requestContext key: the caller's OPAQUE isolation scope (a multi-tenant
host mints its tenant id here). breakwater never parses the value — it
segments the connector SDK's idempotency and rate-limit keys and feeds the
tenantIsolation evaluator. Minted by the trusted runtime on every leg,
mirroring WORKFLOW_SCOPE_CONTEXT_KEY — trust boundary 6 applies: never
populate it from client input, model output, or tool results.
requestContext key: the caller's OPAQUE isolation scope (a multi-tenant host mints its tenant id here). breakwater never parses the value — it segments the connector SDK's idempotency and rate-limit keys and feeds the tenantIsolation evaluator. Minted by the trusted runtime on every leg, mirroring WORKFLOW_SCOPE_CONTEXT_KEY — trust boundary 6 applies: never populate it from client input, model output, or tool results.