Identity and authorization
Authentication is not authorization.
Server-controlled membership, ownership, entitlement, route, scope, source, and operation decisions define access.
- Tenant isolation
- Hash-only customer keys and MCP tokens
- Explicit credential revocation
- No user-metadata authorization