80916c817a
First of the vibe-coder API-rotation batch. Resend mints a new API key authenticated by the old one (POST /api-keys), verifies it by listing keys with the new Bearer token and asserting its id is present, then deletes the old key by id (DELETE /api-keys/<id>). Self-contained blob resend://host/?id=&secret= keeps the token off Identity/Meta/logs/argv. httptest emulator enforces Bearer validity (key authenticates only while it exists) so the test proves a real cutover: old dead, new alive, plus a leak check. Recorded MOCK-ONLY in proofs.go + ROTATION-PROOFS.md (no self-host). Note: GitHub PAT is intentionally NOT an API Rotator — GitHub has no create-token API (classic Authorizations API removed 2020; fine-grained PATs are UI-only), so a PAT belongs in the guided/worklist path, not here. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>