{
  "schema_version": "1.0",
  "experiment_id": "AIEL-2026-0005",
  "legacy_id": "RINNAI-KANTAKUN-AUTH-401-001",
  "source_type": "backfill",
  "title": {
    "en": "Rinnai API 401 ERR_0010: recovering a Kantakun Apps Script collector",
    "ja": "Rinnai APIの401 ERR_0010を調査し、乾太くんApps Script収集を復旧した記録"
  },
  "status": "COMPLETED",
  "timestamps": {
    "created_at": "2026-08-23T08:05:04+09:00",
    "started_at": "2026-08-14T00:00:00+09:00",
    "observed_at": "2026-08-14T00:00:00+09:00",
    "completed_at": "2026-08-14T23:59:59+09:00",
    "published_at": "2026-08-22T23:38:50+00:00",
    "last_verified": "2026-08-14T00:00:00+09:00",
    "updated_at": "2026-08-23T09:59:00+09:00"
  },
  "objective": {
    "summary_en": "Diagnose an HTTP 401 / ERR_0010 failure in a Google Apps Script Kantakun collector, determine whether the failure belongs to the Rinnai authentication path or a broader Apps Script/collector failure, and document the boundary of what can and cannot be concluded from retained evidence.",
    "summary_ja": "Google Apps Scriptの乾太くん収集処理で発生したHTTP 401 / ERR_0010を切り分け、Rinnai認証経路の障害かApps Script/収集処理全体の障害かを判定し、保持証拠から確定できる範囲とできない範囲を記録する。",
    "success_criteria": [
      {
        "id": "SC-001",
        "description_en": "Localize the failure to the authentication path using retained HTTP responses, stack traces, and comparison with other scheduled Apps Script work.",
        "description_ja": "保持されたHTTP応答、スタックトレース、他のApps Script定期処理との比較から障害を認証経路へ局在化する。"
      }
    ],
    "partial_success_criteria": [],
    "failure_criteria": []
  },
  "scope": {
    "included": [
      "Rinnai API HTTP 401 response",
      "ERR_0010 invalid-token response",
      "Google Apps Script execution path through rinnaiGet_(), pollKantakun_(), and pollKantakunHourly()",
      "Bearer credential storage in Apps Script Script Properties",
      "Comparison with other scheduled collection work in the same Apps Script environment",
      "Operator report that authentication was later restored in Work mode",
      "Rinnai Kantakun RDT-93 experiment target",
      "iPhone Kantakun app traffic observation during protocol investigation"
    ],
    "excluded": [
      "Publication excludes authentication or authorization secrets, identifying information, private raw observation data, and sensitive internal system or network details that are not needed to understand or reproduce the experiment."
    ],
    "limitations": [
      "The exact corrective operation performed in the separate Work session is not available in retained evidence.",
      "Token lifetime, refresh endpoint, refresh-token semantics, and revocation conditions are not established.",
      "The public record therefore does not claim whether recovery used token replacement, refresh, re-authentication, header correction, or another change."
    ]
  },
  "environment": {
    "hardware": [
      {
        "role": "experiment_target_dryer",
        "manufacturer": "Rinnai",
        "model": "RDT-93",
        "revision": null,
        "serial_number_public": false,
        "notes": "Model confirmed on 2026-08-23 from the QR-linked product information on the unit used in the experiment; individual-unit details are excluded from the public record."
      }
    ],
    "software": [
      {
        "name": "Google Apps Script",
        "version": null,
        "role": "scheduled Kantakun data collection and troubleshooting"
      },
      {
        "name": "Apps Script Script Properties",
        "version": null,
        "role": "private bearer-token storage"
      },
      {
        "name": "Rinnai API",
        "version": null,
        "role": "Kantakun state and utility-cost data source"
      },
      {
        "name": "Kantakun iPhone app",
        "version": null,
        "role": "mobile-client traffic observation during protocol investigation"
      },
      {
        "name": "Local HTTPS inspection environment",
        "version": null,
        "role": "request-structure observation; exact inspection product not established in retained evidence"
      }
    ],
    "firmware": [],
    "network": {
      "type": "internet_cloud_api",
      "ip_addresses_redacted": true,
      "protocols_observed": [
        "HTTPS"
      ],
      "notes": "Mobile-app traffic had been inspected during protocol investigation, but credentials and installation-specific identifiers are not published."
    },
    "environmental_conditions": []
  },
  "hypotheses": [
    {
      "id": "H-001",
      "statement_en": "The observed failure is specific to the Rinnai authentication credential path rather than a general Apps Script trigger outage.",
      "statement_ja": "観測された障害はApps Scriptトリガー全体の停止ではなく、Rinnai認証情報の経路に局在している。",
      "status": "SUPPORTED",
      "created_at": null,
      "evidence_refs": [
        "O-001",
        "O-002"
      ]
    },
    {
      "id": "H-002",
      "statement_en": "A long-running unattended collector requires an explicit credential-lifecycle strategy instead of assuming one bearer token remains valid indefinitely.",
      "statement_ja": "長期無人収集では1つのBearerトークンが無期限に有効と仮定せず、明示的な認証情報ライフサイクル管理が必要である。",
      "status": "SUPPORTED",
      "created_at": null,
      "evidence_refs": [
        "O-001",
        "O-003"
      ]
    }
  ],
  "procedures": [],
  "actions": [
    {
      "id": "A-001",
      "type": "log_review",
      "description": {
        "en": "Reviewed Apps Script execution logs and the retained request path around the 401 failure.",
        "ja": "401障害時のApps Script実行ログと保持されたリクエスト経路を確認した。"
      },
      "actor": {
        "type": "HUMAN",
        "role": "operator"
      },
      "state": "EXECUTED",
      "executed_at": null,
      "result_refs": [
        "O-001",
        "O-002",
        "O-003"
      ]
    },
    {
      "id": "A-002",
      "type": "recovery",
      "description": {
        "en": "Resolved the authentication failure in a separate Work session; the exact corrective operation is not present in the retained evidence available for this record.",
        "ja": "別のWorkセッションで認証障害を復旧したが、この記録で参照できる保持証拠には具体的な修正操作が残っていない。"
      },
      "actor": {
        "type": "HUMAN",
        "role": "operator"
      },
      "state": "EXECUTED",
      "executed_at": null,
      "result_refs": [
        "O-004"
      ]
    }
  ],
  "observations": [
    {
      "id": "O-001",
      "timestamp": null,
      "description_en": "The Apps Script collector received HTTP 401 with Rinnai errorCode ERR_0010 and a message indicating that the token was invalid.",
      "description_ja": "Apps Script収集処理はRinnai APIからHTTP 401、errorCode ERR_0010、およびトークンが無効である旨のメッセージを受け取った。",
      "observation_type": "api_response",
      "source_type": "execution_log",
      "artifact_refs": [
        "AR-001"
      ],
      "quality": "VALID"
    },
    {
      "id": "O-002",
      "timestamp": null,
      "description_en": "Other scheduled collection work visible in the same Apps Script execution history completed successfully while the Rinnai request failed.",
      "description_ja": "同じApps Script実行履歴では、Rinnaiリクエストが失敗している間も他の定期収集処理は正常終了していた。",
      "observation_type": "execution_history",
      "source_type": "execution_log",
      "artifact_refs": [
        "AR-001"
      ],
      "quality": "VALID"
    },
    {
      "id": "O-003",
      "timestamp": null,
      "description_en": "The retained implementation read RINNAI_TOKEN from Apps Script Script Properties and used it as a bearer credential; its HTTP 401 path raised an error immediately and did not contain a verified token-refresh retry path.",
      "description_ja": "保持実装はApps Script Script PropertiesのRINNAI_TOKENをBearer認証情報として使用し、HTTP 401時は即時エラー終了しており、検証済みのトークン更新・再試行経路は含んでいなかった。",
      "observation_type": "source_review",
      "source_type": "retained_code_summary",
      "artifact_refs": [
        "AR-001"
      ],
      "quality": "VALID"
    },
    {
      "id": "O-004",
      "timestamp": null,
      "description_en": "The operator reports that the authentication error was subsequently resolved in Work mode, but the exact corrective operation is not retained in the publication evidence.",
      "description_ja": "操作者はその後Workモードで認証エラーを解消したと報告しているが、具体的な修正操作は公開証拠に残っていない。",
      "observation_type": "human_report",
      "source_type": "human_report",
      "artifact_refs": [
        "AR-001"
      ],
      "quality": "VALID"
    }
  ],
  "claims": [
    {
      "id": "C-001",
      "statement_en": "The observed incident was an authentication failure in the Rinnai API path rather than a general Google Apps Script outage.",
      "statement_ja": "観測された障害はGoogle Apps Script全体の停止ではなく、Rinnai API認証経路の障害だった。",
      "evidence_state": "VERIFIED",
      "confidence": "HIGH",
      "evidence_refs": [
        "O-001",
        "O-002"
      ],
      "source_refs": []
    },
    {
      "id": "C-002",
      "statement_en": "HTTP 401 / ERR_0010 localizes the failure before Kantakun payload processing, spreadsheet aggregation, and downstream state logic.",
      "statement_ja": "HTTP 401 / ERR_0010により、障害は乾太くんデータ処理、スプレッドシート集計、後段の状態ロジックより前段に局在すると判断できる。",
      "evidence_state": "INFERRED",
      "confidence": "HIGH",
      "evidence_refs": [
        "O-001",
        "O-003"
      ],
      "source_refs": []
    },
    {
      "id": "C-003",
      "statement_en": "The retained collector did not demonstrate a verified automatic token-renewal and bounded-retry path when HTTP 401 occurred.",
      "statement_ja": "保持された収集処理では、HTTP 401時に検証済みの自動トークン更新と限定再試行の経路を確認できなかった。",
      "evidence_state": "OBSERVED",
      "confidence": "HIGH",
      "evidence_refs": [
        "O-003"
      ],
      "source_refs": []
    },
    {
      "id": "C-004",
      "statement_en": "The exact operation that restored authentication cannot be established from the retained public evidence.",
      "statement_ja": "認証を復旧した具体的操作は、保持された公開証拠からは確定できない。",
      "evidence_state": "OBSERVED",
      "confidence": "HIGH",
      "evidence_refs": [
        "O-004"
      ],
      "source_refs": []
    },
    {
      "id": "C-005",
      "statement_en": "Long-running unattended API collection should explicitly manage credential lifecycle rather than assume indefinite validity of a captured bearer token.",
      "statement_ja": "長期無人API収集では取得済みBearerトークンの無期限有効性を前提とせず、認証情報ライフサイクルを明示的に管理すべきである。",
      "evidence_state": "INFERRED",
      "confidence": "HIGH",
      "evidence_refs": [
        "O-001",
        "O-003"
      ],
      "source_refs": []
    }
  ],
  "analysis": [
    {
      "id": "AN-001",
      "method": "fault_localization",
      "summary_en": "The combination of an explicit authentication response, a failing authentication helper, and successful unrelated scheduled work isolates the incident to the Rinnai credential path without asserting an unobserved token-expiry or refresh mechanism.",
      "summary_ja": "明示的な認証エラー応答、認証ヘルパーでの失敗、無関係な定期処理の成功を組み合わせ、未観測のトークン期限切れやrefresh機構を断定せずRinnai認証情報経路へ障害を局在化した。",
      "evidence_refs": [
        "O-001",
        "O-002",
        "O-003",
        "O-004"
      ]
    }
  ],
  "results": {
    "summary_en": "The incident was localized to Rinnai authentication, and the retained implementation lacked a verified automatic credential-renewal path. Authentication was later restored, but the exact recovery operation remains unknown in the retained public evidence.",
    "summary_ja": "障害はRinnai認証経路へ局在化でき、保持実装には検証済みの自動認証情報更新経路がなかった。認証自体はその後復旧したが、具体的な復旧操作は保持公開証拠では未確定である。",
    "success_level": "COMPLETED_WITH_LIMITATIONS",
    "established_claim_refs": [
      "C-001",
      "C-002",
      "C-003",
      "C-004",
      "C-005"
    ],
    "unresolved_claim_refs": [],
    "disproven_claim_refs": []
  },
  "conclusion": {
    "en": "The retained evidence supports treating HTTP 401 / ERR_0010 as an authentication-lifecycle event in the Rinnai path. It does not support claiming a specific refresh endpoint, token lifetime, or exact recovery mechanism.",
    "ja": "保持証拠から、HTTP 401 / ERR_0010はRinnai経路の認証ライフサイクル事象として扱うべきと判断できる。一方、特定のrefresh endpoint、トークン寿命、具体的な復旧方式までは確定できない。",
    "evidence_basis_refs": [
      "C-001",
      "C-002",
      "C-003",
      "C-004",
      "C-005"
    ],
    "remaining_uncertainties": [
      "Exact successful recovery operation",
      "Token lifetime and revocation conditions",
      "Verified refresh endpoint and refresh-token semantics"
    ],
    "recommended_next_actions": [
      "Verify the actual credential-renewal mechanism before implementing automatic refresh and bounded retry."
    ]
  },
  "data_artifacts": [
    {
      "id": "AR-001",
      "type": "legacy_public_record",
      "path": "experiments/RINNAI-KANTAKUN-AUTH-401-001/experiment.json",
      "public": false,
      "notes": "Legacy experiment record and bilingual public article are the retained source records. Secrets and household telemetry are excluded."
    }
  ],
  "sources": [],
  "provenance": {
    "generated_by": "GPT-5.6 Sol assisted reconstruction from retained experiment/publication records",
    "ai_systems": [
      "GPT-5.6 Sol"
    ],
    "human_roles": [
      "operator",
      "publication approver"
    ],
    "automation_systems": [
      "Google Apps Script"
    ],
    "human_editing": "Human performed the protocol investigation and recovery work and explicitly authorised publication; exact recovery details unavailable to the retained record are not reconstructed."
  },
  "publication": {
    "public": true,
    "languages": {
      "en": {
        "published": true,
        "url": "https://ai-experiment-log.pages.dev/en/experiments/rinnai-kantakun-auth-401/",
        "canonical": false
      },
      "ja": {
        "published": true,
        "url": "https://ai-experiment-log.pages.dev/ja/experiments/rinnai-kantakun-auth-401/",
        "canonical": false
      }
    },
    "machine_readable_url": "https://ai-experiment-log.pages.dev/data/experiments/AIEL-2026-0005/experiment.json"
  },
  "relationships": [
    {
      "type": "BACKFILLED_FROM",
      "target": "RINNAI-KANTAKUN-AUTH-401-001"
    },
    {
      "type": "RELATED_TO",
      "target": "AIEL-2026-0008",
      "note": "AIEL-2026-0008 uses the same Rinnai RDT-93 collection stack for post-stop utility-cost timing and reconciliation. It is a separate follow-up and does not alter the authentication conclusions of AIEL-2026-0005."
    }
  ],
  "revisions": [
    {
      "revision": 1,
      "timestamp": "2026-08-23T08:05:04+09:00",
      "type": "INITIAL_BACKFILL",
      "summary": "Formal AIEL record created from the retained Rinnai/Kantakun authentication investigation record."
    },
    {
      "revision": 2,
      "timestamp": "2026-08-23T08:20:00+09:00",
      "type": "SCHEMA_NORMALIZATION",
      "summary": "Normalized the retrospective record to AIEL schema and Charter lifecycle/evidence states after CI validation exposed the provisional record format."
    },
    {
      "revision": 3,
      "timestamp": "2026-08-23T08:31:55+09:00",
      "type": "PUBLICATION_REVIEW",
      "summary": "Integrated pre-publication content review passed for the formal EN/JA pages, in-place migration handling, privacy boundary, and no-BOM reproduction exception."
    },
    {
      "revision": 4,
      "timestamp": "2026-08-22T23:38:50+00:00",
      "type": "METADATA_UPDATE",
      "summary": "Gitleaks 8.24.3 full-history scan completed without detected leaks in GitHub Actions workflow run 32605769230 immediately before publication finalization; secret_scan_performed set to true."
    },
    {
      "revision": 5,
      "timestamp": "2026-08-22T23:38:50+00:00",
      "type": "PUBLICATION_UPDATE",
      "summary": "After human-approved merge to main, GitHub Actions workflow run 32605769230 directly observed the English page, Japanese page, and machine-readable JSON on Cloudflare Pages production. The JSON returned HTTP 200, matched experiment_id=AIEL-2026-0005, and matched the repository public copy byte-for-byte. Publication metadata was finalized from that observed state."
    },
    {
      "revision": 6,
      "timestamp": "2026-08-23T09:59:00+09:00",
      "type": "PUBLICATION_MAINTENANCE",
      "summary": "Reader-facing publication maintenance added the RDT-93 model confirmed from the experiment-used unit and the iPhone Kantakun app / HTTPS inspection context without changing the authentication findings or last_verified date."
    },
    {
      "revision": 7,
      "timestamp": "2026-09-06",
      "type": "METADATA_UPDATE",
      "summary": "Added a reciprocal RELATED_TO relationship to AIEL-2026-0008. The follow-up concerns delayed utility-cost reconciliation on the same collection stack and does not revise this experiment's authentication conclusion."
    }
  ],
  "security": {
    "contains_sensitive_data": true,
    "redactions_applied": true,
    "secret_scan_performed": true,
    "publication_reviewed": true
  }
}
