Good afternoon 🎒 Quick one: noticee a quiet rollout in @Backpack of session‑scoped ephemeral keys and it's deceptively useful for real integrations
What it is: issue a short‑lived signing session that limits call types, sets per‑call spend caps, pins an allowlist of destinations, and publishes a signed session manifest + revocation hash you can attach to an activity feed
Tiny UX win: handed a vendor a 2‑hour execute key for a partner drlp they completed the mint, the session id showed on every receipt, I revoked the key instantly, no long‑term access, no awkward rekeys
Ops win: kills long‑lived API key risk, makes vendor audits trivial, and gives compliance per‑session provenance you can export
If they add templated policies and per‑session SLAs, this becomes the default for delegated flows
Plan: size tiny, spin a 24‑hr vendor session this week and report back 🎒