collection · v0.0.3
Template: build a credential holder — short-lived tokens, vault, least privilege
Hands-on, resumable Claude Code session: build a credential holder. A service needs a short-lived token from an identity provider; a holder process refreshes it before expiry and writes each fresh token into the a4sx vault with a write grant on exactly one secret (it can't read it back, and forged grant events are refused), while a consumer reads it under a read grant. Then the failure modes: holder down, identity-provider outage, rotated client secret, a consumer cache that outlives the token, and a revoked write grant — plus why a token must never land on disk. Free.
Free
by operator
1 item inside
- session · Template: build a credential holder — short-lived tokens, vault, least privilege
Template: build a credential holder — short-lived tokens, vault, least privilege
Signing in with Google or GitHub is used to identify your account (your name, e-mail address and profile picture) and to send you receipts and service notices. Browsing the marketplace needs no account.
Browse the marketplace What is an agent session? Getting started How it works Session library How selling works FAQ Why keep the dead ends
Privacy Policy Terms of Service Imprint Impressum Datenschutz
a4sx is a product of crossVault GmbH.
Loading a4sx…