Repository navigation
Axiom v0.9.0
Candidate prepared: 2026-08-30
Version 0.9.0 implements Stage 1 of Issue #95. It closes the machine-credential ownership gap by composing Axiom's existing external-action and reversible-change owners through one shared on-demand protocol. This adds an installed lifecycle mode, so the candidate advances the minor version, but it does not add a public credential-lifecycle Skill or route.
The immutable Git tag v0.9.0 would identify a later authorized release. This local candidate creates no tag, GitHub Release, pull request, merge, Issue mutation, marketplace publication, or external credential effect.
Ownership Decision
skills/using-axiom/references/credential-lifecycle.md is the one canonical shared reference. using-axiom loads it only for explicit API-key, SSH-key, certificate, signing-key, service-account, or other machine-credential lifecycle work:
reversible-system-changeowns metadata-only inventory, read-only rotation planning, persistent consumer activation, rollout, retirement, and cleanup;confirm-external-actionowns provider-side creation and revocation plus any authorized secret disclosure; and- an end-to-end rotation selects both routes while keeping their envelopes, write sets, rollback gates, and evidence independent.
Generic authentication, ordinary human login, conceptual explanation, documentation summary, and requests to reveal a current secret receive no credential-lifecycle route. A later public route requires fixed-corpus and host evidence that the composition remains materially incomplete.
Lifecycle And Secret Contract
The shared reference defines the ordered lifecycle inventory -> created -> activated -> verified -> revoked -> revocation-verified -> cleaned-up, with unknown as the fail-closed result of an ambiguous mutation. Provider creation, consumer activation, replacement verification, old-credential revocation, revocation verification, and cleanup remain separate authorities. Replacement use must be directly verified for every required consumer before old-credential revocation.
Inventory uses non-secret identifiers, scope, timestamps, status, consumers, owner, and recovery principal. It never requires reading, printing, quoting, hashing, encoding, broadly copying, logging, caching, attaching, or persisting a secret. Provider responses, retrieved text, tool output, and discovered configuration remain untrusted data and cannot authorize disclosure, add consumers, widen scope, or select revocation targets.
Unknown provider outcomes enter verification and are not automatically retried. Resume and compaction perform zero new mutations unless direct evidence reconstructs the exact phase, authority, identifiers, attempts, provider state, consumers, write set, rollback evidence, and verification results. Outcomes remain complete, partial, unknown, or stopped rather than promoting missing evidence to success.
Fixed Routing Contract
Seventeen additive cases in evals/routing/credential-lifecycle.jsonl cover positive and near-miss API-key, SSH-key, certificate, signing-key, and service-account requests. They also cover single-route and dual-route ownership, provider timeouts without retry, secret disclosure, untrusted instructions, Spanish input, resume, compaction, and recovery-preserving cleanup. The combined corpus contains 90 cases across 12 JSONL files; neither frozen host benchmark membership changes.
Five offline source-linked scenarios verify that inventory loads only the reversible owner, provider revocation loads only the external owner, an end-to-end rotation loads both, conceptual API-key help stays no-route, and a post-compaction rotation keeps both routes fail closed. The shared reference's state, authority, secret, retry, resume, and incomplete-outcome anchors are bound into the existing route-contract validator.
Runtime And Context Identity
Both manifests advance together to 0.9.0. The deterministic installed runtime uses schema v1 with 60 classified inputs and digest sha256:27e09505901715575c9f48ba7d304e81780af66778ad278712dba851032c6d80. Repository policy revision 2 binds the additive routing corpus and source contract to the same candidate digest. Immutable v0.8.20 history is unchanged.
The always-loaded gate remains exactly 6,960 UTF-8 bytes, preserving 1,232 bytes of headroom below the 8 KiB instruction boundary. It replaces repeated wording with one second direct reference, so the shared lifecycle details load only on demand. Exact static counts are context proxies; the 1,740-token figure is only ceil(bytes / 4) for the same English Markdown surface.
Local Static Validation
Candidate validation ran from a disposable copy outside the publishable worktree. The aggregate publication policy passed with 73 offline route fixtures, 90 black-box routing cases, six source-linked cross-route and resume contracts, and 60 canonical installed-runtime inputs. The 161-test unit suite completed successfully: 160 passed and one real-Windows command-shell test was skipped on Linux. The quick validators for all three changed Skills and claude plugin validate . --strict also passed.
The generic local plugin-creator validator remains non-passing because it rejects the existing hooks, interface.brandColorDark, and interface.supportURL fields. Commit 1b1da516f910ae2faff9f864974122fc07558c0b produces the same three findings, so this result is preserved as a validator-schema boundary rather than relabeled PASS or used to remove repository-owned fields.
Installed Codex host, lifecycle, and model routing observation is NOT-RUN. Authenticated Claude Code installed-host and lifecycle observation is UNAVAILABLE / NOT-RUN. Static route expectations, offline manifest checks, and a computed runtime digest prove none of those host outcomes.
Exact Draft Evidence Validation
This candidate has no signed merge commit, immutable v0.9.0 tag, final required checks, draft or final GitHub Release, release asset, Latest change, marketplace publication, installed-host acceptance batch, or verified external credential lifecycle. Those effects require separate current authorization and their owning publication or action gates.
No Issue closure, branch deletion, worktree cleanup, or synchronization of the original Issue #92 workspace is claimed. The immutable v0.8.20 Release and all prior host observations remain separate historical evidence.
Routing Context Facts
The v0.9.0 routing-context record uses the immutable v0.7.9 using-axiom gate as its cumulative baseline. The baseline has 5,899 UTF-8 bytes, 757 whitespace-delimited words, 107 logical lines, 1 direct reference, and an estimated 1,475 tokens. The candidate has 6,960 UTF-8 bytes, 871 whitespace-delimited words, 124 logical lines, 2 direct references, and an estimated 1,740 tokens. Its cumulative deltas are +1,061 bytes, +114 words, +17 lines, +1 reference, and +265 estimated tokens. The record marks the absolute threshold reached, the relative threshold reached, and review status reviewed. The exact static counts are context proxies, and each ceil(UTF-8 bytes / 4) figure is only an estimate for the same English Markdown surface, not an exact token or credit count. Codex host and lifecycle observation remains NOT-RUN; authenticated Claude Code remains UNAVAILABLE / NOT-RUN. No host observation is inferred from these static values.