Per-user OIDC-gated storage is strictly safer than writing API keys / credentials to local container files, so the tool description should not discourage that use case. Adds an explicit allowlist for sensitive data the user actively shares (vs. asking for them). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>