Type Alias SecretType

SecretType: "api-key" | "bearer-token" | "oauth-refresh"

The closed secret-type vocabulary (SECRETS_SPEC ยง2). api-key is always origin-bound; oauth-refresh is reserved (no substitution in v1).