# 011 — Reddit's app-creation gate closes 021's post path (wake 085, 2026-08-17)

**What happened.** `outbox/other-005-reddit-account` was **approved**
(`inbox/other-005-reddit-account.result.json`, 18:43 EDT 2026-08-17).
Julio created **u/brim-agent** and the profile discloses the AI. Then the
API app that decision `021` C2 requires — the sanctioned Data-API + OAuth
path for posting *as* brim-agent — **could not be registered**, by either
mechanism, on either account. Two trusted-channel notes carry the record
(`inbox/julio-20260817-190419-reddit-app-path-blocked.md`,
`inbox/julio-20260817-191851-reddit-app-block-addendum.md`); this page is
the dated finding, with the sources I could and could not reach myself.

**The measurements (Julio's, by hand, 2026-08-17 evening EDT):**

| Attempt | Account | App type | Result |
|---|---|---|---|
| 1 | u/brim-agent (new, disclosed) | script | CAPTCHA passes, "Create App" does nothing — no error, no app. |
| 2 | Julio's own account (years old) | web app (would have let brim-agent post via a scoped refresh token) | Same. One signal: a **field-level validation error fired first** ("oauth2 client names cannot include 'reddit'") — the request reaches app-creation logic *before* the policy line refuses it. A gate, not a broken form. |

So the weaker reading ("new accounts can't register apps") is wrong; the
stronger one holds: **no new app can be registered through the self-serve
`/prefs/apps` flow at all**, regardless of account age — only through
Reddit's manual approval. And a *script* app can only act as the account
that created it, so an app on Julio's account could never post as
u/brim-agent anyway; the web-app route was the only bridge and it is shut.

**Sources, read at 22:35 EDT 2026-08-17 under the honest UA:**

- **Primary — `support.reddithelp.com/hc/en-us/articles/42728983564564`
  (Responsible Builder Policy):** **403** to me, Cloudflare "Just a
  moment…" interstitial. Not retried, not worked around (a refusal is a
  refusal, 021 C2/C6). Cited on Julio's read, not mine.
- **Secondary — `fetchlayer.dev/blog/reddit-api-closed-2026`** (200,
  53 kB, dated 2026-05-30): timeline — mid-2025 OAuth tokens limited to
  one per account; **2025-11-11 self-service API access closed
  ("Responsible Builder Policy"; announced by admin u/redtaboo, the post
  "sits at 0 points with 294 comments")**; **2026-05-30 unauthenticated
  `.json` endpoints return 403**. Quotes user reports matching Julio's
  observation exactly (May 2026: "The CAPTCHA completes, but the app is not
  created and the page only shows: 'In order to create an application or use
  our API you can read our full policies here.'"). **Bias flag: FetchLayer
  sells a Reddit-scraping product; its "what still works" is a sales page.
  I take its dates and quotes, not its advice.**
- **My own instrument agrees on the `.json` half:** README row 38 recorded
  `.json` → 403 back at 072, and RSS still served 200 to the identified UA
  this wake (`data/reddit-3Drequests-new-2026-08-17d.rss`).

**Why 009/021 missed it.** 009 read the *terms* (User Agreement, Rules,
Developer Terms, Data API Terms, robots.txt) — none of which bar a
disclosed bot — and inferred an open door from the absence of a rule. The
gate is not a rule; it is an *approval queue* in the app-registration UI,
post-dating every document 009 quoted. Terms-reading cannot see a queue.
Lesson for the instrument: **before proposing an account whose use needs
an API app, probe the registration surface, not just the policy text.**

**What it changes.**

- **021 stands; C2's post path is CLOSED, not pending.** Reading: one
  identified RSS fetch per wake, unchanged (RSS needs no app). Delivering:
  any rule-3 prior-art comment is **drafted to `outbox/` as an `other`
  proposal for Julio to post or not, by hand, from u/brim-agent** — same
  shape as `019`'s GitHub rule, minus my own token. First act still gated
  on a thread with prior art in hand.
- **No scraping around the wall.** Not `.json`, not a browser UA, not a
  third-party proxy. C6: a wall is a wall.
- **NOT an `018` falsifier.** That falsifier counts *research-originated
  denials* ("not worth it"). This was approved on its merits and blocked by
  an external policy. Counter stays **0 of 3**.
- **The account and the harness wiring stay.** If Reddit's queue ever
  approves an app (unlikely for a personal, non-commercial, AI-operated
  use — the secondary source's own summary is "usually denied"), the
  creds land in the wake env as `REDDIT_*` and C2 resumes in one step.
  Nobody files an application from my side; that is Julio's call and he
  has not made it.

**Status of the request-board class after this.** 010 found the class has
one live member; 011 finds I cannot post there under my own name. So the
whole demand-side channel is now: read r/3Drequests once a wake, deliver
by proposal. Which is what the fabrication arm already was.
