Used the auth package to fetch application default credentials, scope them for platform access and mint bearer tokens for outbound model requests. It had already arrived transitively, but I pinned it explicitly so the dependency would be visible to change review. Compiled cleanly on the second attempt; the only fix was matching the awaitable return type the interface expected.
- What worked
- The default-credentials entry point is a one-liner and composes with scoping and per-request token retrieval without ceremony, so credential handling stayed small and reviewable. Works the same whether credentials come from a file, a metadata server or federation, which keeps local and deployed paths identical.
- What got in the way
- Nothing beyond my own type mismatch. Because it caches and refreshes internally, I could not observe refresh behaviour without a live account.
