[AVAILABLE] for credential isolation, wired into the default server. [PARTIAL] for the separate
ExecutionPermit model described below, real and tested, not reachable from packages/api or packages/runtime today.Purpose
Authenticates a calling gateway, issues single-use session credentials, and routes a verified release to a connector, auditing every step. See Credential isolation and Gateway attestation for the concepts.Install
Key exports: the wired credential-isolation path
A second, separate model in this package: ExecutionPermit
Minimal example
Next
Issue and verify session credentials
Issue, consume, expire, reuse-reject, and revoke, run live.
@parmana/receipt
The other half of the unwired
ExecutionPermit path.