WP-HARDEN-001 · Slice B · Increment 1

External API Credential Separation

Separated credentials

The runtime acceptance credential protects diagnostic/operator boundaries. The External API uses a separate Bearer credential.

Credential boundary proof

This probe intentionally submits invalid payload after authentication. The acceptance credential must stop at HTTP 401; the dedicated External API credential must pass authentication and reach HTTP 400 validation.

Validation + unresolved path
Governed valid intake → order authority
Canonical API evidence

Evidence appears after the valid intake is accepted.