Select service-jwt, bootstrap, or env exclusively: JWT login uses a JSON file, self-revokes, and never falls back to bootstrap or BAO_TOKEN. The platform JWT mount/role is still unpublished, so auto keeps named bootstrap/env providers. session revoke --accessor-file revokes an already-issued token with fingerprint-only evidence. Production remains fail-closed. Assistant: grok Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00 |
||
|---|---|---|
| .. | ||
| archived | ||
| ADHOC-2026-08-21.md | ||
| ADHOC-2026-08-23.md | ||
| SECRETS-WP-0001-statehub-bootstrap.md | ||
| SECRETS-WP-0002-bootstrap.md | ||
| SECRETS-WP-0004-warden-sign-token-lane.md | ||
| SECRETS-WP-0005-scope-intent-value-gaps.md | ||
| SECRETS-WP-0006-catalog-lane-adoption.md | ||
| SECRETS-WP-0007-production-lifecycle-hardening.md | ||
| SECRETS-WP-0008-layer-model-lifecycle-conformance.md | ||