{"service":"platphorm-keys","version":"1.0.0-phase1","baseUrl":"https://keys.platphormnews.com","publicSafeAccess":true,"authPolicy":{"keyName":"PLATPHORM_API_KEY","requireApiKey":true,"acceptedHeaders":["Authorization: Bearer $PLATPHORM_API_KEY","X-PlatPhorm-API-Key: $PLATPHORM_API_KEY"],"publicSafePhase1":true,"enforcementDefault":true},"issuanceRole":"Protected source of truth for PLATPHORM_API_KEY values across PlatPhormNews platform actions.","keyStoragePolicy":{"rawSecretsStored":false,"oneTimeReveal":true,"storedMaterial":["key hash","AES-256-GCM encrypted material where backend persistence is available","public prefix"]},"keyRotationPolicy":"Rotation generates a new secret for an existing key id and reveals it once to authorized callers.","keyRevocationPolicy":"Revocation disables validation while preserving audit history.","rateLimitPolicy":"Provisioning and validation are bounded by atomic fixed-window counters in same-account DynamoDB. Identifiers are stored only as SHA-256 hashes; storage failure denies closed.","scopes":[{"scope":"read","access":"operator-issued","description":"Read public-safe platform resources."},{"scope":"write","access":"operator-issued","description":"Create or update resources where a service permits writes."},{"scope":"mcp","access":"operator-issued","description":"Use MCP introspection and permitted MCP actions."},{"scope":"trace","access":"operator-issued","description":"Attach trace context and inspect permitted trace links."},{"scope":"admin","access":"protected only","description":"Administrative key-management actions."},{"scope":"sync","access":"protected only","description":"Refresh network/discovery metadata."},{"scope":"report","access":"protected only","description":"Generate Sheets, Docs, and Decks reports."},{"scope":"workflow","access":"protected only","description":"Run remediation/workflow integrations."},{"scope":"site","access":"protected only","description":"Manage site-scoped access."},{"scope":"registry","access":"protected only","description":"Mutate trusted registry state."},{"scope":"keys","access":"protected only","description":"Manage key lifecycle records."},{"scope":"bbs","access":"protected issuance only","description":"Authenticate private PlatPhorm BBS member areas."}],"telemetryAuditPolicy":"Public telemetry is summary-only. Sensitive spans, usage, and audit details are protected.","trustedDomainPolicy":"*.platphormnews.com trusted by default; localhost, private, link-local, and metadata hosts are not trusted for discovery/proxy/replay.","routeStandard":["health","docs","openapi","llms","rss/feed","sitemap","mcp metadata","agents","security","trust"],"vercelMetadataPolicy":"Only safe request metadata is captured; Authorization, X-PlatPhorm-API-Key, cookies, raw IPs, and raw bodies are not public.","tracePropagationPolicy":"W3C trace context is accepted and response context is emitted. Routine product and MCP traces are durably queued in same-account DynamoDB, drained to Trace every 15 minutes, retried at most five times with exponential backoff, and retained as health-visible dead letters after exhaustion. Lifecycle certification exports directly for synchronous Trace readback.","backendModelScaffoldingPolicy":"Server-only provider-neutral adapter returns honest degraded state when no model provider is configured.","dataExposurePolicy":"Discovery files never contain raw key secrets, private key ids tied to users, sensitive audit data, or raw IP addresses.","securityContact":"admin@platphormnews.com","requiredTrustLine":"Web dashboard, public-safe discovery, browser-based operations, trusted-domain discovery, standard route compliance, Vercel metadata capture, trace inspection, and agentic workflow discovery are intentionally supported for public read-only debugging and operator workflows. Mutating, administrative, ingestion, replay, fork, remediation, deployment, sync, test-triggering, reporting, and write actions require PLATPHORM_API_KEY."}