docs: entity-scoped API key recipe + control/data plane model - #206
Conversation
Move duplicated content out of the new entity-scoped-keys recipe into the skills that already own it (entities/orm-provisioning, principals/api-keys, principals/org-scoping), and cross-link the control/data plane section from the skills that already assumed the concept.
Follow-up commit: giving each fact one ownerThe plane model and the routing row are exactly the gaps we had — three skills ( The rest of the review was about duplication: What moved where
Two things worth flagging beyond placement
Net effect: Happy to drop any of it if you disagree with a call. |
Summary
constructive-principals: newentity-scoped-keys.mdreference — end-to-end recipe (entity type → scoped principal → step-up →createApiKey→ use/revoke) with the create-time-scoping probe, the flatcreatePrincipalSDK gap, live-provenverifyPasswordsemantics (wrong password →result: null), and the identity-user-id vs principal-row-id distinctionconstructive-architecture: control plane vs data plane section (endpoints, tokens, operations) and themodules.<host>endpoint in the mapfeatures.md: routing row for principals/API keysReview notes
PRINCIPAL_NOT_OWNEDon the row id)