Skip to main content
← Back to list
01Issue
FeatureOpenSwamp CLIPublic
AssigneesNone

Relationships

#3135 Docs: extension push dry-run authentication verdict names the credential (follow-up to Lab 3088)

Opened by skunk-ape · 10/7/2026

What changes

Lab 3088 changes the authentication verdict that swamp extension push --dry-run reports:

  • A personal key: Signed in as <username>. (unchanged; the username now also comes from the whoami answer, so a personal key in SWAMP_API_KEY with no cached identity is named too).
  • An API token for a collective: Signed in with an API token for @<collective> (fingerprint <fp>).
  • Guard, when the server does not name the token's collective: Signed in with an API token (fingerprint <fp>).

The passed authentication row in the dry_run JSON gains an optional credential object, using the field names of swamp auth whoami --json: { username, fingerprint } for a personal key, { collectiveToken: true, collectiveSlug, fingerprint } for a token.

When the registry does not report the caller's collectives and the credential has no username, collective membership now reports not run (cause registry-unavailable) with: Could not check that @<collective> is one of your collectives: the registry did not report your collectives, and this credential has no username to check against. A real push is still refused.

Pages to update

  • content/manual/reference/extensions/publishing.md: the JSON output table lists registryChecks as { name, status, message, cause? }; add credential? on a passed authentication row. Consider an example of the API token form beside the signed-in examples.
  • content/manual/how-to/extensions/create-and-publish.md and content/manual/tutorials/publish-an-extension.md quote the signed-in form only; still correct, optionally mention the token form for CI.

Land after the Lab 3088 fix ships.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

10/7/2026, 2:53:58 PM

No activity in this phase yet.

03Sludge Pulse

Sign in to post a ripple.