{ "_comment": [ "Identity map: API-key fingerprints to account origins (NO key material).", "Checked in. Fingerprints are sha256 of the raw key bytes (${identity-resolve.py fp}).", "Resolution rule: api_key -> account_origin(s); one origin rolls scope UP", "to the umbrella account; two or more (openrouter + provider) keeps scope", "DOWN at the key itself. Keys under top-level '_' entries are ignored.", "Schema: accounts: { email: { keys: [ {fp, origins:[email...], label?} ] } }" ], "_example": { "uma@example.com": { "keys": [ {"fp": "sha256:EXAMPLE-replace-with-real-fingerprint", "origins": ["uma@example.com"], "label": "main"}, {"fp": "sha256:EXAMPLE-openrouter-key-fingerprint", "origins": ["uma@example.com", "provider-acct"], "label": "openrouter"} ] } }, "accounts": {} }