sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · providers.sgit.ai · llms-full

Reading room / providers.sgit.ai / llms-full.txt · section 25 of 33

The four

{{claim:patterns-canonical}}

#PatternWhere the credential livesWhat bounds itVerdict
0Key in the pageIn the delivered applicationNothingNever. Anybody who opens the page has the key and the account. A plan quota is a ceiling, not a bound: it belongs to the whole account
1Bounded key in the pageIn the page, provisioned per user with a spending limit and a resetMoney, and a reset windowAcceptable where the platform can mint one. The limit is the blast radius, so choosing the number is a risk decision rather than a default
2Short-lived tokenNot in the page. A server exchanges the real key for a token with a short lifeTime, and the server's policyThe standard answer — and it needs a server: the vendor's, if it offers one for that product, otherwise yours
3Host holds the keyNever in the application. The application asks a host, which holds the key and enforces the termsThe host, which the application cannot reachThe strongest, and this estate's own: the only pattern where the bounded thing cannot reach the bounding thing

The ladder is not a maturity model. Pattern 1 with a $5 limit can be a better answer than pattern 2 with a badly-scoped minter. The question is always what is the blast radius, and who chose it.