flexport-install-auth
Installation
SKILL.md
Flexport Credential and Token Boundary
Overview
Prefer a distinct endpoint-scoped OAuth client for each workload. Treat broad API keys as an explicit exception, and budget token acquisition because client-credential tokens last 24 hours while token requests are limited to 10 per day.
Prerequisites
- Named workload owner and exact endpoint inventory
- Flexport administrator access to API Credentials
- Secret store, redacted audit sink, and rotation procedure
Instructions
Step 1: Choose the credential type
Use OAuth client credentials for new integrations so endpoint resources can be selected. Accept an API key only after documenting why its broad access is necessary.