approvedcompleteApache-2.0

Auth + control-plane API client

003-auth-api-client

The binary learns to authenticate against a Statecraft control plane and speak its API. Auth v1 is a browser-assisted session-cookie handoff (the control plane's chassis auth is cookie based, and the embedded rauthy exposes OIDC; the exact mechanism is DECIDE-AT-IMPLEMENTATION between OAuth device-flow-style polling and a localhost callback, constrained below). Tokens/cookies are stored in a 0600 credentials file, never in the config file. An api module gives every later verb a typed, authenticated request path with consistent error mapping.

Establishes
  • ? (symbol)
  • ? (symbol)
Sections
  • 003: Auth + API client
  • 1. Cross-repo dependency
  • 2. Behavior
  • Auth mechanism decision (2026-07-14 amendment)
  • 3. Acceptance
  • 4. Out of scope
  • 5. Status (2026-07-14)
Source
specs/003-auth-api-client/spec.md @ ac2fa199be29as of 2026-07-17 ยท shard 46b6c05e0ca4