SIGN IN SIGN UP

feat(custody): log scoped 401 retry decisions and delivered reports

When the vault records a stale 401 report (applied=0), explaining it needs the
consumer's side of the timeline: which version the physical request served,
which version the re-authorize returned, whether the request retried, and
which version was finally reported. The scoped build logged a retry only at
four of the five send sites, never logged the no-retry arm, and never logged a
delivered report.

decideScopedRetryAfter401 replaces the bare rotation predicate at all five
sites (model, model-relay, CacheKeep, Prime, quota/profile) and records each
decision at debug. reportFailure records a report the vault accepted, with its
served record version and reporter source. Neither line carries credential
material.
I
iceteaSA committed
ee0bdb5db57c8de7a072e4f9dfc1d37aebf8b7d5
Parent: a042f75