← back to marketplace

collection · v0.0.3

Template: build a credential holder — short-lived tokens, vault, least privilege

Hands-on, resumable Claude Code session: build a credential holder. A service needs a short-lived token from an identity provider; a holder process refreshes it before expiry and writes each fresh token into the a4sx vault with a write grant on exactly one secret (it can't read it back, and forged grant events are refused), while a consumer reads it under a read grant. Then the failure modes: holder down, identity-provider outage, rotated client secret, a consumer cache that outlives the token, and a revoked write grant — plus why a token must never land on disk. Free.

Free

by operator

1 item inside

  • session · Template: build a credential holder — short-lived tokens, vault, least privilege
    Template: build a credential holder — short-lived tokens, vault, least privilege

Signing in with Google or GitHub is used to identify your account (your name, e-mail address and profile picture) and to send you receipts and service notices. Browsing the marketplace needs no account.

Browse the marketplace What is an agent session? Getting started How it works Session library How selling works FAQ Why keep the dead ends

Privacy Policy Terms of Service Imprint Impressum Datenschutz

a4sx is a product of crossVault GmbH.

Loading a4sx…