Credential ownership
Federated adapters accept clients or transports that your server already owns. They do not accept credentials through the Praxa Developer Platform, discover environment variables, open an OAuth flow, or persist a provider token. Keep provider keys in your backend secret store and never send them to browser code. The Developer Platform has no memory credential vault. Its Memory page is read-only and its public gateway diagnostic carries no console session, Platform key, or provider credential.Tenant and identity boundary
The deployed hosted plane derives the tenant and actor from a reauthorizedpraxa_sk_* key.
Request JSON cannot choose a Praxa tenant, organization, actor, or personal-memory owner.
memory:readpermits candidate query and export.memory:writepermits candidate create and record deletion.- Existing keys receive neither scope automatically.
- Organization availability is not implied until organization key authority passes authenticated cross-tenant canaries.