{
  "schema_version": "1.0",
  "id": "credential-security",
  "title": "Credential Security",
  "summary": "Issuance, hashing, scopes, attribution, spending limits, risk response, rotation, and revocation.",
  "sections": {
    "storage": "Full secrets are displayed once and never stored as recoverable plaintext.",
    "identifier": "A non-secret prefix and credential ID may be displayed and logged.",
    "management": [
      "POST /v1/account/credentials/rotate",
      "POST /v1/account/credentials/{credential_id}/revoke",
      "POST /v1/account/credentials/revoke-all",
      "POST /v1/security/freeze"
    ],
    "risk_levels": [
      "low: monitor",
      "medium: restrict expensive work and verify",
      "high: lock/revoke affected credential",
      "critical: revoke and freeze affected account"
    ],
    "limits": "Protective suspension is not a determination of wrongdoing."
  },
  "version": "2026-08-v6",
  "effective_at": "2026-08-10T00:00:00Z",
  "content_hash": "sha256:464b2f5e0a8dc6f59e1b3fd42a83ba432e3d35a5818d4f1050b0986c33207dad"
}