Expand description
Context shared by persisted agent definitions and credential routing. This identifies work ownership; it is not proof of organization membership.
resolve decides which context a new session binds: the user’s default
org, a repository’s org, an agent’s permitted set and an explicit choice
combine under one rule that refuses rather than falls back.
Modules§
- resolve
- Which work context a new session binds.
Structs§
- Work
Context - Immutable authority on an agent/resource. This is a routing key, not a membership attestation. The token issuer validates each requested org.
Functions§
- validate_
organization_ id - Check an organization id’s canonical form: 1-256 bytes of ASCII
alphanumerics,
.,_or-. Shared byWorkContext::validateand by places that name an org without an account, such as a repository’s.car/config.toml.