Credential Custody and Turn Admission

Credential Custody and Turn Admission An architecture diagram generated by Archify. TAP user · Save or select a key · Architecture component TAP user Save or select a key Gateway · Custody, consent, release · Credential custody boundary · sole authority Gateway Custody, consent, release sole authority Credential vault · Ciphertext + data-key envelope · Credential custody boundary Credential vault Ciphertext + data-key envelope Environment root key · KMS CMK or secret-store root · Architecture component · no per-agent keys Environment root key KMS CMK or secret-store root no per-agent keys AgentSessionDO · Turn admission + cache · Room execution boundary · memory only AgentSessionDO Turn admission + cache memory only ze-harness estate · Credential alias + revision · Room execution boundary ze-harness estate Credential alias + revision Model provider · OpenRouter, OpenAI, Anthropic… · Architecture component Model provider OpenRouter, OpenAI, Anthropic… save / rotate / delegate envelope ciphertext + revision encrypt/decrypt with bound context authorize before turn miss only: memory material inject credential alias run admitted turn Credential custody boundary Room execution boundary Legend Frontend Backend Database Cloud Security External

Authorization is not encryption

  • • Gateway rechecks delegation, policy, revocation, and credential revision before every new turn.
  • • A Gateway outage is unavailable; it never becomes an implicit allow.

Exact cache and deduplication unit

  • • Use an opaque credential identity plus its revision — never providerId alone.
  • • Coalesce concurrent cold loads per room and exact identity; invalidate on a different revision.

KMS scope

  • • One root key per environment or required region; a distinct data key per stored credential revision.
  • • KMS runs on save/rotation and cold materialization, not once per agent, execution, or provider request.