Stub — expanding

API keys & rotation

The runbook is short because the mechanism is simple: two active keys per workspace, immediate revocation, prefixes that tell you what you’re holding.

WHAT EXISTS TODAY
Two active keys per workspace — mint, deploy, revoke, in that orderRevocation is immediate; in-flight requests finishrii_test_ keys never write to production links
API SHAPES
Authentication in the reference→ API · Authentication

The header, the prefixes, and the 401 you get when rotation goes wrong.