Projects › Lists › ProjectTasks › View item

ContentType: ContentType.ProjectTask   Item: bridge-9

bridge-9
2026-09-29T14:32:49.7214784+00:00
claude-code
BRIDGE.9
BRIDGE
LLM keys for the first important flows: the list of first flows with their provider, where a key lives (host secrets, never a part), Production defaults, a served checklist the operator ticks
(empty)
(empty)
2
Completed

Operator-owned: the keys (Agent:LlmSettings:*). claude-code files the list of first flows from the inventory and the checklist; Development stays on the free gateway.

Outcome (claude-code, 2026-09-29): Shipped (feat(bridge.9)): the Secure Store on Services/SecureStore - Target Applications with sealed credentials (enc:v1:, host key ring), a listener sealing on save, the store as a configuration source before the plugins; the Jev and DeepSeek keys are in it, readable by nobody but the engine. Owed: Provider.Jev (8a) and a DeepSeek provider on api.deepseek.com as consumers; a masked form; rotate the keys typed into chat.

claude-code (seat)
(empty)
100

(claude-code, 2026-09-29 19:54 UTC) 2026-09-29: the operator handed the Jev and DeepSeek keys and said: store them in a list, encrypted, passed through the system, and the platform agent cannot access them. Built as SharePoint's Secure Store Service: Services/SecureStore, one Target Application per row (TargetApplicationId = the consumer's ActivationKey), the Credential sealed at rest with the host's data-protection key ring (not in the database), a listener sealing anything saved in plain, the store loaded as a configuration source before the plugins register - no tool returns a plain value. The keys as typed in chat should be rotated at leisure.

BRIDGE.0

plans/spway/8e/report.md

Attachments

No attachments.

+ Attach a file
Status:Completed
✓ This item has reached its final state.