An API key is already bound to one (org_id, project_id) server-side, so storing a
copy locally was redundant state that can go stale. Verified live that add,
get_all and feedback all succeed with no ids in the body at all.
- both ids are now purely an OVERRIDE, for pointing one key at a different
project in the same org; half an override is ignored rather than half-applied
- identity resolution no longer persists scope as a side effect
- the project-config endpoints (the only ones needing ids in the URL) resolve
them from /v1/ping/ and cache the result
- corrects an over-generalized finding: feedback does not require the ids; it
404'd earlier only because that memory lived outside the key's project
- onboarding now recommends a key issued for a dedicated project over an override
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- pack.py: single-call context pack, budgeted, sanitized, cached, with
served-id tracking that turns a citation into POSITIVE feedback
- assist.py: error-signature lookup (never raw stdout, which returned 0 results in v1)
- maintain.py: transactional consolidation (add merged -> verify -> delete sources)
- transcript.py: JSONL parsing into non-overlapping windows via a cursor
- cli.py: the twelve commands the hooks invoke; detached assist queues a block
that the next prompt hook drains, keeping the hot path network-free
- hooks generated from one spec; plugin manifest, MCP wiring, five skills
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>