Volter World

Detect an API's credential issuer

Status: Accepted. Date: 2026-09-30. Card t_ad153e0a, tasks t_78502407 and t_c46588a4.

Web Risk's SDK obtains an access token through Google OAuth using Application Default Credentials. Detecting only the Web Risk SDK omits the credential issuer; treating GOOGLE_APPLICATION_CREDENTIALS as ordinary app config can copy a real credential file path from an example into the World.

An API descriptor may name its credentialIssuer, another pack of that vendor. Detection expands that declared relationship and explains it in the vendor report; selection remains the operator's. Credential-door fill names also detect their issuer exactly, without relying on suffix heuristics. A credential file path without a selected issuer becomes a disposable missing path, never the example's real path.

Web Risk verifies issued tokens through the kernel's existing owner-store projection, exposed to derived handlers as ownerRow over the manifest's allowed ownerReads pairs, and checks its spec's OAuth scopes. Revoked, expired and invalid issued tokens are refused. A standalone World may state an external token through a door, where the API cannot create one itself; it carries its grant and expiry. No unconfigured issuer produces an authenticated success. The architecture's descriptor section owns these fields.

View Markdown source