MUDRAID_PRIVATE_KEY_PATH and MUDRAID_KEY_ID
(or the corresponding custom prefix). The loader reads the key when constructing
the client; recreate the client after changing that configuration. A custom signer
owns its own key lifecycle.
If a key may be compromised, use the available authorized client/key containment
controls and verify the resulting enforcement state. Replacing a local key file
alone does not revoke the previous public key or already-issued access tokens.
Offline token validation may accept an issued token until expiry; live enforcement
behavior must be verified for the integration. Restore access through the relevant
enforcement workflow rather than bypassing an existing hold.
See Configuration and
Agent identity.
