Report vulnerabilities privately through the repository's GitHub security advisory feature.
Delegated verifies issuer-signed bearer capabilities against explicit host configuration. Security
depends on issuer-key custody, trustworthy `OperationContext` construction, atomic shared replay
state, durable audit handling, short token lifetimes, and secure transport.
The library does not authenticate the bearer or establish that a user is currently present.