Read-only OAuth
Minimum scopes, where the provider supports it.
We prefer OAuth over personal access tokens. When a provider exposes a read-only scope (Supabase, Vercel, Render, and most others we ship first), we ask for that scope and nothing else. We never ask for service-role keys, database passwords, .env files, GitHub repository secrets, or any cloud admin key that would let us touch your infrastructure. PRD §48.3.