This view must deliver
- •Change password and manage the second factor.
- •Active sessions and devices, with revoke.
- •An access log: who logged in, from where, and what sensitive action they took.
- •API credentials and webhook endpoints if the API channel is active.
Blocked on
- •API is listed as a payment channel but nothing in scope manages keys, webhooks, a sandbox or delivery logs. Either this view absorbs it or the API channel needs its own developer section.