Without an explicit -ttl the role path could mint ~32-day session tokens.
Pass SESSION_TTL in both role and policy modes. Bump 0.1.3.
Co-Authored-By: Claude <noreply@anthropic.com>
entity-alias only works with -role; add OPENBAO_SESSION_ROLE so session tokens
can carry the user entity (and read humans/self) via the openbao-session role.
Bump 0.1.2.
Co-Authored-By: Claude <noreply@anthropic.com>
Mint the session token with -entity-alias from OPENBAO_SESSION_ENTITY so
{{identity.entity.id}} resolves and the session can read humans/self (read-only)
in addition to shared/*. Document the claude-session policy with humans/self.
Bump 0.1.1.
Co-Authored-By: Claude <noreply@anthropic.com>
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.
Co-Authored-By: Claude <noreply@anthropic.com>