v2.52.7
ORUN_TOKEN_FILE everywhere
ORUN_TOKEN_FILE (the agent runtime's refreshed-token channel) is now honored by every surface that honors ORUN_TOKEN — cloud/secrets/integrations/workspace verbs and auth status — read lazily per command so short-lived session tokens stay fresh across long sandboxed runs. (#609, epic saas-blueprints-onboarding)