- Updated verify_api_key() to check secrets first (admin, user, register) - Secrets are now treated as API keys with appropriate scopes - All OpenRPC methods now work with secrets (register_runner, list_runners, etc.) - Simplified auth_verify since verify_api_key handles everything - Admin UI now fully functional with admin secret from .env