Agents authenticate with their own device-flow ceremony
The SDK ships startAgentCeremony, pollAgentCeremony, and refresh functions for the agent device-authorization flow (RFC 8628). Each agent identity binds its key material to its account, and rotating a key revokes the prior binding immediately.