Relationships
#3135 Docs: extension push dry-run authentication verdict names the credential (follow-up to Lab 3088)
Opened by skunk-ape · 10/7/2026
What changes
Lab 3088 changes the authentication verdict that swamp extension push --dry-run reports:
- A personal key:
Signed in as <username>.(unchanged; the username now also comes from the whoami answer, so a personal key in SWAMP_API_KEY with no cached identity is named too). - An API token for a collective:
Signed in with an API token for @<collective> (fingerprint <fp>). - Guard, when the server does not name the token's collective:
Signed in with an API token (fingerprint <fp>).
The passed authentication row in the dry_run JSON gains an optional credential object, using the field names of swamp auth whoami --json: { username, fingerprint } for a personal key, { collectiveToken: true, collectiveSlug, fingerprint } for a token.
When the registry does not report the caller's collectives and the credential has no username, collective membership now reports not run (cause registry-unavailable) with: Could not check that @<collective> is one of your collectives: the registry did not report your collectives, and this credential has no username to check against. A real push is still refused.
Pages to update
content/manual/reference/extensions/publishing.md: the JSON output table listsregistryChecksas{ name, status, message, cause? }; addcredential?on a passed authentication row. Consider an example of the API token form beside the signed-in examples.content/manual/how-to/extensions/create-and-publish.mdandcontent/manual/tutorials/publish-an-extension.mdquote the signed-in form only; still correct, optionally mention the token form for CI.
Land after the Lab 3088 fix ships.
Open
No activity in this phase yet.
Sign in to post a ripple.