Architecture decision records
Each record describes a decision that shapes agent-auth, the context it was made in and what it costs. Records are immutable once accepted. A later record can supersede an earlier one.
| Record | Status |
|---|---|
| 1. Ed25519 JWTs backed by server state | Accepted |
| 2. Hash-chained audit log in SQLite | Accepted |
| 3. Conservative scope attenuation | Accepted |
| 4. Bun executables and tag-driven releases | Accepted |
To propose a new decision, copy the structure of an existing record into a pull request.