Connect Apps

One connect action per application. Open-Connect holds the capability reference; agents never see provider secrets.

Credential boundary
Agents never see the secret
Provider tokens stay server-side. An agent presents an Open-Connect scoped key; the gateway validates permission and calls the provider on its behalf.