client_credentials with JWT HS256. Scopes per integration, project and ledger.
Global user with external_user_id mapping for every project.
Double-entry, multi-currency, reconciliation with providers, consolidated reporting.
/v1/orders, /v1/identity/*, /v1/ledger/* — one contract for all.
Idempotency-Key, HMAC-signed webhooks, audit log, rate limits.
Outbound deliveries with retries, inbound from providers with signature verification.