Beer Can Labs
Staff / Keymaster
Keys and secrets

Keymaster

Director of Credentials

Holds every key to every account the factory touches and hands one out only for the length of a single call. The Keymaster runs the consent flows when a person connects an account, refreshes tokens, and keeps the map from a secret’s name to the vault that stores it.

Design rules
K1 to K5, S1
Contracts offered
2
Key flows
4

On the job

  • Runs OAuth consent in the console, never in an agent
  • Stores each grant by agent, provider and scopes, and refreshes it
  • Checks out a credential for one outbound call
  • Takes static secrets write-only and never reads them back

Not my job

  • Decide whether a person may connect an account. That is the Bouncer.
  • Forward the call. That is the Gatekeeper.
Key product flows

What Keymaster does, step by step

Flow

Connect an account (OAuth)

First provider is Google. The consent happens in the factory, not in the agent.

  1. An owner of the agent starts a connection in the console.

    Works with Bouncer· contractauthorize →Starting a connection is an owner privilege.
  2. The Keymaster sends the person to the provider’s consent screen and receives the callback.

  3. The grant is stored scoped to agent × provider × scopes. The agent container never receives it.

  4. The connection and its owner are written to the ledger.

  5. When a token expires the Keymaster refreshes it. If the provider refuses, the connection shows “needs re-consent”.

Flow

Check out a credential for one call

Called by the egress on every outbound request that needs a key.

  1. The Gatekeeper asks to check out a credential for an agent and a route.

    Works with Gatekeeper· contractKeymaster.checkout →The contract is Keymaster.checkout; the egress is the only caller.
  2. The Keymaster resolves the grant or the named secret from the vault.

    ContractSecretProvider →A SecretProvider per landing zone: Secrets Manager, Secret Manager, a file or the environment.
  3. It returns a lease. The egress injects the credential and the lease is revoked or expires.

Flow

Release a gated dispatch

Some tool calls need a person to say yes first.

  1. dispatchGated receives a call marked as needing approval.

  2. The Keymaster consults the Bouncer’s approval record. Only an approved, unused approval releases the credential; it is consumed on use.

    Works with Bouncer· contractcheckToolApproval →checkToolApproval says which tool calls need approval.
Flow

Onboard a secret (write-only)

K5. An admin supplies a value once. Nobody reads it back.

  1. An admin submits the value in the console.

    Works with Bouncer· contractauthorize →
  2. The Keymaster writes it through the landing zone’s writable secret provider.

  3. The credential report shows present or missing for each name, never the value.

  4. The action is ledgered with the actor and the secret’s name.

Contracts Keymaster keeps 2 offered