API tokens
In a private chat with @UkiyoComputeBot, use/tokens to create or revoke a token. If your account has no email, enter it once during creation. Existing-email users are not asked again.
Copy the secret when it is revealed. It cannot be recovered from the stored hash. Treat it like a password: do not paste it into support tickets, Git, public chats, agent transcripts, or screenshots.
Supply it to clients as UKIYO_API_TOKEN using your local secret manager or private environment configuration. Do not put real tokens in shared examples. Revoke lost/exposed tokens immediately through /tokens. A revoked token must no longer authenticate.
