approvedcompleteApache-2.0
Auth + control-plane API client
003-auth-api-client
The binary learns to authenticate against a Statecraft control plane and speak its API. Auth v1 is a browser-assisted session-cookie handoff (the control plane's chassis auth is cookie based, and the embedded rauthy exposes OIDC; the exact mechanism is DECIDE-AT-IMPLEMENTATION between OAuth device-flow-style polling and a localhost callback, constrained below). Tokens/cookies are stored in a 0600 credentials file, never in the config file. An api module gives every later verb a typed, authenticated request path with consistent error mapping.
- Depends on
- Establishes
- ? (symbol)
- ? (symbol)
- Sections
- 003: Auth + API client
- 1. Cross-repo dependency
- 2. Behavior
- Auth mechanism decision (2026-07-14 amendment)
- 3. Acceptance
- 4. Out of scope
- 5. Status (2026-07-14)
- Source
- specs/003-auth-api-client/spec.md @ ac2fa199be29as of 2026-07-17 ยท shard 46b6c05e0ca4