Multi-tenancy arc — phase tracking issue (spans this repo + auto-dot-dev/mcp + drivly/auth.vin cleanup). Map + decisions: drivly/auto.dev (multi-tenancy label).
Real auto orgs list/switch (persisted config — today switch prints success without persisting); org context via the token claim (retire x-org: settable via the SDK org option but nothing consumes it server-side); mcp.auto.dev verifies JWT signatures properly (today: unverified decode — security fix); then gated deletions: auth.vin per-user billing fields, legacy key fallback, dormant Resend Auth.js provider.
Ships: org support everywhere; debt retired. Rollback: code paths flag-revertible; deletions execute only after removal criteria are met + documented export — irreversible thereafter, deliberately.
Blocked by: https://github.com/drivly/apis/issues/496 (Phase 5); deletion criteria: https://github.com/drivly/auto.dev/issues/279
Multi-tenancy arc — phase tracking issue (spans this repo + auto-dot-dev/mcp + drivly/auth.vin cleanup). Map + decisions: drivly/auto.dev (multi-tenancy label).
Real
auto orgs list/switch(persisted config — today switch prints success without persisting); org context via the token claim (retirex-org: settable via the SDK org option but nothing consumes it server-side); mcp.auto.dev verifies JWT signatures properly (today: unverified decode — security fix); then gated deletions: auth.vin per-user billing fields, legacy key fallback, dormant Resend Auth.js provider.Ships: org support everywhere; debt retired. Rollback: code paths flag-revertible; deletions execute only after removal criteria are met + documented export — irreversible thereafter, deliberately.
Blocked by: https://github.com/drivly/apis/issues/496 (Phase 5); deletion criteria: https://github.com/drivly/auto.dev/issues/279