browser auth for people, service-account credentials for unattended agents, and no token-signing secret in the mcp runtime