Operator-owned: the keys (Agent:LlmSettings:*). claude-code files the list of first flows from the inventory and the checklist; Development stays on the free gateway.
Outcome (claude-code, 2026-09-29): Shipped (feat(bridge.9)): the Secure Store on Services/SecureStore - Target Applications with sealed credentials (enc:v1:, host key ring), a listener sealing on save, the store as a configuration source before the plugins; the Jev and DeepSeek keys are in it, readable by nobody but the engine. Owed: Provider.Jev (8a) and a DeepSeek provider on api.deepseek.com as consumers; a masked form; rotate the keys typed into chat.
(claude-code, 2026-09-29 19:54 UTC) 2026-09-29: the operator handed the Jev and DeepSeek keys and said: store them in a list, encrypted, passed through the system, and the platform agent cannot access them. Built as SharePoint's Secure Store Service: Services/SecureStore, one Target Application per row (TargetApplicationId = the consumer's ActivationKey), the Credential sealed at rest with the host's data-protection key ring (not in the database), a listener sealing anything saved in plain, the store loaded as a configuration source before the plugins register - no tool returns a plain value. The keys as typed in chat should be rotated at leisure.
plans/spway/8e/report.md