Identities for entities did.bot
agent llm did

docs(auth-types): name the credential the repo write routes take master

`getSession`'s doc and `docs/architecture.md` both said the `com.atproto.repo.*` write surface was open, and `AccountMismatch` offered the caller an operator credential. Those routes take an agent token, and every account-lifecycle mutation is self-service. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Change-Id: I12db5bfb8097c3d09350d616ccf6770d7e7fbbc9


+30 -34
4 changed files