, not a paid provider, protected-artifact or Railiance acceptance receipt. Remaining delivery is owned by REINAH-WP-0003-T05/T06, LLM-WP-0009-T03 and SAND-WP-0015-T04 under HFACT T01/T03/T04.