This package is intended for private Composer distribution. Never add client secrets, signing keys, OTPs, recovery codes, App Ops grants, tenant snapshots, or server-side management operations to this repository.
Report security issues privately to the Novvor Identity security owners. Do not open a public issue for credential exposure. A credential found in current code or history must be revoked and rotated; making a repository private is not a substitute for remediation.