Data dictionary
The complete inventory of what Writ keeps about you and your agents. If an object isn’t listed here, Writ doesn’t store it.
A standing rule: raw secrets are never stored. API keys, sponsor tokens, and magic-link tokens are kept as SHA-256 hashes only. The raw value is shown exactly once, at creation, and then it’s gone.
Tenant
Your account. One tenant per email address. Everything below belongs to a tenant.
API key
Authenticates calls to the gate. Looks like writ_…. A tenant can have many.
Lost your key? While signed in to the portal you can mint a new one (API keys → + New key) and revoke the lost one. No need to delete anything.
Sponsor token
The human half of the credential pair. Looks like writ_sp_…. One per
tenant, minted when the tenant is created, shown once, never recoverable,
never re-issued through the portal today.
It authorizes the human-side operations: creating grants, revoking and reinstating principals. The API key says which tenant is asking; the sponsor token says a human approved this.
Principal
An agent acting on someone’s behalf: a sponsor (the human or system that approves) plus an agent (the software doing the work), within a tenant. Principals come into existence implicitly — the first time a grant names them — and can be revoked pre-emptively.
Policy
One per tenant. A table mapping each verb to a mode. There is no per-agent or per-environment policy today.
The verb set is fixed in the gate (money movement, identity, data changes, communications, infrastructure, and others). Custom verbs are not supported today.
Grant
A short-lived permission slip minted by a human (sponsor token or dashboard)
after a STEP_UP, or directly via POST /v1/grants.
Receipt
Written for every decision the gate makes — ALLOW, DENY, STEP_UP,
REVOKE, and others. Denials write receipts too: the refusal itself is
auditable. Receipts are the audit log, and the audit log is the meter.
Verify any receipt chain with GET /v1/receipts/verify or ./writ verify-chain.
Revocation
The kill switch. Revoking a principal denies every subsequent check for that sponsor/agent pair, immediately.
Reinstate undoes it; the principal can check again.
Magic-link token
Single-use sign-in token, emailed to you. Stored as a SHA-256 hash with a 15-minute expiry; the raw token travels in the URL fragment so it never lands in server logs. The account-creation variant works the same way and creates the tenant only when clicked.
Rate limits
Unauthenticated endpoints are bounded before any account lookup, so the limits themselves can’t be used to probe for accounts: 30 magic-link requests per hour per IP, a per-email cooldown on magic links, and per-tenant caps on key creation.