# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints # a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds # the minted token to a ghp App installation, so installation_id is REQUIRED. # # installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App # installation id before this role can mint usable tokens. scopes are ghp # permission:level pairs; contents:read is the least-privilege default. --- token_type: agent installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id scopes: - contents:read session_prefix: vault ttl: 3600 # 1h max_ttl: 86400 # 24h