Dataset Workbench
Store a cloud-storage credential for dataset import
Save an owner-scoped credential used by source_uri imports from private buckets. Encrypted at rest (Fernet) and never echoed back — the listing is masked by construction. Prefer a presigned/SAS URL where you can: it imports with no stored secret at all.
POST
Store a cloud-storage credential for dataset import
Authorizations
Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.
Body
application/json

