Conversation
The harness comment said "one credential type, two projects". The first half is
wrong. Hookdeck has organization API keys as well as project API keys, and the
Outpost API additionally accepts a short-lived tenant JWT from
`GET /tenants/{tenant_id}/token` — `docs/apis/openapi.yaml` in hookdeck/outpost
carries both `AdminApiKey` and `TenantJwt`, and the tenant portal uses the
second for browser calls.
Caught in review of hookdeck/agent-skills#28, which had taken the claim from
#40 and restated it in a skill agents read. A wrong sentence in this repository
became a wrong sentence in a product artefact, which is the propagation path
worth noticing: we write the findings, so our errors ship.
What is true of this harness is narrower and is what the comment now says: it
injects one project API key per project, and which project a key belongs to
decides whether an Outpost call works.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MQzUoMAwEBJWpEGVvVzSjK
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caught by review on hookdeck/agent-skills#28.
packages/hookdeck/src/runtime.tssaid "One credential type, two projects." The first half is wrong:GET /tenants/{tenant_id}/token.docs/apis/openapi.yamlinhookdeck/outpostcarries both security schemes —AdminApiKeyandTenantJwt, the latter per-tenant and valid 24 hours — and the tenant-facing portal uses the second for browser calls.Why it is worth a PR rather than a quiet edit
The sentence propagated. #40 states it ("There is one credential type in Hookdeck — a project API key"), a subagent writing the fix for #40 restated it in
skills/outpost/SKILL.md, and it reached review as a claim in a product artefact agents read.We write the findings, so our errors ship. That is the path worth noticing, and it is the second time this week a wrong sentence of ours reached something public — the first was docs-reach figures quoted from a reporting defect (#83).
What is actually true of the harness
Narrower, and that is what the comment now says: it injects one project API key per project, and which project a key belongs to decides whether an Outpost call works. That is still the finding behind #39 and the prompt addendum.
#40's body still carries the wrong sentence and is corrected separately in a comment.
🤖 Generated with Claude Code
https://claude.ai/code/session_01MQzUoMAwEBJWpEGVvVzSjK