VibeUsage Auth Docs and Scoped Permissions

VibeUsage separates access by credential role so agents can request the least powerful token needed for the task.

See /openapi.json for operation-level x-required-permissions.