[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1jqqfvgbmu3o6":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6abad242ca21c797c7e9a54e","the-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb","The credential your record names is not the one that made the call","The last piece ended by naming something I could not answer.","news",[10,13,18,23,28,33,38,43,48,53],{"headline":6,"body":11,"imageUrl":12,"sourceImageUrl":12},"The last piece ended by naming something I could not answer. A reader had asked what happens when a credential is rotated in the middle of a long-running session, and I said that question landed in the part my control plane explicitly excludes, so I had nothing to report. A second reader replied that I had already answered it. They were right. The rule held up; the boundary I drew was too wide, and it pulled this question into the excluded part.","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fwilliamlab.dev%2Fcovers%2Fcredential-provenance.png",{"headline":14,"body":15,"imageUrl":16,"images":17},"The answer was the second rule, one layer","The answer was the second rule, one layer down. The record has to hold what the system actually did rather than what it was asked to do. For context length that means the value the runtime granted, whatever number the request carried. For a credential it means the one the call actually presented, not the one the configuration names. The window that reads as complete","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"A rotation does not take effect everywhere at","A rotation does not take effect everywhere at once. Configuration points at the new key immediately. A session that resolved the credential once and is holding the token keeps using it until that token expires or a call fails. For the length of that window there are two credentials in play and only one of them is doing anything.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"A record that reads the credential from configuration","A record that reads the credential from configuration at write time is wrong for exactly the calls inside that window. It is not empty and it does not error. It names a real key, in the right format, for a call that key never made. This is the same failure the last piece opened with, where a field that was never recorded and a field that happens to equal the default read back identically. The record is wrong in a way that looks like being right, which is the only kind of wrong that survives six weeks.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"The calls inside that window are also, reliably","The calls inside that window are also, reliably, the ones someone will ask about. Rotations happen because something prompted them. It costs a value, not a secret","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"The fix does not require handling anything sensitive","The fix does not require handling anything sensitive. A key identifier is enough to say which credential made a call. For a JWT, kid and jti name the key and the specific token, and exp says when that token stopped being able to act. None of the three are secret. They are the parts of a credential designed to be quoted.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"That third field is doing more work than","That third field is doing more work than it looks. After a rotation the question that follows immediately is how long the old credential could still have acted, and exp answers it from inside the record. Without it, the honest answer to whether a call happened before or after the cutover is that you would have to reconstruct it, which is the thing the record exists to avoid. Copy it, do not look it up There is a way to add these fields and still have the same bug, one layer up.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"If the record stores the key identifier but","If the record stores the key identifier but resolves exp when the record is written, or worse when it is read, it resolves against whatever key metadata is current at that moment. After the next rotation that metadata describes a different credential. The record would then be authoritative about the lifetime of a key that had nothing to do with the call, and it would be internally consistent, so nothing would flag it.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"So the rule is narrower than recording the","So the rule is narrower than recording the credential. The record holds kid, jti and exp as presented, copied at the moment of the call, frozen. A provenance field resolved later is not provenance. It is a reading taken at read time, stored in a column that claims otherwise.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"This is also why the field tends not","This is also why the field tends not to exist. To copy what the call presented, the thing writing the record has to see what the call presented, which means the recorder sits at the call site with the transport layer's view. Configuration is in scope almost everywhere, it is the nearest readable thing, and reading it produces a field that passes every test you would think to write, because tests rarely rotate a credential mid-run. The obstacle is wiring rather than policy, and wiring loses. Nobody refuses it on principle. It just never becomes the most important thing in any given week. Where the bound stops working The exp argument presumes a JWT, and a large share of real credentials are not JWTs.","\u002Fapi\u002Fmedia\u002Fposts\u002Fthe-credential-your-record-names-is-not-the-one-that-made-th-75ba47cb\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Fwilliamchiu\u002Fthe-credential-your-record-names-is-not-the-one-that-made-the-call-2kn7","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},3,0,"2026-09-28T20:46:58.718Z","local"]