ptone
The delete, suspend and refresh paths all revoke the agent credential they are retiring (handlers_agents_core.go's delete handler, handlers_agent_lifecycle.go's suspendAgent, and the refresh endpoint). A create or launch has no equivalent: once the Hub mints a credential for a create or start dispatch, nothing revokes it if that create or launch then fails - the credential stays valid for its full lifetime regardless of whether the agent ever ran. This affects: - Synchronous create (DispatchAgentCreate) - Provision and reprovision - Create-with-gather, including the case where the broker reports required env vars still missing after gathering (handled as a non-error value today, not a dispatch error) - Finalize-env - A broker launch report that ends in a confirmed failure before the agent ever reaches running (the asynchronous create path) - A start/resume dispatch for a non-running agent - The create-failure cleanup paths that hard-delete an agent row outside the main delete handler (e.g. tearing down a still-provisioning row before recreating it) Expected behavior: every one of these failure paths should revoke the credential it minted, the same way the delete path already does, without masking the original failure if the revoke itself errors.