Enforcement
Enforcement
Enforcement adds three gate capabilities for tenant agents and CI pipelines:
- Credential vault — envelope-encrypted API keys (Stripe only in Phase 1).
- Gated execution — single-use leases that call a fixed upstream host with a vaulted credential.
- CI attestation — signed
writ scanmanifests and per-repo drift.
These endpoints are tenant-facing and documented here. Portal-only endpoints (vault enrollment and revocation, which require a signed-in session + TOTP) are internal and omitted.
Credential vault
The vault stores one credential per enrolled system per tenant. Phase 1 supports Stripe only (systemId: stripe).
- Credentials are envelope-encrypted with AWS KMS
GenerateDataKeyand an encryption context{tenant_id, system_id}. - The plaintext credential exists only in gate memory at execute time.
- After enrollment the API key is never displayed or returned again.
- Revocation sets the credential status to
revokedand burns outstanding leases.
Enroll and revoke are portal-only actions: sign in at https://app.withwrit.com, go to Enforcement, and confirm with your authenticator app.
Gated execution
1. Get an ALLOW token
Your agent calls POST /v1/check as usual. An ALLOW response contains an authToken bound to the exact write.
2. Create a lease
Convert the ALLOW token into a single-use lease bound to the exact Stripe request you intend to send. The lease TTL is capped to the token’s remaining life (≤ 90 seconds).
3. Execute
Call POST /v1/execute with the lease id and the same method/path/body.
The gate returns Stripe’s status and body verbatim. If the lease is expired, reused, the request bytes don’t match, or the credential is revoked, the gate fails closed: no upstream call, and an error receipt.
Constraints
systemIdmust bestripein Phase 1.pathmust begin with/v1/.bodymust be JSON and ≤ 1 MB.- No streaming, no multipart, no arbitrary URLs.
CI attestation
writ scan can emit a signed manifest for CI.
Fetch the manifest key
Issue once per tenant:
Store the returned key in CI as WRIT_MANIFEST_KEY.
Produce a signed manifest
The manifest includes:
repoIdcommitShascannerVersion- per-language findings summary
- ungated write-sites (
path+verb) policyFileHashtimestamp
It is signed with HMAC-SHA256 over the canonical JSON.
Submit the manifest
where manifest-payload.json is:
The gate verifies the signature, stores the manifest, and returns drift vs the previous manifest:
newUngatedSitesresolvedSitespolicyHashChangedscannerVersionChanged
View the latest manifest and drift in the portal under Enforcement, or via GET /v1/manifests and GET /v1/manifests/{repoId}.
API reference
See the Enforcement endpoints in the API reference:
POST /v1/leasesPOST /v1/executeGET /v1/manifest-keyPOST /v1/manifestsGET /v1/manifestsGET /v1/manifests/{repoId}