Skip to content

Correct what a Hookdeck credential is - #89

Open
leggetter wants to merge 1 commit into
mainfrom
correct-credential-types
Open

leggetter wants to merge 1 commit into
mainfrom
correct-credential-types

Conversation

@leggetter

Copy link
Copy Markdown
Collaborator

Caught by review on hookdeck/agent-skills#28.

packages/hookdeck/src/runtime.ts said "One credential type, two projects." The first half is wrong:

  • Hookdeck has organization API keys and project API keys.
  • The Outpost API additionally accepts a short-lived tenant JWT from GET /tenants/{tenant_id}/token. docs/apis/openapi.yaml in hookdeck/outpost carries both security schemes — AdminApiKey and TenantJwt, the latter per-tenant and valid 24 hours — and the tenant-facing portal uses the second for browser calls.

Why it is worth a PR rather than a quiet edit

The sentence propagated. #40 states it ("There is one credential type in Hookdeck — a project API key"), a subagent writing the fix for #40 restated it in skills/outpost/SKILL.md, and it reached review as a claim in a product artefact agents read.

We write the findings, so our errors ship. That is the path worth noticing, and it is the second time this week a wrong sentence of ours reached something public — the first was docs-reach figures quoted from a reporting defect (#83).

What is actually true of the harness

Narrower, and that is what the comment now says: it injects one project API key per project, and which project a key belongs to decides whether an Outpost call works. That is still the finding behind #39 and the prompt addendum.

#40's body still carries the wrong sentence and is corrected separately in a comment.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MQzUoMAwEBJWpEGVvVzSjK

The harness comment said "one credential type, two projects". The first half is
wrong. Hookdeck has organization API keys as well as project API keys, and the
Outpost API additionally accepts a short-lived tenant JWT from
`GET /tenants/{tenant_id}/token` — `docs/apis/openapi.yaml` in hookdeck/outpost
carries both `AdminApiKey` and `TenantJwt`, and the tenant portal uses the
second for browser calls.

Caught in review of hookdeck/agent-skills#28, which had taken the claim from
#40 and restated it in a skill agents read. A wrong sentence in this repository
became a wrong sentence in a product artefact, which is the propagation path
worth noticing: we write the findings, so our errors ship.

What is true of this harness is narrower and is what the comment now says: it
injects one project API key per project, and which project a key belongs to
decides whether an Outpost call works.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MQzUoMAwEBJWpEGVvVzSjK
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant