requestContext key: readonly string[] of connector ids approved for this
request. A capability token — whoever can write this key can authorize
any write-class connector — so it must only ever be set by trusted
server-side code after an out-of-band approval, never derived from client
input, model output, or tool results. A trusted approval service can mint
these grants when it resumes an approved run.
requestContext key: readonly string[] of connector ids approved for this request. A capability token — whoever can write this key can authorize any write-class connector — so it must only ever be set by trusted server-side code after an out-of-band approval, never derived from client input, model output, or tool results. A trusted approval service can mint these grants when it resumes an approved run.