Implemented and independently code-reviewed XEntropy's values-free API Key Table, metadata catalog, local CLI/API/stateless MCP surfaces, and disabled-by-default loopback transport without importing, revealing, validating, rotating, or using a secret value.
XEntropy API Key Table v1
Scope and ownership
- Host:
rdmsm4x. - Canonical project root:
/Users/richh/dev/apps/Xentropy. - Sole-writer isolated worktree:
/Users/richh/dev/_handoff/codex-out/xentropy-api-key-table-v1. - Branch:
codex/api-key-table-v1. - Base commit:
f41eb604575450645da5cd97806a4e1e8ec081c6. - Independently accepted code checkpoint:
1be7e7ec51bd4349d474a33ee5f352f5e3c295a2. - Final documentation checkpoint before changelog publication:
92f303499062ffea8b559092eb308e6ee499b899. - Canonical dirty
mainwas observed only at path/status level and was not edited, staged, stashed, cleaned, merged, reset, or otherwise integrated. - Product mode: Prototype with production-grade credential safety.
What changed and why it matters
- Added an app-owned direct SQLite schema-v2 metadata catalog with exact schema verification, transactional schema-1 migration, integrity checks, composite credential/version parents, revisions, changes, tombstones, explicit unknown assertions, and deterministic bounded snapshots.
- Seeded a values-free baseline of 21 unresolved candidate groups plus one incident-only chat exposure record. These are observations, not 22 confirmed credentials; confirmed/resolvable credential count remains zero.
- Added the SwiftUI API Key Table with vendor, service, status,
creation, expiration, scope, source, API Base, and redacted Notes
columns plus purpose-labeled endpoint details. Row selection never
reveals a value. Only a known
api_baseis shown as API Base. - Added metadata-only
xentropyctl, a typed JSON API, and a final 2026-07-28 stateless MCP request adapter with per-request caller/scope authorization, numeric JSON-RPC errors, bounded outputs, deterministic cache metadata, no session handshake, and no reveal/redeem/validate/mutate/execute tool. - Added a disabled-by-default loopback listener with one app-owned caller profile per lane, exact loopback Host/peer/Origin/framing/media checks, per-request authentication, authenticated-lane rate limits, value-free mode-0600 JSONL audit, read-only canonical catalog verification, correlation IDs, and server-side post-stop dispatch prevention.
- Added pure HMAC-bound rotation-plan generation with no provider side effects. Actual provider create/store/update/canary/revoke work remains owner-attended and unimplemented.
- Preserved LiteLLM as route/model/budget authority and Tyrell as the separate sanitized quota/token evidence plane. No LiteLLM route, credential, runtime, or Tyrell/TokenBar code/ledger changed.
Exact project files touched
All paths below are relative to
/Users/richh/dev/_handoff/codex-out/xentropy-api-key-table-v1:
ISSUES.mdPROJECT_SUMMARY.mdREADME.mdSESSION-STATE.mdapp/Package.swiftapp/Sources/CSQLite/module.modulemapapp/Sources/CSQLite/shim.happ/Sources/XEntropy/APIKeyTableView.swiftapp/Sources/XEntropy/CapabilityView.swiftapp/Sources/XEntropy/CredentialCatalogClient.swiftapp/Sources/XEntropy/RootSplitView.swiftapp/Sources/XEntropy/WorkspaceViewModel.swiftapp/Sources/XEntropy/XEntropyApp.swiftapp/Sources/XEntropyCLI/CLICommand.swiftapp/Sources/XEntropyCLI/CLIOutput.swiftapp/Sources/XEntropyCLI/GatewayAudit.swiftapp/Sources/XEntropyCLI/GatewayRuntimeProfile.swiftapp/Sources/XEntropyCLI/GatewayServeApplication.swiftapp/Sources/XEntropyCLI/HTTP1Framing.swiftapp/Sources/XEntropyCLI/LocalBearerAuthenticator.swiftapp/Sources/XEntropyCLI/LoopbackHTTPServer.swiftapp/Sources/XEntropyCLI/main.swiftapp/Sources/XEntropyCore/CredentialCatalogModels.swiftapp/Sources/XEntropyCore/CredentialCatalogRedaction.swiftapp/Sources/XEntropyCore/CredentialCatalogService.swiftapp/Sources/XEntropyCore/CredentialCatalogStore.swiftapp/Sources/XEntropyCore/RedactedCredentialBaseline.swiftapp/Sources/XEntropyCore/RotationPlanning.swiftapp/Sources/XEntropyCore/SQLiteCredentialCatalog.swiftapp/Sources/XEntropyGateway/CatalogAPIHandler.swiftapp/Sources/XEntropyGateway/GatewayModels.swiftapp/Sources/XEntropyGateway/StatelessMCPHandler.swiftapp/Tests/XEntropyCLITests/CLICommandTests.swiftapp/Tests/XEntropyCLITests/LoopbackHTTPServerTests.swiftapp/Tests/XEntropyCLITests/SecretLeakBoundaryTests.swiftapp/Tests/XEntropyCoreTests/CredentialCatalogModelsTests.swiftapp/Tests/XEntropyCoreTests/CredentialCatalogServiceTests.swiftapp/Tests/XEntropyCoreTests/RotationPlanningTests.swiftapp/Tests/XEntropyCoreTests/SQLiteCredentialCatalogTests.swiftapp/Tests/XEntropyGatewayTests/CatalogAPIHandlerTests.swiftapp/Tests/XEntropyGatewayTests/GatewayTestSupport.swiftapp/Tests/XEntropyGatewayTests/StatelessMCPHandlerTests.swiftapp/Tests/XEntropyTests/APIKeyTableViewModelTests.swiftdocs/architecture/api-key-catalog-schema.mddocs/architecture/api-key-table-local-access.mddocs/backlog/phased-roadmap.mddocs/superpowers/plans/2026-08-28-api-key-table-mvp.mddocs/superpowers/specs/2026-08-28-api-key-table-and-stateless-mcp-design.md
External coordination/durable-record paths:
/Users/richh/.agent-coordination/checkins/codex-xentropy-api-key-table-20260827.json/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260828-0422-xentropy-api-key-table.md- Apple Notes iCloud folder
llmlogthrough/Users/richh/scripts/notes_changelog.zsh.
Commands and verification evidence
swift test --package-path app— 122/122 XCTest cases passed: 26 app/UI, 62 core, 15 gateway, and 19 CLI/transport/boundary.- Focused renamed server-stop test stress — 50/50 consecutive repetitions passed; a late partial-request remainder produced zero catalog reads after the server router/context boundary was cleared.
swift test --package-path app --filter SecretLeakBoundaryTests— 3/3 passed across schema SQL, forbidden schema columns, SQLite composite parents, snapshots/changes, CLI/API/MCP/HTTP success and error payloads, local sensitive metadata, and LiteLLM candidate exclusion.swift build --package-path app --product XEntropy— passed.swift build --package-path app --product xentropyctl— passed.git diff --check— passed.- Path/count-only provider-key and private-key scans — zero matching files; no matched values were printed.
- Production locator/resolver, Keychain mutation, and bearer-literal scans — zero matching source files.
- All listener tests used synthetic in-process authentication on
ephemeral loopback ports and stopped their listener. The production
servecommand, live catalog, and live Keychain were not used.
Independent disposable-archive review reproduced the same 122/122 split, 50/50 stop stress, 3/3 aggregate suite, both product builds, clean diff, and zero provider/private-key material paths. Lifecycle is received, reviewed, and accepted at code-review level only; nothing is merged, activated, deployed, or accepted for provider/secret use.
Explicit non-changes and outstanding owner actions
- No live
.envor Apple Notes secret body was scanned, sourced, copied, logged, imported, or retained. The baseline uses prior values-free alias/source observations only. - No secret was written to SQLite, Git, documentation, task messages, agent mail, logs, CLI/API/MCP output, or this changelog.
- The chat-exposed OpenRouter generation remains compromised pending owner revocation. It was not recovered, validated, or imported.
- No production app catalog was migrated or seeded; no Keychain item was created/read/updated/deleted; no fixed listener profile was started.
- No provider credential was created, validated, rotated, or revoked. GoDaddy, Cloudflare, Firecrawl, OpenRouter, mem0, and other adapters remain day-two design work.
- The future Touch ID-confirmed Copy Secret action and 30-second best-effort clipboard clearing remain a separately approved local-only feature, not an MCP operation.
- Remote HTTPS/OAuth/OIDC, claude.ai connection, public exposure, signing, packaging, publication, and deployment remain separately gated.
- Rich must choose branch disposition and separately reconcile the unrelated dirty canonical checkout.
- Tomorrow's first real rotation canary must be owner-attended, provider-specific, values-free in preview, target-confirmed, dual-key/rollback protected, and stop before revocation on any unknown consumer, tenant, scope, or partial failure.
Rollback / undo
No canonical project file, live catalog, Keychain item, provider,
service, listener, or deployment was mutated, so the immediate rollback
state is the unchanged dirty canonical main at base commit
f41eb604575450645da5cd97806a4e1e8ec081c6. The feature
branch and linked worktree are intentionally retained. If Rich rejects
the feature, deleting only the linked worktree and local
codex/api-key-table-v1 branch after preserving any desired
review artifacts removes the implementation without touching
main; no such deletion was performed by this task.