{"schemaVersion":"repository.manifest/v1","id":"reits-auth","name":"reits-auth","organization":"reits","workspacePath":"reits-auth","ownership":{"accountable":"Identity Platform","workstream":"W1"},"source":{"remote":"https://gitea.reits.tech/reits/reits-auth.git","defaultBranch":"main","observedRevision":"2aebd6b20b88b98edbd9b11b29c0db87d5a55b0c","posture":"exact-default","verifiedAt":"2026-07-21T08:13:05Z"},"lifecycle":{"class":"platform","status":"active","decision":"Retain as the canonical non-native authentication and durable session authority; complete MFA, recovery, consumer propagation and asymmetric signing."},"runtime":{"kind":["Go","MySQL session registry","systemd"],"production":"deployed","entrypoints":["go test ./...","./scripts/smoke.sh"]},"surfaces":[{"kind":"api","name":"Authentication, challenge, refresh, session and revocation APIs"},{"kind":"service","name":"Client-scoped token and session authority"}],"contracts":[{"name":"AuthSession","role":"producer","version":"unversioned"},{"name":"TokenIntrospection","role":"producer","version":"unversioned"},{"name":"RevocationEvent","role":"producer","version":"unversioned"}],"tests":{"commands":["go test ./...","./scripts/smoke.sh"],"workflowCount":2,"status":"present"},"slo":{"tier":"tier-0","status":"partial","objectives":["Authentication availability","Bounded revocation propagation","Durable session registry recovery"]},"idempotencyKey":"d01-repository-manifest-v1-reits-auth","links":{"registry":"/api/repository-manifests","schema":"/schemas/repository-manifest.v1.schema.json"}}