Observed boundary
Credentials remain outside the Reframe UI and Store projection. The instrument owns lifecycle semantics; provider authentication owns credential exchange.
A host-owned capability for carrying a writer-initiated Codex sign-in through a governed MIDI2 lifecycle and a provider-authorized handoff.
Executable Risk-managed Security review pending
codex.auth.instrumentcodex/auth.login.startcodex-auth-instrumentCopilot intent
→ Reframe admission
→ MIDI2 discovery / readiness / lifecycle
→ provider-authorized browser or WebKit projection
→ redacted authenticated-state result
→ FountainStore receipt + AX-visible Copilot and Monitor projectionCredentials remain outside the Reframe UI and Store projection. The instrument owns lifecycle semantics; provider authentication owns credential exchange.
Fountain Coach may publish this sanitized contract under explicit risk management while the external security review remains pending.
Independent security review, full live acceptance, MIDI Association logo permission, and a released named build.
MIDI 2.0 Logo Licensing Program · SysEx ID policy · MIDI 2.0 product submission
Instrument Catalog · The Book of Reframe: behavior and evidence · Reframe Governance: doctrine and acceptance