Authentication
Keys and sessions must be scoped.
API keys
Scopes
Reveal once
Revocation
Tenant ID
Audit
How integrations should authenticate, send idempotent requests, subscribe to events, and recover from failures.
Keys and sessions must be scoped.
Requests that affect business state need validation.
Event delivery should be verifiable and recoverable.