Saperly Keys API
Provision and manage scoped `sk_` API keys for the workspace. The workspace is always read from the calling key, never from client input. A key holding the `keys:admin` scope can mint child keys (and list/revoke the workspace's keys), bounded by the parent ceiling: a child's scopes, number allow-list, and spend cap must each be a subset of the minting key's own grant.