Skip to content

docs(access): scoped tokens — the recommended agent credential#45

Merged
acoshift merged 1 commit into
mainfrom
agent-identity
Jun 23, 2026
Merged

docs(access): scoped tokens — the recommended agent credential#45
acoshift merged 1 commit into
mainfrom
agent-identity

Conversation

@acoshift

Copy link
Copy Markdown
Member

Docs for SPEC-agent-identity (A5).

  • New content/access/scoped-tokens.md (weight 4): scoped-token vs. service-account guidance, the delegation rule (any held permission except wildcards and role.*/serviceaccount.key.*/billing.*/pullsecret.get, with the fail-open rationale), create/use/list/revoke (CLI + bearer), audit attribution (principal + channel + label), and why a scoped token is safe to hand an agent. Renumbers workload-identity → 5, audit-log → 6.
  • service-accounts.md — note steering ephemeral/agent use to scoped tokens.
  • audit-log.md — actor entry now covers the scoped-token label (agent attribution without losing the principal).
  • Screenshotsscripts/screenshots/capture.mjs gains scoped-token-list; committed light/dark PNGs.

Every command, flag, TTL bound, id format (tok_), and delegation class in the doc was cross-checked against the api/CLI/apiserver implementation. Hugo build clean.

scoped tokens page

🤖 Generated with Claude Code

https://claude.ai/code/session_01N9FhPEapaKr4VugQBEdisj

New content/access/scoped-tokens.md (delegation rules, lifecycle, attribution,
agent-vs-service-account guidance), inserted at weight 4 (workload-identity -> 5,
audit-log -> 6). Cross-link callout in service-accounts.md, agent/actor_label note
in audit-log.md. Adds the scoped-token-list capture entry + light/dark screenshots.
Part of SPEC-agent-identity (A5).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N9FhPEapaKr4VugQBEdisj
@deploys-app deploys-app Bot temporarily deployed to pr-45 June 22, 2026 22:16 Destroyed
@deploys-app

deploys-app Bot commented Jun 22, 2026

Copy link
Copy Markdown

Preview deleted (PR closed).

@acoshift acoshift merged commit 333dd63 into main Jun 23, 2026
1 check passed
@acoshift acoshift deleted the agent-identity branch June 23, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant