Part of #938.\n\nHarden the merged two-App persistence foundation before #941, #942, and #943: add an external-safe MCP/browser authorization transaction identifier bound to app kind and Entra subject; add cross-provider lifecycle delivery replay claims; define stable credential-version grant semantics; and correct the webhook replay contract to delivery-id uniqueness plus HMAC validation without an unenforceable GitHub delivery-age assertion.\n\nDependencies: #954\nBlocks: #941, #942, #943
Part of #938.\n\nHarden the merged two-App persistence foundation before #941, #942, and #943: add an external-safe MCP/browser authorization transaction identifier bound to app kind and Entra subject; add cross-provider lifecycle delivery replay claims; define stable credential-version grant semantics; and correct the webhook replay contract to delivery-id uniqueness plus HMAC validation without an unenforceable GitHub delivery-age assertion.\n\nDependencies: #954\nBlocks: #941, #942, #943