Keys secured.
The credential primitive of the platform pack — mint, scope, rotate, revoke, verify, audit, as one callable surface. Pre-launch, and this deck says so on every slide where it matters.
The moment an API has a second caller, its builder is in the key business: a keys table, a hashing scheme, a rotation policy nobody wrote down, a revocation path that gets its first test the night it is needed. The general-purpose auth vendors sell login for humans. The gateway products bundle a key check into a gateway you must adopt whole. The unit itself — a credential minted, scoped, rotated, revoked, and audited — is nobody's product, so everyone builds it badly, once per API.
The agent era multiplies both sides of the obligation at once. An agent holds keys to every service it calls — dozens of credentials per agent, not one password per human. An agent-native business issues keys to every agent that calls it — callers it will never meet, onboard, or interview. Hand-rolled custody was tolerable at human scale; at machine scale, the unrotated key and the untested revocation path stop being embarrassments and start being the perimeter.
Three things in the estate are the substrate itself; this is not one of
them. keys.do is a primitive of the platform pack — registry coordinate
primitives/security — the way functions.do is primitives/execution and
database.do is primitives/data. The platform's capability contract makes
principal and budget first-class terms; a key is where those terms
become something a caller can physically present. That is the whole
scope: not identity (the rail is id.org.ai), not consent (the pair is
oauth.do), not a gateway — custody of the held credential, sold at the
unit.
The pack is why the primitive is worth its own door. The estate's other primitives — functions, workflows, data, payments — are metered calls, and every metered call arrives with a credential to check. When this surface serves, it sits in the path of the pack's own traffic by construction. Stated as design, not as tenancy: no production caller is claimed anywhere in this record, because none exists yet.
The document addressed to this door's buyer is a verb surface, and its designed shape is fixed — shown here as design, binding only when the door serves:
Mint is cheap; verify is the product — it is the call in the path of every other call, and it is where the meter is designed to sit. Scopes bound what a key may reach; the principal binds who answers for it; a budget, where the platform contract sets one, caps what it may spend.
// designed shape — binds when the surface serves (the amber below)
POST /keys // mint: bind principal + scopes; secret shown once, hashed at rest
POST /verify // the volume event: secret in, verdict out — principal, scopes, budget
POST /keys/:id/rotate // new secret; the old one enters a declared grace window
DELETE /keys/:id // revoke: dead everywhere the platform answers, no redeploy
GET /keys/:id/audit // every presentation, verdict, and caller — the 2am question, answerable
The door itself. Everything in the code block above is designed shape, not a served endpoint: keys.do's apex today is a hosting placeholder, posted plainly on the serving slide. This claim flips green when the verbs answer at the apex, with a cold re-run in evidence — and until it does, this deck describes the contract's shape and claims nothing about its availability.
The security sub-batch is two primitives with one boundary. keys.do holds the HELD side: a credential the issuer mints and the caller holds — presented directly, revocable by the issuer alone, no consent flow anywhere in its life. oauth.do holds the GRANTED side: access a principal gives through a consent flow, carried by an expiring token that exists because someone else said yes. The routing rule for every edge case: ask who can kill the credential without asking anyone. If the issuer alone can, it is a Key, and it lives here. If revoking it means withdrawing someone's consent, it is a grant, and it lives next door.
The boundary is what keeps both doors sharp. This door never grows a
consent screen, a redirect flow, or a token exchange; the pair never
grows a keys table. Between them sits the identity rail: id.org.ai
answers who the caller is, this door answers what the caller
presents, the pair answers who granted the access.
The pair's apex serves. oauth.do answers 200 today (curl-verified 2026-07-30; re-verified 2026-07-31) — what stands there is the estate's sign-in application under the id.org.ai masthead ("Simple, Secure Sign-In for Humans and AI Agents"; the page's canonical is id.org.ai). That is stated as what it is: a liveness fact about the sibling's door, not a claim about this one — and the masthead filing is the oauth.do record's own business.
The identity rail serves. id.org.ai answers 200 today (curl-verified 2026-07-30; re-verified 2026-07-31) — the rail a key's principal binding is designed to point into.
Concreteness over adjectives, and candour over both: these are the doors checked cold on 2026-07-30 and re-checked 2026-07-31, each carrying its own state — including this brand's own apex, posted as exactly what it is.
keys.do answers 200 today — and what it serves is a hosting
placeholder: "Coming Soon — Domain keys.do is not yet provisioned"
(Startup Builder, noindex; re-verified cold 2026-07-31, identical).
Not a product surface, not the estate's own leaf. Posted green because
it is the apex's true, curl-verifiable behavior; the product surface is
the amber gate on the contract slide.
platform.do serves — the operator of the pack this primitive belongs
to, live at its own front door.
Serving is a liveness fact, not a tenancy claim — and here the registry and the door agree: domains/data/registry.tsv files keys.do as planned, P1, and the apex confirms it. This record wears pre-launch as pre-launch. The books flip when the door does, not before.
Primary motion is B2D: the builder who evaluates in the docs and converts at the first minted key — no sales motion, no demo call, the docs' depth as the trust engine. Secondary is B2A, stated as design reasoning, not a market figure: agents multiply both sides of a credential — an agent holds keys to every service it calls, and an agent-native business issues keys to every agent that calls it. When the machine surface serves, the same verbs answer to an agent caller; until then, the B2A leg is design intent and is stated as exactly that.
the pack design puts credential verification in the path of every metered call the other primitives serve — attached demand once the surface serves, claimed only then
held vs granted is a rule, not a roadmap: this door never grows a consent flow, the pair never grows a keys table, and neither dilutes into a generic auth platform
append-only presentation history compounds with every verified call — the record an issuer cannot reconstruct after the fact and will not casually migrate away from
keys.do is the generic name for the thing itself, in the estate whose pack the credential plane instruments
The apex answers, and answers honestly: a hosting placeholder, no product, no simulated signup — the true state of a planned P1 primitive, on the record.
The door. The verb surface on the contract slide serves at the apex, cold-verifiable. This is the gate everything conditional in this deck hangs from, and it is stated once here and once where the shape is drawn.
The claim that matters. An issuer outside the estate mints keys, its callers present them, a revocation lands without a redeploy, and the audit trail shows the whole life of the credential. It posts when it has happened, with the record in evidence — never implied before.
The record is the surface today: this deck, at pitch.keys.do. The door opens when the key surface serves at keys.do — no signup is simulated here.
If this was forwarded to you: keys.do is the credential primitive of an infrastructure estate — API-key mint, verify, rotate, revoke, and audit as one callable surface, the HELD side of a two-door security pair whose GRANTED side is oauth.do. It is pre-launch and says so: the two ambers it wears openly are the door itself serving and the first external issuer running a credential's whole life in production. What is green is what a cold check confirms today — the apexes and what each actually serves, placeholder included. Judge it by how plainly it labels the difference.