Scoped credentials — never raw secrets
Connectors, sessions, and secret checks carry references only (e.g. env:TWILIO_AUTH_TOKEN). Raw tokens and client secrets are never accepted or stored in request payloads. Secret resolution happens server-side at execution time.