Stats API
GET /api/stats returns statistics for the authenticated owner. Send a server-issued Bearer token with read permission. An anonymous request returns 401; a write-only token returns 403.
{ "tokens": 4, "projects": 12 }
tokens counts issued credentials, including revoked entries but excluding deleted tokens. projects counts current agent sources; hosts and clusters are excluded. Counts are derived from owner-scoped token/source queries. No cross-owner aggregate or shared write counter is maintained.
The JSON shape is preserved, but authentication is now required. Responses are not cached. Storage failures return 503; the shared read request budget can return 429. See Monitoring API for the complete credential and limit contract.