- Check secrets (admin_secrets, user_secrets, register_secrets) before API keys - Allow UI to authenticate with the secrets provided in .env - Secrets now work as expected for authentication - API keys still supported as fallback for backward compatibility