rdmsm4x-changelog-20260827-0546-xentropy-api-key-table-grounding
rdmsm4x-changelog-20260827-0546-xentropy-api-key-table-grounding
Completed a values-free XEntropy API Key Table grounding, source-coverage audit, security design pass, and cross-project coordination so implementation can begin from an approved threat model and an isolated writer worktree without exposing or mutating credentials.
Scope
- Host:
rdmsm4x - Canonical project inspected:
/Users/richh/dev/apps/Xentropy - Related read-only roots inspected:
/Users/richh/dev/sites/dev.dataroo.net,/Users/richh/dev/localAI/litellm,/Users/richh/dev/apps/tyrell, and/Users/richh/dev/lib/apple-notes-api-key-inventory - External research: MCP 2026-07-28, Claude remote connectors, and official Cloudflare, GoDaddy, Firecrawl, OpenRouter, and Mem0 credential-lifecycle documentation
- Secret handling: environment files were inspected only for variable names, assignment presence, source class, and file metadata. No file was sourced and no secret value was printed, copied, validated, stored, messaged, or added to project artifacts.
Local state changed
- Created and updated
/Users/richh/.agent-coordination/checkins/codex-xentropy-api-key-table-20260827.jsonwith root, HEAD, exclusions, read-only progress, and current blockers. - Created fleet message
/Users/richh/.agent-coordination/mail/20260827-052901-3DCBC274__from-codex-rdmsm4x__to-claude-rdmsm4x__xentropy-api-key-table-20260827.mdasking Claude for accountable ownership, dirty-file provenance, accepted PRD/plan state, safe worktree, and the Tyrell boundary. It was dispatched but no acknowledgment was observed by 05:47 EDT. - Sent a value-free proposed XEntropy/LiteLLM contract to Codex task
01a0407a-ee17-7162-95a7-f7072a6b739ffor focused compatibility and secret-boundary review. The review returned compatible-with-required-corrections and made no XEntropy/LiteLLM file or runtime changes. - SwiftPM may have refreshed ignored
.buildcache state while running the existing test suite. - Created this changelog file.
No tracked or untracked XEntropy project file was created, edited, deleted, staged, committed, or moved by this work.
Repository evidence
- Root:
/Users/richh/dev/apps/Xentropy - Branch:
main - HEAD:
f41eb604575450645da5cd97806a4e1e8ec081c6 - Upstream:
origin/main - Pre-existing dirty paths preserved:
- modified
PROJECT_SUMMARY.md - modified
docs/backlog/phased-roadmap.md - untracked
STATUS.md - untracked
docs/product/PRD-addendum-2026-08-24-automation-and-api-observability.md - untracked
docs/research/field-evidence-credential-sprawl-2026-08-24.md
- modified
Commands and checks run
scutil --get ComputerName,hostname,pwdgit status --short --branch,git rev-parse HEAD,git log, file timestamps, and boundedgit diff/rginspection- Full reads of repository and fleet coordination instructions before work
- Bounded
rg/find/sedinspection of XEntropy, dev.dataroo, LiteLLM, Tyrell, and prior Apple Notes inventory artifacts - Values-free shell parsing that enumerated environment-variable aliases and whether assignments were blank or present without emitting right-hand-side values
swift testfrom/Users/richh/dev/apps/Xentropy- Primary-source HTTP/documentation checks for MCP and the named providers
~/.agent-coordination/agent_msg.zsh send, targeted message-file read, and inbox/status checks- Codex task message and immediate task-status snapshot for the LiteLLM review request
Verification evidence
- Host and canonical root resolved to
rdmsm4x:/Users/richh/dev/apps/Xentropy. - The repository remained at the same HEAD and retained the same five pre-existing dirty paths after the audit.
- Existing XCTest suites passed. Static enumeration found 35 declared XCTest methods; this is a source count, not a claim about newly added tests.
- The local app remains a Phase 0 read-only discovery shell with no credential persistence, validation, mutation, CLI/API, or MCP implementation.
- The API observability addendum remains a draft and contains a schema defect: blank expiration currently implies non-expiring. The approved design must instead model explicit known, confirmed non-expiring, unknown, and not-applicable states.
- The values-free environment scan found 28 source-plus-alias observations across eight files, representing 21 distinct alias names. These are observations, not deduplicated credential identities.
- The dated Apple Notes inventory is stale source-coverage evidence only: 30 deduplicated candidates, four protected/unread bodies, all unvalidated. Its unsalted fingerprinting method is unsuitable for XEntropy and was not rerun.
- The OpenRouter value exposed in chat was not read, copied, validated, or imported. Only the requirement for a metadata-only compromised/pending-revocation state was retained.
- Tyrell already owns the provider usage/quota evidence plane and deliberately separates vendor-authoritative quota from local activity proxies. No Tyrell or TokenBar code or data was imported.
- Remote Claude connectors require a publicly reachable HTTPS MCP endpoint, which is outside the presently authorized local-only boundary and requires Rich's explicit approval.
Design result
- Recommended staged boundary:
- metadata-only catalog and API Key Table;
- separately approved local Keychain/selected-manager broker with explicit foreground reveal and direct child-process injection;
- optional remote stateless MCP metadata mirror only after public exposure, OAuth/OIDC, issuer/audience/client binding, and per-operation authorization are approved.
- Raw secret values never enter metadata SQLite/SwiftData/CloudKit, Git, logs, task messages, HTTP API responses, or MCP results.
- Stable logical credential IDs and per-generation version IDs are required for safe dual-key rotation and rollback.
- Every asserted date, tenant, scope, and validation fact requires explicit state, provenance, observed-at time, and confidence.
- CLI/API/MCP share one typed metadata application service. MCP
remains read/plan-only;
secret.revealis local UI-only and any later runtime broker uses explicit named launch profiles rather than returning values. - LiteLLM review correction: replace the arbitrary
xentropy exec --credential ... -- programdefault with foreground-approved, signed named launch profiles that bind credential/version, executable identity, fixed alias, argument and working-directory policy, audience, expiry, and permitted network destination. General command execution, if ever allowed, is a separate high-risk secret-delegation feature. - LiteLLM review correction: add
catalog.snapshotandcatalog.changessemantics (or equivalent) with schema/projection versions, revisions, deterministic pagination/filter/sort, ETags orupdated_since, and tombstones so consumers converge after restarts. - LiteLLM review correction: make active/preferred credential versions and overlap/cutover/binding state explicit; never infer a usable generation from recency.
- LiteLLM review correction: treat source coverage, consumer graphs, tenants/accounts, device availability, private endpoints, paths, and caller identity as separately scoped sensitive metadata with redacted defaults, output bounds, URL/path filtering, secret-safe typed errors, caller-scoped caches, and revocation/compromise invalidation.
- LiteLLM review correction:
rotation.planis pure/read-only, bound to an immutable input snapshot, idempotency key, plan hash/revision, expiry, and stale-plan refusal; addrotation.getPlanfor referenced plans. - Required negative tests now include no secret patterns or raw Keychain references, no private paths/URLs in default MCP output, no cross-caller cache bleed, cache invalidation on compromise/revocation, arbitrary executable rejection, refusal on unknown tenant/scope/version, safe dual-generation coexistence, stale-plan refusal, and provider-body/header-free errors.
Outstanding owner actions and blockers
- Rich must approve the consolidated product/security choices before the repository permits application-code implementation.
- Claude must acknowledge the current writer and identify a safe branch/worktree, or the existing dirty checkout must otherwise be reconciled without overwriting another task.
- Clarify whether “xprotect documentation” meant the published XEntropy documentation or a different protected page.
- Decide whether the first release is local-only or includes a publicly reachable Claude connector. Public exposure is not implied by “stateless.”
- Revoke the chat-exposed OpenRouter credential and store its replacement through an approved local authority before any owner-attended rotation canary.
- Choose a disposable/scoped provider credential for the owner-attended canary. No real rotation, validation, or revocation was attempted.
- Repair or explicitly re-authorize the Notes changelog publisher before using it. Apple Notes publication of this changelog is pending; the Markdown archive exists at this path.
Undo
- Remove only
/Users/richh/.agent-coordination/checkins/codex-xentropy-api-key-table-20260827.jsonif this task check-in is no longer needed. - Fleet messages are immutable coordination records and should not be manually deleted.
- Remove only this changelog file if Rich explicitly requests its deletion.
- Any ignored SwiftPM build cache can be regenerated by a future build; no cleanup was performed because destructive cleanup was unnecessary.
Apple Notes persistence
Pending. The required Markdown archive is complete, but
zsh ~/scripts/notes_changelog.zsh <changelog.md> was
intentionally not run because the current shared LiteLLM state documents
an unresolved deletion hazard in that publisher. Do not claim this entry
exists in Notes until a safe publisher run is observed.