deepseek-harness/docs
Yichen Jiang 86a9f8c862 feat(credentials): store durable credential records beside references
The seam answered one question — what is behind this environment-variable
name — and that shape cannot hold what an authorization grant is: a
multi-field, rotating value keyed by a provider id rather than by a POSIX
identifier. The Models page already works around the gap by inventing a
synthetic environment name (`MINIMAX_CN_API_KEY`) for a route the user added
by hand, because the store's key must look like one.

`CredentialKey` is `<scope>/<id>`, where the scope is the owning plugin's
registered name. The owner is in the key because a `grant` payload is written
in its owner's format: two plugins serving the same provider name would
otherwise read each other's payload, and a record left by an uninstalled
plugin could not be told from a live one. The `/` also keeps the grammar
disjoint from `CredentialRef`, so the key spaces cannot collide.

`CredentialRecord` is `api-key` (key and/or provider environment values) or
`grant` (an opaque, owner-owned payload). The asymmetry is deliberate: an api
key is the harness's own data, a grant is a package it carries for someone
else. `modifyRecord` is the only write path because a correct write depends
on the current value — a token refresh is read-decide-replace under one
cross-process lock, without which two processes rotating one refresh token
lose whichever wrote first.

`.credentials.yaml` becomes a versioned two-section document. The pre-release
flat layout is refused by name, with the entry count and the one edit needed,
rather than read as an empty store — which would surface as an authentication
failure on the first request instead of at load. A grant payload is admitted
in both directions, so a value the document could not read back exactly as
written is refused rather than stored lossily.
2026-08-20 17:58:38 +08:00
..
cookbook Merge remote-tracking branch 'origin/master' into feat/plugin-owned-settings-surface 2026-08-14 15:46:01 +08:00
cordis-api fix: test/docs 2026-08-13 01:30:49 +08:00
cordis-tutorial docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
i18n docs: split brand guidelines into bilingual pair 2026-08-19 21:01:18 +08:00
postmortem refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
subsystems feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
user docs(user): point the provider guide at the adapter's catalog section 2026-08-19 13:46:39 +08:00
agent-lifecycle.i18n.yaml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
agent-lifecycle.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
agent-lifecycle.zh.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
AGENTS.md update architeture.md 2026-08-12 21:01:11 +08:00
api-gateway.i18n.yaml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
api-gateway.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
api-gateway.zh.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
architecture.i18n.yaml docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
architecture.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
architecture.zh.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
capability-seams.i18n.yaml docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
capability-seams.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
capability-seams.zh.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
config-catalog.i18n.yaml feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
config-catalog.md feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
config-catalog.zh.md feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
cordis-primer.i18n.yaml docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
cordis-primer.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
cordis-primer.zh.md docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
defensive-patterns.i18n.yaml docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
defensive-patterns.md docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
defensive-patterns.zh.md docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
development.i18n.yaml feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
development.md feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
development.zh.md feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
event-producer-consumer.i18n.yaml feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
event-producer-consumer.md feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
event-producer-consumer.zh.md feat(credentials): store durable credential records beside references 2026-08-20 17:58:38 +08:00
glossary.i18n.yaml docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
glossary.md docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
glossary.zh.md docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
graph-atlas.i18n.yaml refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
graph-atlas.md refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
graph-atlas.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
module-graph.i18n.yaml test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
module-graph.md test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
module-graph.zh.md test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
persistence-catalog.i18n.yaml Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
persistence-catalog.md Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
persistence-catalog.zh.md Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
rescope.i18n.yaml build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
rescope.md build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
rescope.zh.md build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
testing.i18n.yaml test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
testing.md test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
testing.zh.md test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
tool-catalog.i18n.yaml docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-catalog.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-catalog.zh.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-execution-pipeline.i18n.yaml refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
tool-execution-pipeline.md refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
tool-execution-pipeline.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
web-styling.i18n.yaml docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
web-styling.md
web-styling.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00