rdmsm4x-changelog-20260927-0118-rdmodelrouter-keys
rdmsm4x - feature - populate API keys in keychain and support CLI logins - agy - FEAT-20260927-10 - rdmodelrouter - 2026-09-27 01:18 EDT
[2026-09-27 01:18:00 EDT · rdmsm4x · agy@rdmsm4x/rmrkeys0927 · FEAT-20260927-10]
Summary
Completed Phase 3 delivery for rdmodelrouter in worktree
~/dev/_worktrees/rdmodelrouter-keys-20260927 (branch
rmr/keys-logins-20260927, commit 5cf2830).
What Was Done
- VERIFY R1 Resolution:
- Fixed post-cutover Codex tie-breaking logic in
Dispatcher.swiftso that verified accounts (selection.verified == true, e.g.icloud) take precedence over unverified placeholder accounts (gmail) when drain dates tie or reset dates are absent. - Added unit test
postCutoverPrefersVerifiedAccountOverUnverified.
- Fixed post-cutover Codex tie-breaking logic in
- Key Inventory (
KEY-INVENTORY.md):- Scanned
~/dev,~/.config,~/.secrets, and~for.env-style API key configurations. - Identified 33 occurrences across 9 distinct keys/endpoints with zero cross-file value conflicts.
- Scanned
- Keychain Credential Storage:
- Stored all 9 distinct provider keys/settings into the macOS login
Keychain under service
"rdmodelrouter", account"<VAR_NAME>". - Used native Security framework in-memory APIs
(
SecKeychainAddGenericPassword/SecItemCopyMatching) without exposing secret values on argv, shell history, or logs.
- Stored all 9 distinct provider keys/settings into the macOS login
Keychain under service
- Call-Time Key Resolver
(
KeyResolver.swift):- Implemented
KeychainKeyResolverto resolve credentials at call time directly from Keychain and environment. - Non-secret status checks report presence, source, and 4-character
masked fingerprints (
KeyResolution). Never caches or writes keys to disk.
- Implemented
- Tyrell Architecture Proposal
(
TYRELL-PROPOSAL.md):- Inspected
~/.tyrell/and~/Library/Application Support/Tyrell/. - Drafted specification for Tyrell
key-registry.jsonandcli-logins.jsonholding non-secret credential references and login statuses.
- Inspected
- Official CLI Service Logins
(
AccountStatusReader.swift):- Implemented
rdmodelrouter accounts [--json]reporting official status forclaude,codex,agy, andgrok. - Implemented
rdmodelrouter login <cli> [--account <id>] [--apply]: dry-run by default printing exact commands; isolatesCODEX_HOMEfor secondary accounts (e.g.~/.codex-gmail).
- Implemented
- StatusKit & StatusApp:
- Extended
RDModelRouterStatusKitandRDModelRouterStatusAppto render provider key presence and CLI login status.
- Extended
- Verification & Testing:
- Universal2 compilation verified for
rdmodelrouterandRDModelRouterStatusApp(x86_64+arm64, Intel minos 26.7). - Test suite passing: 69 tests across 10 suites, 0 failures.
NoSecretLiteralsTestsscanner verified zero API keys committed to the repository.- Handoff documentation written to
~/dev/_handoff/rdmodelrouter-keys-20260927/RESULT.md.
- Universal2 compilation verified for