fix(auth): preserve header credential provenance locally
The non-cloud session builder labeled header-sourced API keys as environment credentials. Preserve their resolved API-key source so Core 401 responses receive CREDENTIAL_INVALID recovery, while true environment credentials retain their existing self-hosted error behavior.
M
Max Loffgren committed
3d68074eb10a734aee93beb4c292ace87be76e89
Parent: 4af4bea