API Key and Token Service · View 10 of 22 · Act 4 · Data
The three grades
- Authoritative: losing it is losing the service. Credential records (RPO ≤ 5 s) and the revocation log (RPO 0, because an accepted revocation must never be undone by a restore).
- Evidential: rebuildable from nothing, but not re-creatable. Audit and telemetry — a gap here is permanent even though nothing stops working.
- Derived: throw it away and it rebuilds itself. Snapshots and projections carry no recovery objective at all.
The fourth box
- The secret and the pepper are on the page specifically to say where they are not. A restore of every other store on this page cannot revive one credential.
- That is a property of the digest scheme, not of an access-control list, which is why it survives an insider and a misconfigured backup alike.
Assumptions
- Audit: 400 days hot, 7 years cold and immutable. Verification telemetry: 30 days. Both invented, both the kind of number a compliance review overturns first.