SIGN IN SIGN UP

feat(providers)!: add credential-scoped target discovery (#67)

## Summary

Add credential-scoped provider sessions so one Cloudflare or Vercel
credential can discover
multiple account/zone targets without making DNS operations guess across
accounts.

## Usage

```ts
const session = await Cloudflare.Auth.restore({ authorization, credential });
const resolution = await session.resolveTarget(DomainName.parse("mail.example.com"));

if (resolution._tag === "Resolved") {
  const dns = await session.forTarget(resolution.target);
  await dns.createRecord(resolution.target.zoneName, record);
}
```

## Flow

```text
persisted provider authorization + credential
  -> provider-specific restore
  -> listTargets / resolveTarget
  -> Resolved | SelectionRequired | NotFound
  -> forTarget(selected target)
  -> focused DNS record operations
```

## Changes

- Add Effect and Promise provider-session seams with explicit target
resolution outcomes.
- Add Cloudflare multi-account/multi-zone discovery with account,
zone-type, status, and nameserver evidence.
- Add Vercel personal/team installation discovery and current
`/v2/oauth/access_token` callback semantics.
- Keep DNS record operations target-bound and provider-specific
refresh/revocation behavior outside the generic DNS interface.

## Validation

- `DOMAINKIT_WORKSHOP_PORT=4183 bun run release:check`

## Follow-up Scope

- React target-selection UX remains outside this provider contract
change.
S
Saatvik Arya committed
85eec88188cffc6daefd01bc3843c31452d7f378
Parent: 7bafe22
Committed by GitHub <noreply@github.com> on 8/31/2026, 8:51:59 AM