GET /api/secrets/policy
Machine-readable policy for authenticated targets and credentials agents must not send.
Secret storage policy
The buyer path is accountless, so secret storage would need ownership checks, encryption lifecycle, rotation, and abuse controls before activation.
Safe alternatives
Use target-owned webhook URLs, short-lived per-request headers, or a dedicated allowlisted deployment when authenticated target calls need stronger controls.
Machine-readable policy for authenticated targets and credentials agents must not send.
Validate target safety before paying, without storing secrets or executing a target.