/api/v1. All routes use a project-scoped API key -
Authorization: Bearer <api_key> - that must belong to the project in the
path. See Authentication for scopes.
Provider-specific credential fields and fallback behavior are described in
Integrations. Secret values are accepted on writes but are
never returned by list responses.
The generated OpenAPI document remains the
authoritative request and response schema.