Credentials and Authentication
Different callers receive different authority.
Human users authenticate with an httpOnly dashboard session. Agents use a pm_live wallet credential that is shown once, stored as a hash and scoped to one wallet. Paymod Code device authorization is separate and must not be treated as a financial credential.
Wallet credential rotation is supported by issuing another credential. A dedicated scoped-session credential model is deferred. Internal executor and relayer secrets stay server-side.