{
  "$comment": "Variables a conformance runner MUST supply before executing the suite. Every ${name} appearing in a fixture is either declared here or captured by an earlier fixture's `captures` block; tools/validate.mjs enforces that. This file is a manifest, not a fixture.",
  "credentials": {
    "worker_http_token": "Bearer token for the primary worker identity (worker_agent_uid: worker-http). Holds the claims created by claim-grant.success.",
    "worker_other_token": "Bearer token for a second, distinct worker identity. Used to prove that claim conflict and renewal authorization are enforced against identity, not just against the claim id. MUST NOT be the same principal as worker_http_token.",
    "producer_token": "Bearer token for an identity authorized to create work items.",
    "lead_token": "Bearer token for an identity authorized to accept handoffs and post blackboard entries."
  },
  "seeded_state": {
    "active_claim_id": "Identifier of a claim in claim_status: active, owned by worker_http_token, with sufficient TTL remaining to complete. Runners MAY satisfy this by substituting the claim_id captured from claim-grant.success rather than seeding one separately.",
    "expired_claim_id": "Identifier of a claim whose lease has expired, owned by worker_http_token. Cannot be produced by the suite itself without waiting out a TTL, so the runner MUST seed it directly or advance the implementation's clock."
  }
}
