g1t/services/identity/migrations/0015_run_credentials.sql
| 1 | -- Run credentials: each sandbox run's tokens are bound to the agent run |
| 2 | -- they work for, so they can be found, and revoked, when it stops. The |
| 3 | -- rest of the binding (kind, use, git grants) is in agent_scope's `run`. |
| 4 | ALTER TABLE access_tokens ADD COLUMN run_id TEXT; |
| 5 | CREATE INDEX access_tokens_run ON access_tokens (run_id) WHERE run_id IS NOT NULL; |