[BUG][INFRA][PRJ-431] INT-S004 OpenRouter API KEY expired — 401 — Temporary rotate / Permanent fix via Composio.dev POC #1

Open
opened 2026-07-27 18:42:47 +00:00 by yonks · 0 comments
Owner

♾️ WeOwnNet 🌐 — ISSUE: WeOwnChat INT-S004 401 Auth Failure

🔄 REVISED: 12:39 MDT W31 D1 — Composio.dev strategic context added


TITLE

[BUG][INFRA][PRJ-431] INT-S004 OpenRouter API KEY expired — 401 — Temporary rotate / Permanent fix via Composio.dev POC

REPORTER

👤 USER:@LAW (INT-S004)

TIMELINE

  • Detected: W31 D1 (Mon 27 Jul 2026) ~12:37 MDT
  • Temp Resolved: W31 D1 ~12:37 MDT — key rotated by @GTM:ADMIN
  • Permanent Fix: PENDING — Composio.dev POC (PRJ-431, W31 Focus)

ENVIRONMENT

Field Value
Instance INT-S004 (WeOwnChat)
Service OpenRouter.ai
Error Code 401 User not found
Affected User @LAW
Affected Model ALL (shared API key)
Impact Window Minutes — @GTM was present to rotate immediately

ROOT CAUSE

OpenRouter.ai API key for INT-S004 had expired on its 7-day lifecycle. Rotating keys manually every 7 days is a recurring operational burden and introduces risk of:

  1. User-facing downtime when @GTM is unavailable
  2. Human error in key naming, expiry dates, or copy-paste
  3. No audit trail for key lifecycle management

TEMPORARY RESOLUTION (Applied)

@GTM:ADMIN manually rotated the API key:

Detail Value
Action Manual key rotation
Performed By @GTM:ADMIN
New Key Name OPENROUTER_API_ANYTHINGLLM_INT-S004_7D_EXP_2026-08-03T1230MDT
Expiry 2026-08-03 12:30 MDT
Status 🟢 OPERATIONAL — TEMPORARY FIX
Next Expiry 2026-08-03 — will fail again without Composio.dev integration

🏆 PERMANENT FIX — Composio.dev POC (PRJ-431)

This incident is the catalyst for a permanent architectural fix.

Detail Value
Solution Composio.dev — API key management, automated rotation, auth orchestration
Project PRJ-431 — #FedArch W31 Focus
Status 🟡 FEATURED POC — In-scope for W31
Goal Eliminate manual key rotation across ALL instances (INT-S004, INT-P05, INT-P08, INT-M02, INT-B001)
Target By end of W31 — Composio.dev integrated as the centralized API key management layer

What Composio.dev Solves

Problem Current State Composio.dev Target State
Expired keys Manual rotation every 7 days Auto-rotation with expiry alerts
401 errors User-facing downtime until @GTM intervenes Zero-downtime key refresh
Key sprawl Multiple keys across instances, manually tracked Single pane of glass for all API keys
Audit trail No log of key lifecycle Full audit history per key
Rotational burden @GTM:ADMIN must drop everything to rotate Fully automated — exception-only intervention

RECOMMENDATIONS — UPDATED

# Action Owner Priority Status
1 Composio.dev POC — scope, test, deploy as API key management layer @GTM + DRPbot 🔴 P0 NEW — PRJ-431
2 Set calendar reminder 2026-08-02 — manual backup rotation if Composio not live @GTM:ADMIN 🟠 P1 DONE
3 Document manual rotation procedure in _OPS_/ for redundancy AI:@GTM 🟢 P2
4 Evaluate auto-rotation script as fallback if Composio POC is delayed DRPbot 🟢 P3

RELATED ARTIFACTS

Artifact URL / REF
Composio.dev https://composio.dev
PRJ-431 _S004_PROJECTS_/PRJ-431.md (pending)
This Issue WeOwnChat/s004/issues
DRPbot Prompt git.weown.tools/DRPbot/s004

STATUS

Layer Status
🟢 Temporary Fix Key rotated — INT-S004 operational
🟡 Permanent Fix 🏗️ PRJ-431 — Composio.dev POC in-scope for W31
# ♾️ WeOwnNet 🌐 — ISSUE: WeOwnChat INT-S004 401 Auth Failure ## 🔄 REVISED: 12:39 MDT W31 D1 — Composio.dev strategic context added --- ### TITLE [BUG][INFRA][PRJ-431] INT-S004 OpenRouter API KEY expired — 401 — Temporary rotate / Permanent fix via Composio.dev POC ### REPORTER 👤 USER:@LAW (INT-S004) ### TIMELINE - **Detected:** W31 D1 (Mon 27 Jul 2026) ~12:37 MDT - **Temp Resolved:** W31 D1 ~12:37 MDT — key rotated by @GTM:ADMIN - **Permanent Fix:** ⬜ PENDING — Composio.dev POC (PRJ-431, W31 Focus) ### ENVIRONMENT | Field | Value | |:------|:-------| | **Instance** | INT-S004 (WeOwnChat) | | **Service** | OpenRouter.ai | | **Error Code** | `401 User not found` | | **Affected User** | @LAW | | **Affected Model** | ALL (shared API key) | | **Impact Window** | Minutes — @GTM was present to rotate immediately | ### ROOT CAUSE OpenRouter.ai API key for INT-S004 had **expired** on its 7-day lifecycle. Rotating keys manually every 7 days is a recurring operational burden and introduces risk of: 1. **User-facing downtime** when @GTM is unavailable 2. **Human error** in key naming, expiry dates, or copy-paste 3. **No audit trail** for key lifecycle management ### TEMPORARY RESOLUTION (Applied) @GTM:ADMIN manually rotated the API key: | Detail | Value | |:-------|:-------| | **Action** | Manual key rotation | | **Performed By** | @GTM:ADMIN | | **New Key Name** | `OPENROUTER_API_ANYTHINGLLM_INT-S004_7D_EXP_2026-08-03T1230MDT` | | **Expiry** | 2026-08-03 12:30 MDT | | **Status** | 🟢 **OPERATIONAL — TEMPORARY FIX** | | **Next Expiry** | 2026-08-03 — will fail again without Composio.dev integration | ### 🏆 PERMANENT FIX — Composio.dev POC (PRJ-431) > **This incident is the catalyst for a permanent architectural fix.** | Detail | Value | |:-------|:-------| | **Solution** | **Composio.dev** — API key management, automated rotation, auth orchestration | | **Project** | **PRJ-431** — #FedArch W31 Focus | | **Status** | 🟡 **FEATURED POC — In-scope for W31** | | **Goal** | Eliminate manual key rotation across ALL instances (INT-S004, INT-P05, INT-P08, INT-M02, INT-B001) | | **Target** | By end of W31 — Composio.dev integrated as the centralized API key management layer | ### What Composio.dev Solves | Problem | Current State | Composio.dev Target State | |:--------|:--------------|:--------------------------| | **Expired keys** | Manual rotation every 7 days | Auto-rotation with expiry alerts | | **401 errors** | User-facing downtime until @GTM intervenes | Zero-downtime key refresh | | **Key sprawl** | Multiple keys across instances, manually tracked | Single pane of glass for all API keys | | **Audit trail** | No log of key lifecycle | Full audit history per key | | **Rotational burden** | @GTM:ADMIN must drop everything to rotate | Fully automated — exception-only intervention | ### RECOMMENDATIONS — UPDATED | # | Action | Owner | Priority | Status | |:-:|:--------|:-----:|:--------:|:------:| | 1 | **Composio.dev POC** — scope, test, deploy as API key management layer | @GTM + DRPbot | 🔴 P0 | ⬜ NEW — PRJ-431 | | 2 | **Set calendar reminder 2026-08-02** — manual backup rotation if Composio not live | @GTM:ADMIN | 🟠 P1 | ✅ DONE | | 3 | **Document manual rotation procedure** in `_OPS_/` for redundancy | AI:@GTM | 🟢 P2 | ⬜ | | 4 | **Evaluate auto-rotation script** as fallback if Composio POC is delayed | DRPbot | 🟢 P3 | ⬜ | ### RELATED ARTIFACTS | Artifact | URL / REF | |:---------|:-----------| | **Composio.dev** | `https://composio.dev` | | **PRJ-431** | `_S004_PROJECTS_/PRJ-431.md` (pending) | | **This Issue** | WeOwnChat/s004/issues | | **DRPbot Prompt** | `git.weown.tools/DRPbot/s004` | ### STATUS | Layer | Status | |:------|:------:| | 🟢 **Temporary Fix** | ✅ Key rotated — INT-S004 operational | | 🟡 **Permanent Fix** | 🏗️ PRJ-431 — Composio.dev POC in-scope for W31 |
yonks added the
Priority
Critical
1
label 2026-07-27 18:48:01 +00:00
yonks added the 📅 2026-W31🔧 infrastructure🧊 INT-S004🎯 PRJ-431 labels 2026-07-27 19:41:51 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: WeOwnChat/s004#1