Static API keys never expire, share identity, and silently shadow federation. WIF replaces them with attested JWT exchange for short-lived per-session tokens.
How a PEP classifies every Claude Code hook event into gating, context, or observe, wires the correct output schema per event, and deny-closes unknown events.
Build an auditor-grade trail for Claude Code and MCP servers without leaving your perimeter: per-agent identity, a hash-chained ledger, untrusted MCP signals.