BYOK-only operation
Bearer gateway-key traffic requires customer-supplied provider credentials. Server-owned provider credentials are not eligible for those requests.
Evidence in the current implementation
- • Gateway-key requests pass requireByok=true into the gateway engine.
- • Credential resolution disables server-environment credentials when requireByok is set.
- • Missing customer credentials produce a terminal/missing-credential attempt rather than silently switching to a server-owned key.
- • Attempt traces expose the credential source for successful attempts.
Reproduce it
- 1. Create a gateway API key.
- 2. Connect one customer provider credential and configure a fallback chain.
- 3. Disable or invalidate the primary customer credential.
- 4. Send a request with the gateway API key.
- 5. Inspect aethergate_telemetry.attempt_trace and confirm every successful attempt reports credentialSource=byok_vault.