AUTH4D-3 D1 persistence boundary
This ticket adds relational storage primitives and no public HTTP routes. The authentication and management endpoints listed in other fragments continue to follow their owning feature contracts.
- Tenant-owned records carry
tenant_id; relationships use composite tenant/entity foreign keys. - Provider subjects are unique within a tenant and provider, so a subject used by one customer does not reserve or identify it in another customer realm.
- D1 session rows are indexes only. Durable Objects remain authoritative for session validity, one-time values, refresh rotation, and coordinated rate limits.
- Authentication and authorization reads use D1 sessions anchored with
first-primary. Related domain writes use D1 batch execution so failed batches do not leave partial records.
See D1 schema operations (repository file docs/operations/d1-schema.md) for migration, fixture, backup, and local
verification procedures.
Source: docs/api-spec/auth4d-3.md