# Detect an API's credential issuer

Status: Accepted. Date: 2026-09-30. Card t_ad153e0a, tasks t_78502407 and t_c46588a4.

Web Risk's SDK obtains an access token through Google OAuth using Application Default Credentials. Detecting only
the Web Risk SDK omits the credential issuer; treating GOOGLE_APPLICATION_CREDENTIALS as ordinary app config can
copy a real credential file path from an example into the World.

An API descriptor may name its credentialIssuer, another pack of that vendor. Detection expands that declared
relationship and explains it in the vendor report; selection remains the operator's. Credential-door fill names
also detect their issuer exactly, without relying on suffix heuristics. A credential file path without a selected
issuer becomes a disposable missing path, never the example's real path.

Web Risk verifies issued tokens through the kernel's existing owner-store projection, exposed to derived handlers
as ownerRow over the manifest's allowed ownerReads pairs, and checks its spec's OAuth scopes. Revoked, expired and
invalid issued tokens are refused. A standalone World may state
an external token through a door, where the API cannot create one itself; it carries its grant and expiry. No
unconfigured issuer produces an authenticated success. The architecture's descriptor section owns these fields.
