* fix(security): enforce server-side actor identity * test: align message schema assertion with actor hardening * fix(security): enforce server actor identity in chat and broadcast * feat(auth): add scoped agent API keys with expiry and revocation