approvedcompleteAGPL-3.0
Tenants: OAuth login + per-org GitHub App installation
004-tenants-github-app
The tenancy spine of milestone M2: a user authenticates against the control plane (embedded rauthy, chassis auth), creates a tenant, and installs the statecraft GitHub App into their own GitHub org; from then on everything the platform does for them keys off the installation_id and happens inside their org. Nobody joins our org; code sovereignty is the product's first-class property. This spec owns the tenants service: tenant + installation records on CoreLedger, the App installation handshake, webhook receipt, and an installation-token mint helper the factory (spec 005) consumes.
- Depends on
- Establishes
- backend/tenants/ (directory)
- Sections
- 004: Tenants + GitHub App
- 1. Operator prerequisites (SATISFIED 2026-07-14: the App exists)
- 2. Territory
- 3. Behavior
- 4. Acceptance
- 5. Out of scope
- Source
- specs/004-tenants-github-app/spec.md @ f136bf323cecas of 2026-07-21 ยท shard bd78c752411a