/*
 * Design tokens for every Iron Sheepdog surface. This block is the only place
 * a colour literal belongs; `tests/unit/designTokens.test.ts` fails the build
 * if one appears in a rule below it, and holds the API reference's Tailwind
 * theme to the same values.
 *
 * Tokens are named for the role they play, not the colour they happen to be,
 * so two roles that share a value today can diverge without touching a rule.
 * The site is light-only: there is no dark theme to keep in step.
 */
:root {
  /* Brand. --isd-red-rgb backs the accent washes that need an alpha. */
  --isd-red: #b21f28;
  --isd-red-dark: #470c10;
  --isd-red-subtle: #f0d2d4;
  --isd-red-rgb: 178 31 40;
  --isd-inverse-rgb: 17 17 17;

  /* Ink on light surfaces. */
  --isd-ink: #2a2a2a;
  --isd-ink-strong: #111111;
  --isd-muted: #5c5c5c;

  /* Surfaces, page outward to inset. */
  --isd-bg: #f3f3f3;
  --isd-surface: #ffffff;
  --isd-surface-sunken: #eeeeee;
  --isd-surface-sunken-hover: #e0e0e0;
  --isd-accent-wash: #f7f0f0;

  /* Deliberately dark surfaces: the header, code panels, revealed secrets. */
  --isd-inverse: #111111;
  --isd-inverse-raised: #1a1a1a;

  /* Ink and lines on those dark surfaces. */
  --isd-on-dark: #ffffff;
  --isd-on-dark-muted: #e8e8e8;
  --isd-on-dark-subtle: #bbbbbb;
  --isd-on-dark-border: #666666;
  --isd-on-dark-border-strong: #999999;
  --isd-on-dark-border-subtle: #333333;
  --isd-on-dark-wash: rgb(255 255 255 / 0.06);
  --isd-on-dark-border-translucent: rgb(255 255 255 / 0.45);

  /* Hairlines on light surfaces. */
  --isd-border: #d8d8d8;
  --isd-wash: rgb(0 0 0 / 0.04);

  /* Status. Each state carries its own fill, ink and edge. */
  --isd-ok-bg: #e8f5e9;
  --isd-ok-ink: #1b5e20;
  --isd-ok-border: rgb(21 128 61 / 0.45);
  --isd-ok-fill: rgb(21 128 61 / 0.12);
  --isd-warn-bg: rgb(180 83 9 / 0.12);
  --isd-warn-ink: #b45309;
  --isd-warn-border: rgb(180 83 9 / 0.45);
  --isd-danger-bg: #fde8e8;
  --isd-danger-bg-hover: #f5c6c6;
  --isd-danger-ink: #8a1f1f;
  --isd-danger-border: #f5b5b5;

  /* Type scale for headings, shared with the API reference. */
  --isd-text-h1: clamp(2.2rem, 5vw, 3rem);
  --isd-text-h2: 1.55rem;
  --isd-text-h3: 1.15rem;

  /* Radius scale. Everything rounded picks one of these three. */
  --isd-radius: 2px;
  --isd-radius-lg: 4px;
  --isd-radius-pill: 999px;

  /* Elevation. */
  --isd-shadow-header: 0 2px 8px rgb(0 0 0 / 0.18);
  --isd-shadow-raised: 0 10px 40px rgb(0 0 0 / 0.08);

  --font-body:
    "Roboto Condensed", "Helvetica Neue", Helvetica, Arial, sans-serif;
  --font-display: "Bebas Neue", "Arial Narrow", Impact, sans-serif;
  --font-mono: "DM Mono", ui-monospace, Menlo, monospace;
  --font: var(--font-body);
}

* {
  box-sizing: border-box;
}

html {
  scroll-behavior: smooth;
}

/* Anchor jumps can cross thousands of pixels; animating that is exactly what
   this preference asks us not to do. */
@media (prefers-reduced-motion: reduce) {
  html {
    scroll-behavior: auto;
  }
}

body.portal {
  margin: 0;
  min-height: 100vh;
  font-family: var(--font-body);
  color: var(--isd-ink);
  background: var(--isd-bg);
  font-weight: 400;
  letter-spacing: 0.01em;
}

body.portal.portal--marketing {
  background: var(--isd-inverse);
  color: var(--isd-surface);
}

.portal-header {
  position: sticky;
  top: 0;
  z-index: 1000;
  display: flex;
  align-items: center;
  justify-content: space-between;
  gap: 1rem;
  width: 100%;
  flex-shrink: 0;
  padding: 0.9rem 1.5rem;
  background: var(--isd-inverse);
  border-bottom: 3px solid var(--isd-red);
  color: var(--isd-surface);
  box-shadow: var(--isd-shadow-header);
}

.portal-brand {
  display: flex;
  align-items: center;
  gap: 0.75rem;
  text-decoration: none;
  color: inherit;
  font-family: var(--font-mono);
  font-weight: 500;
  font-size: 0.85rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
}

.portal-brand img {
  height: 28px;
  width: auto;
}

.portal-nav {
  display: flex;
  flex-wrap: wrap;
  gap: 0.35rem 1.15rem;
  align-items: center;
}

/*
 * Mobile nav toggle. Injected by portal.js so the static pages and the
 * /docs-injected header share one implementation. Hidden on desktop.
 */
.portal-nav-toggle {
  display: none;
  appearance: none;
  border: 1px solid var(--isd-on-dark-border);
  background: transparent;
  color: var(--isd-on-dark-muted);
  border-radius: var(--isd-radius);
  padding: 0.4rem 0.55rem;
  cursor: pointer;
  line-height: 0;
}

.portal-nav-toggle:hover {
  border-color: var(--isd-on-dark-border-strong);
  color: var(--isd-on-dark);
}

.portal-nav-toggle svg {
  width: 1.15rem;
  height: 1.15rem;
  display: block;
}

.portal-nav-toggle .portal-nav-toggle-close {
  display: none;
}

.portal-nav-toggle[aria-expanded="true"] .portal-nav-toggle-open {
  display: none;
}

.portal-nav-toggle[aria-expanded="true"] .portal-nav-toggle-close {
  display: block;
}

.portal-nav a {
  color: var(--isd-on-dark-muted);
  text-decoration: none;
  font-family: var(--font-mono);
  font-size: 0.82rem;
  letter-spacing: 0.04em;
  text-transform: uppercase;
}

.portal-nav a:hover,
.portal-nav a[aria-current="page"] {
  color: var(--isd-on-dark);
  text-decoration: underline;
  text-underline-offset: 4px;
}

.portal-nav-cta {
  border: 1px solid var(--isd-red) !important;
  color: var(--isd-on-dark) !important;
  background: var(--isd-red);
  border-radius: var(--isd-radius);
  padding: 0.35rem 0.75rem !important;
  text-decoration: none !important;
}

.portal-nav-cta:hover {
  background: var(--isd-red-dark) !important;
  border-color: var(--isd-red-dark) !important;
}

.portal-nav button {
  appearance: none;
  border: 1px solid var(--isd-on-dark-border);
  background: transparent;
  color: var(--isd-on-dark-muted);
  border-radius: var(--isd-radius);
  padding: 0.3rem 0.7rem;
  cursor: pointer;
  font-family: var(--font-mono);
  font-size: 0.78rem;
  letter-spacing: 0.04em;
  text-transform: uppercase;
}

.portal-nav button:hover {
  border-color: var(--isd-on-dark-border-strong);
  color: var(--isd-on-dark);
}

.portal-main {
  max-width: 52rem;
  margin: 0 auto;
  padding: 2rem 1.25rem 3rem;
}

.portal-main h1,
.portal-main h2,
.portal-main h3 {
  font-family: var(--font-display);
  font-weight: 400;
  letter-spacing: 0.04em;
  text-transform: uppercase;
  color: var(--isd-ink-strong);
}

.portal-main h1 {
  font-size: var(--isd-text-h1);
  line-height: 0.95;
  margin: 0 0 0.65rem;
}

.portal-main .lede {
  font-size: 1.1rem;
  line-height: 1.45;
  margin: 0 0 1.75rem;
  /* Matches .portal-main's own measure. A narrower lede than the body copy
     beneath it reads backwards and left a ragged step in the text block. */
  max-width: 46rem;
  color: var(--isd-muted);
  font-weight: 300;
}

.portal-main h2 {
  font-size: var(--isd-text-h2);
  margin: 2rem 0 0.5rem;
}

.portal-main h3 {
  font-size: var(--isd-text-h3);
  margin: 1.5rem 0 0.4rem;
}

.portal-main p,
.portal-main li {
  line-height: 1.55;
}

.portal-main code,
.portal-main pre {
  font-family: var(--font-mono);
}

/*
 * Matches the API reference at /docs, which fills inline code with a neutral
 * tint and delineates it with a hairline ring. The ring does the work: the fill
 * is close to the page background, so a span sitting on the page rather than on
 * a white card is still legible. Brand red is kept for accents instead of being
 * spent on every inline token — the reference alone carries about 70 of them.
 */
.portal-main code {
  background: var(--isd-bg);
  box-shadow: inset 0 0 0 1px var(--isd-border);
  padding: 0.1em 0.35em;
  border-radius: var(--isd-radius);
  font-size: 0.92em;
}

.portal-main pre {
  background: var(--isd-inverse);
  color: var(--isd-on-dark-muted);
  padding: 1rem 1.1rem;
  border-radius: var(--isd-radius-lg);
  overflow-x: auto;
  font-size: 0.88rem;
  line-height: 1.45;
}

/* —— Marketing home (inspired by ironsheepdog.com) —— */
.marketing-hero {
  position: relative;
  min-height: calc(100vh - 4rem);
  display: flex;
  align-items: flex-end;
  overflow: hidden;
  background:
    linear-gradient(
      105deg,
      rgb(var(--isd-inverse-rgb) / 0.92) 28%,
      rgb(var(--isd-inverse-rgb) / 0.55) 70%,
      rgb(var(--isd-red-rgb) / 0.35) 100%
    ),
    url("https://images.unsplash.com/photo-1601584115197-04ecc0da31d7?auto=format&fit=crop&w=2400&q=80")
      center / cover no-repeat;
}

.marketing-hero-inner {
  width: min(100%, 72rem);
  margin: 0 auto;
  padding: 4.5rem 1.5rem 4rem;
}

.marketing-eyebrow {
  font-family: var(--font-mono);
  font-size: 0.8rem;
  letter-spacing: 0.14em;
  text-transform: uppercase;
  color: var(--isd-red-subtle);
  margin: 0 0 1rem;
}

.marketing-hero h1 {
  font-family: var(--font-display);
  font-weight: 400;
  font-size: clamp(3.4rem, 10vw, 6.5rem);
  line-height: 0.9;
  letter-spacing: 0.03em;
  text-transform: uppercase;
  margin: 0 0 1.25rem;
  max-width: 14ch;
  color: var(--isd-on-dark);
}

.marketing-hero .marketing-lede {
  font-size: clamp(1.05rem, 2vw, 1.25rem);
  font-weight: 300;
  line-height: 1.4;
  max-width: 34rem;
  margin: 0 0 1.75rem;
  color: var(--isd-on-dark-muted);
}

.marketing-ctas {
  display: flex;
  flex-wrap: wrap;
  gap: 0.75rem;
}

.marketing-btn {
  display: inline-flex;
  align-items: center;
  justify-content: center;
  min-height: 2.75rem;
  padding: 0.65rem 1.25rem;
  font-family: var(--font-mono);
  font-size: 0.82rem;
  letter-spacing: 0.08em;
  text-transform: uppercase;
  text-decoration: none;
  border-radius: var(--isd-radius);
  border: 1px solid transparent;
  transition:
    background 0.15s ease,
    color 0.15s ease,
    border-color 0.15s ease;
}

.marketing-btn-primary {
  background: var(--isd-red);
  color: var(--isd-on-dark);
  border-color: var(--isd-red);
}

.marketing-btn-primary:hover {
  background: var(--isd-red-dark);
  border-color: var(--isd-red-dark);
}

.marketing-btn-ghost {
  background: transparent;
  color: var(--isd-on-dark);
  border-color: var(--isd-on-dark-border-translucent);
}

.marketing-btn-ghost:hover {
  border-color: var(--isd-on-dark);
  background: var(--isd-on-dark-wash);
}

.marketing-section {
  background: var(--isd-bg);
  color: var(--isd-ink);
}

.marketing-section-inner {
  width: min(100%, 72rem);
  margin: 0 auto;
  padding: 4rem 1.5rem;
}

.marketing-section h2 {
  font-family: var(--font-display);
  font-weight: 400;
  font-size: clamp(2rem, 5vw, 3.25rem);
  line-height: 0.95;
  letter-spacing: 0.03em;
  text-transform: uppercase;
  margin: 0 0 0.85rem;
  color: var(--isd-ink-strong);
  /* 18ch broke "What you can access" mid-phrase; this keeps the display
     line-length short without forcing an awkward break. */
  max-width: 24ch;
}

.marketing-section .section-lede {
  font-size: 1.1rem;
  font-weight: 300;
  line-height: 1.45;
  max-width: 38rem;
  margin: 0 0 2rem;
  color: var(--isd-muted);
}

.marketing-split {
  display: grid;
  gap: 1.5rem;
  grid-template-columns: 1fr;
}

@media (min-width: 800px) {
  .marketing-split {
    grid-template-columns: 1.1fr 0.9fr;
    gap: 2.5rem;
    align-items: end;
  }
}

.marketing-points {
  list-style: none;
  margin: 0;
  padding: 0;
  display: grid;
  gap: 1rem;
}

.marketing-points li {
  border-left: 3px solid var(--isd-red);
  padding: 0.35rem 0 0.35rem 1rem;
}

.marketing-points strong {
  display: block;
  font-family: var(--font-display);
  letter-spacing: 0.04em;
  text-transform: uppercase;
  font-size: 1.25rem;
  font-weight: 400;
  color: var(--isd-ink-strong);
  margin-bottom: 0.2rem;
}

.marketing-points span {
  color: var(--isd-muted);
  font-weight: 300;
  line-height: 1.4;
}

.marketing-footer {
  background: var(--isd-inverse);
  color: var(--isd-on-dark-subtle);
  font-family: var(--font-mono);
  font-size: 0.75rem;
  letter-spacing: 0.05em;
  text-transform: uppercase;
  padding: 1.25rem 1.5rem 2rem;
}

.marketing-footer-inner {
  width: min(100%, 72rem);
  margin: 0 auto;
  display: flex;
  flex-wrap: wrap;
  gap: 0.75rem 1.5rem;
  justify-content: space-between;
}

.marketing-footer a {
  color: var(--isd-on-dark);
  text-decoration: none;
}

.marketing-footer a:hover {
  text-decoration: underline;
  text-underline-offset: 3px;
}

.login-shell {
  min-height: calc(100vh - 4rem);
  display: grid;
  place-items: center;
  padding: 1.5rem;
}

.login-card {
  width: min(100%, 24rem);
  background: var(--isd-surface);
  border-radius: var(--isd-radius);
  border: 1px solid var(--isd-border);
  padding: 1.75rem 1.5rem 1.5rem;
  box-shadow: var(--isd-shadow-raised);
}

.login-card h1 {
  margin: 0.75rem 0 0.25rem;
  font-family: var(--font-display);
  font-size: 2rem;
  letter-spacing: 0.04em;
  text-transform: uppercase;
  font-weight: 400;
  color: var(--isd-ink-strong);
}

.login-card .sub {
  margin: 0 0 1.25rem;
  color: var(--isd-muted);
  font-size: 0.95rem;
  font-weight: 300;
}

.login-card label {
  display: block;
  font-family: var(--font-mono);
  font-size: 0.75rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  font-weight: 500;
  margin: 0.75rem 0 0.3rem;
}

.login-card input {
  width: 100%;
  padding: 0.55rem 0.65rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  font: inherit;
}

.login-card input:focus {
  outline: 2px solid var(--isd-red-subtle);
  border-color: var(--isd-red);
}

.login-actions {
  display: flex;
  flex-direction: column;
  gap: 0.6rem;
  margin-top: 1.1rem;
}

.login-actions button {
  appearance: none;
  border: none;
  border-radius: var(--isd-radius);
  padding: 0.7rem 1rem;
  font-family: var(--font-mono);
  font-size: 0.8rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  font-weight: 500;
  cursor: pointer;
}

.btn-primary {
  background: var(--isd-red);
  color: var(--isd-on-dark);
}

.btn-primary:hover {
  background: var(--isd-red-dark);
}

.btn-secondary {
  background: var(--isd-surface-sunken);
  color: var(--isd-ink-strong);
}

.btn-secondary:hover {
  background: var(--isd-surface-sunken-hover);
}

.login-error {
  margin-top: 0.85rem;
  padding: 0.65rem 0.75rem;
  background: var(--isd-danger-bg);
  border: 1px solid var(--isd-danger-border);
  border-radius: var(--isd-radius);
  color: var(--isd-danger-ink);
  font-size: 0.9rem;
  display: none;
}

.login-error.visible {
  display: block;
}

.login-logo {
  height: 36px;
  width: auto;
}

/*
 * /docs: shared portal header; Protocol offsets via --isd-portal-header-height.
 *
 * The fallback lives on :root because portal.js measures the real header and
 * writes the variable to documentElement. Declaring it on body.portal--docs
 * instead would shadow that write for every descendant, pinning the offset at
 * the fallback and silently discarding the measurement.
 */
:root {
  --isd-portal-header-height: 3.75rem;
}

/*
 * Plain content panel. Same surface and the same gutters as .cred-panel; the
 * only difference is the red left rail, which marks a working section on the
 * console pages and would read as an alert running down a page of prose.
 *
 * A page title and its lede sit on the page ground; a panel holds the content
 * below them. Every page follows that shape.
 */
.portal-panel {
  margin: 0 0 2rem;
  /* Side gutters match .cred-panel. The lighter top accounts for the 1rem
     margin on a leading h2, which lands the first line in the same place. */
  padding: 0.5rem 1.25rem 1.5rem;
  background: var(--isd-surface);
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
}

.portal-panel > h2:first-child {
  margin-top: 1rem;
}

/* —— Company console (/keys, /admin/companies) —— */
.cred-panel {
  margin: 0 0 2.5rem;
  padding: 1.25rem 1.25rem 1.5rem;
  background: var(--isd-surface);
  border: 1px solid var(--isd-border);
  border-left: 4px solid var(--isd-red);
  border-radius: var(--isd-radius);
}

.cred-panel > h2 {
  margin-top: 0;
}

.cred-lookup label {
  display: block;
  font-family: var(--font-mono);
  font-size: 0.75rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  margin: 0 0 0.35rem;
}

.cred-lookup-row {
  display: flex;
  flex-wrap: wrap;
  gap: 0.5rem;
}

.cred-lookup-row input,
.cred-create input {
  flex: 1 1 12rem;
  min-width: 0;
  padding: 0.55rem 0.65rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  font: inherit;
}

.cred-lookup-row input:focus,
.cred-create input:focus {
  outline: 2px solid var(--isd-red-subtle);
  border-color: var(--isd-red);
}

.cred-status {
  margin: 0.85rem 0 0;
  padding: 0.55rem 0.7rem;
  border-radius: var(--isd-radius);
  font-size: 0.92rem;
}

.cred-status--info {
  background: var(--isd-surface-sunken);
  color: var(--isd-ink);
}

.cred-status--ok {
  background: var(--isd-ok-bg);
  color: var(--isd-ok-ink);
}

.cred-status--error {
  background: var(--isd-danger-bg);
  color: var(--isd-danger-ink);
}

.cred-company {
  margin-top: 1.25rem;
}

.cred-company-head {
  display: flex;
  flex-wrap: wrap;
  gap: 1rem;
  justify-content: space-between;
  align-items: flex-end;
  margin-bottom: 1rem;
}

.cred-company-head strong {
  display: block;
  font-family: var(--font-display);
  font-size: 1.35rem;
  letter-spacing: 0.04em;
  text-transform: uppercase;
  font-weight: 400;
}

.cred-meta {
  display: flex;
  flex-wrap: wrap;
  gap: 0.5rem 1rem;
  margin-top: 0.25rem;
  font-size: 0.9rem;
  color: var(--isd-muted);
}

/*
 * The flex row above is for chips — a code span and a label sitting side by
 * side, which is what the `gap` is for. On a paragraph of prose it means every
 * inline element becomes a flex item, so `<em>and</em>` mid-sentence gets 1rem
 * of column gap beside it and reads as a typo. Paragraphs keep the type and
 * colour and lay out as text.
 */
p.cred-meta {
  display: block;
}

.cred-create {
  display: flex;
  flex-wrap: wrap;
  gap: 0.5rem;
  align-items: center;
}

.cred-reveal {
  margin: 0 0 1.25rem;
  padding: 1rem 1.1rem;
  background: var(--isd-inverse);
  color: var(--isd-on-dark-muted);
  border-radius: var(--isd-radius-lg);
}

.cred-reveal strong {
  display: block;
  font-family: var(--font-display);
  letter-spacing: 0.04em;
  text-transform: uppercase;
  font-weight: 400;
  margin-bottom: 0.35rem;
}

.cred-reveal-notice {
  margin: 0 0 0.5rem;
  color: var(--isd-red-subtle);
  font-size: 0.92rem;
}

.cred-reveal-hint {
  margin: 0 0 0.85rem;
  color: var(--isd-on-dark-subtle);
  font-size: 0.88rem;
}

.cred-reveal-row {
  margin: 0 0 0.65rem;
}

.cred-reveal-row label {
  display: block;
  font-family: var(--font-mono);
  font-size: 0.72rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  color: var(--isd-on-dark-subtle);
  margin: 0 0 0.25rem;
}

.cred-reveal-field-help {
  margin: 0 0 0.4rem;
  color: var(--isd-on-dark-subtle);
  font-size: 0.82rem;
  line-height: 1.4;
  font-weight: 300;
}

.cred-reveal-field-help code {
  background: transparent;
  color: var(--isd-red-subtle);
  padding: 0;
  font-size: 0.95em;
}

.cred-reveal-value {
  display: flex;
  gap: 0.45rem;
  align-items: stretch;
}

.cred-reveal-value input {
  flex: 1 1 auto;
  min-width: 0;
  padding: 0.5rem 0.6rem;
  border: 1px solid var(--isd-on-dark-border);
  border-radius: var(--isd-radius);
  background: var(--isd-inverse-raised);
  color: var(--isd-on-dark);
  font-family: var(--font-mono);
  font-size: 0.85rem;
}

.cred-reveal-value input:focus {
  outline: 2px solid var(--isd-red);
  border-color: var(--isd-red);
}

.cred-reveal-value .cred-copy-btn {
  flex: 0 0 auto;
  white-space: nowrap;
}

.cred-reveal-actions {
  display: flex;
  flex-wrap: wrap;
  gap: 0.5rem;
  margin-top: 0.75rem;
}

/*
 * No `overflow-x: auto` here, deliberately.
 *
 * A scrollable wrapper turns "this table is too wide" into a gesture the reader
 * has to discover, and it hid a real defect for a while: with a key scoped to all
 * seven APIs the table needed 788px in a 747px wrapper at *every* desktop width,
 * because the page measure caps at 52rem. The table below cannot exceed its
 * container, so there is nothing left to scroll.
 */
.cred-table-wrap {
  container-type: inline-size;
}

/*
 * `table-layout: fixed` is the guarantee.
 *
 * With automatic layout a column grows to fit its widest cell and the table
 * pushes past its container — an API id like `example-bq-jobs-by-broker` is one
 * unbreakable 25-character token, and seven of them in a chip list is all it
 * takes. Fixed layout inverts that: the columns take the shares declared below
 * and content wraps inside them, so a row gets taller rather than the table
 * getting wider. Height is free here; width is not.
 *
 * `overflow-wrap: anywhere` is the other half. It only breaks a token when there
 * is no other option, so a chip that fits stays whole, but a long one can never
 * spill out of its cell.
 */
.cred-table {
  width: 100%;
  table-layout: fixed;
  border-collapse: collapse;
  font-size: 0.92rem;
}

.cred-table td,
.cred-table th {
  overflow-wrap: anywhere;
}

/*
 * Column shares. Scopes takes the most because it is the only column whose
 * content is unbounded; actions take the least because a menu is one button.
 */
.cred-table--keys th:nth-child(1) {
  width: 26%;
}
.cred-table--keys th:nth-child(2) {
  width: 46%;
}
.cred-table--keys th:nth-child(3) {
  width: 21%;
}
.cred-table--keys th:nth-child(4) {
  width: 7%;
}

.cred-table--apis th:nth-child(1) {
  width: 30%;
}
.cred-table--apis th:nth-child(2) {
  width: 26%;
}
.cred-table--apis th:nth-child(3) {
  width: 30%;
}
.cred-table--apis th:nth-child(4) {
  width: 14%;
}

.cred-table th,
.cred-table td {
  text-align: left;
  padding: 0.55rem 0.45rem;
  border-bottom: 1px solid var(--isd-border);
  vertical-align: middle;
}

.cred-table th {
  font-family: var(--font-mono);
  font-size: 0.72rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  color: var(--isd-muted);
  font-weight: 500;
}

.cred-table code {
  font-size: 0.85em;
}

/*
 * "created Feb 1, 2026" is a single fact and wrapping it mid-phrase cost 17px of
 * row height on every row. A table column grows to fit unwrappable content, and
 * this one has room to take it from the chip list beside it, which wraps happily.
 */
.cred-table td[data-label="Lifetime"] .cred-meta {
  white-space: nowrap;
}

.cred-empty {
  color: var(--isd-muted);
  font-style: italic;
}

.cred-muted {
  color: var(--isd-muted);
}

/*
 * A key with no label.
 *
 * It sits where every other row carries a name in semibold, so it has to read as
 * an absence rather than as a name that happens to be "(no label)". Lighter and
 * italic against the surrounding weight does that; the parentheses alone did
 * not, because the cell's <strong> was still bolding it.
 */
.cred-no-label {
  font-weight: 300;
  font-style: italic;
  color: var(--isd-muted);
}

.cred-actions {
  white-space: nowrap;
  text-align: right;
}

/*
 * Row actions live in a menu.
 *
 * Three buttons cost 207px of a 747px table — the widest column after scopes,
 * spent on controls rather than data, and present on every row whether or not
 * anyone is about to act. One trigger costs about 40px. It also puts Revoke
 * behind a step instead of leaving it permanently adjacent to Rotate.
 *
 * The menu is positioned inside its own cell, which only works because no
 * ancestor scrolls or clips any more — see .cred-table-wrap above.
 */
.cred-menu-wrap {
  position: relative;
  display: inline-block;
}

.cred-menu-btn {
  min-width: 2.1rem;
  padding: 0.3rem 0.45rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  background: var(--isd-surface);
  color: var(--isd-ink);
  font-family: var(--font-mono);
  font-size: 0.9rem;
  line-height: 1;
  cursor: pointer;
}

.cred-menu-btn:hover,
.cred-menu-btn[aria-expanded="true"] {
  border-color: var(--isd-red);
  color: var(--isd-red);
}

.cred-menu-btn:focus-visible {
  outline: 2px solid var(--isd-red-subtle);
  border-color: var(--isd-red);
}

.cred-menu {
  position: absolute;
  top: calc(100% + 0.25rem);
  right: 0;
  z-index: 20;
  min-width: 11rem;
  padding: 0.25rem;
  display: flex;
  flex-direction: column;
  background: var(--isd-surface);
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  box-shadow: var(--isd-shadow-raised);
  text-align: left;
}

.cred-menu[hidden] {
  display: none;
}

.cred-menu-item {
  padding: 0.5rem 0.6rem;
  border: 0;
  border-radius: var(--isd-radius);
  background: none;
  color: var(--isd-ink);
  font-family: var(--font-mono);
  font-size: 0.72rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  text-align: left;
  white-space: nowrap;
  cursor: pointer;
}

.cred-menu-item:hover,
.cred-menu-item:focus-visible {
  background: var(--isd-surface-sunken);
  outline: none;
}

.cred-menu-item--danger {
  color: var(--isd-danger-ink);
}

.cred-menu-item--danger:hover,
.cred-menu-item--danger:focus-visible {
  background: var(--isd-danger-bg);
}

.cred-panel .btn-primary,
.cred-panel .btn-secondary,
.cred-panel .btn-danger {
  appearance: none;
  border: none;
  border-radius: var(--isd-radius);
  padding: 0.55rem 0.9rem;
  font-family: var(--font-mono);
  font-size: 0.78rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  font-weight: 500;
  cursor: pointer;
}

.cred-panel .btn-danger {
  background: var(--isd-danger-bg);
  color: var(--isd-danger-ink);
}

.cred-panel .btn-danger:hover {
  background: var(--isd-danger-bg-hover);
}

.cred-actions .btn-secondary,
.cred-actions .btn-danger {
  padding: 0.35rem 0.55rem;
  font-size: 0.7rem;
}

.cred-panel a.btn-secondary {
  display: inline-block;
  text-decoration: none;
  line-height: 1.2;
}

.access-results {
  list-style: none;
  margin: 0.45rem 0 0;
  padding: 0;
  border: 1px solid var(--isd-border);
  background: var(--isd-surface);
  max-height: 16rem;
  overflow-y: auto;
}

.access-results li {
  margin: 0;
  border-bottom: 1px solid var(--isd-border);
}

.access-results li:last-child {
  border-bottom: none;
}

.access-result {
  display: flex;
  justify-content: space-between;
  align-items: baseline;
  gap: 1rem;
  width: 100%;
  padding: 0.55rem 0.7rem;
  border: none;
  background: transparent;
  font: inherit;
  text-align: left;
  cursor: pointer;
}

.access-result:hover,
.access-result:focus {
  background: var(--isd-accent-wash);
}

.access-result code {
  font-size: 0.8em;
  color: var(--isd-muted);
}

.visually-hidden {
  position: absolute;
  width: 1px;
  height: 1px;
  padding: 0;
  margin: -1px;
  overflow: hidden;
  clip: rect(0, 0, 0, 0);
  white-space: nowrap;
  border: 0;
}

/* ——————————————————————————————————————————————————————————————
 * Dark mode
 *
 * The Protocol docs at /docs already follow the system theme, so a
 * light-only portal meant a user in dark mode got dark docs and a light
 * portal on the same journey.
 *
 * Implemented by redefining the palette tokens rather than restyling
 * components, so anything built on the tokens follows automatically. The
 * header and the marketing hero are intentionally unchanged — they are
 * already near-black and are the brand's fixed anchor in both themes.
 * —————————————————————————————————————————————————————————————— */

/* ——————————————————————————————————————————————————————————————
 * Mobile header
 *
 * Below this width the five nav links plus the auth control wrapped into a
 * five-row stack roughly 320px tall — about 40% of a phone viewport before
 * any content, with no way to collapse it. The nav now hides behind the
 * injected toggle.
 *
 * Placed after the base .portal-nav rules: media queries carry no extra
 * specificity, so an earlier block would lose to the later base declarations.
 * —————————————————————————————————————————————————————————————— */
/*
 * Mobile.
 *
 * One breakpoint for the whole portal, matching the nav collapse below: a second
 * threshold would put the header and the content on different rhythms as the
 * viewport narrows.
 *
 * The tables are the reason this block exists. A four-column table with a chip
 * list in it needs about 600px, and a 375px screen offers 290px once the page and
 * panel gutters are paid — so the row scrolled sideways inside its own wrapper,
 * hiding the expiry and every action. Here each row becomes a card: the header
 * row is dropped and each cell states its own label instead, with the actions
 * getting a full-width row of their own at the bottom.
 */
@media (max-width: 767px) {
  .portal-header {
    flex-wrap: wrap;
    row-gap: 0;
  }

  .portal-nav-toggle {
    display: inline-flex;
  }

  .portal-nav {
    display: none;
    order: 3;
    width: 100%;
    flex-direction: column;
    align-items: stretch;
    gap: 0;
    margin: 0.9rem -1.5rem -0.9rem;
    padding: 0.25rem 1.5rem 0.75rem;
    border-top: 1px solid var(--isd-on-dark-border-subtle);
  }

  .portal-header.portal-header--open .portal-nav {
    display: flex;
  }

  .portal-nav a {
    padding: 0.7rem 0;
    border-bottom: 1px solid var(--isd-on-dark-border-subtle);
    font-size: 0.9rem;
  }

  .portal-nav .portal-nav-auth {
    padding-top: 0.85rem;
  }

  .portal-nav .portal-nav-auth a,
  .portal-nav .portal-nav-auth button {
    display: block;
    width: 100%;
    text-align: center;
    border-bottom: none;
  }

  /* Gutters. 375px minus the page and panel padding left 290px of content —
     23% of the screen spent on whitespace, which the tables cannot afford. */
  .portal-main {
    padding: 1.5rem 0.85rem 2.5rem;
  }

  /*
   * Touch targets. Every button in the portal is about 26px tall, which is a
   * mouse target, not a finger one. Applied to the content buttons rather than
   * every button so the header's own collapsed nav keeps its layout.
   */
  .portal-main .btn-primary,
  .portal-main .btn-secondary,
  .portal-main .btn-danger {
    min-height: 2.25rem;
  }

  .cred-panel {
    padding: 1rem 0.9rem 1.25rem;
  }

  .portal-panel {
    padding: 0.4rem 0.9rem 1.25rem;
  }

  /* Each row becomes a card. Roles on the elements keep the table semantics
     that changing `display` would otherwise drop. */
  .cred-table-wrap {
    overflow-x: visible;
  }

  .cred-table,
  .cred-table tbody,
  .cred-table tr,
  .cred-table td {
    display: block;
    width: auto;
  }

  /* Column shares belong to a table; a card takes the width it is given. */
  .cred-table {
    table-layout: auto;
  }

  .cred-table thead {
    display: none;
  }

  .cred-table tr {
    border: 1px solid var(--isd-border);
    border-radius: var(--isd-radius);
    padding: 0.65rem 0.75rem;
    margin: 0 0 0.75rem;
    background: var(--isd-surface);
  }

  .cred-table td {
    border-bottom: none;
    padding: 0.3rem 0;
  }

  /*
   * The dropped header, restated per cell and stacked above its value rather
   * than beside it. A label/value pair in two columns only works for a cell with
   * exactly one child, and these cells carry two — a name over its id, an expiry
   * over the date it was set — so the second child landed in the label column.
   *
   * No data-label on the actions cell: a labelled row of buttons reads as a
   * field.
   */
  .cred-table td[data-label]::before {
    content: attr(data-label);
    display: block;
    margin-bottom: 0.1rem;
    font-family: var(--font-mono);
    font-size: 0.66rem;
    letter-spacing: 0.08em;
    text-transform: uppercase;
    color: var(--isd-muted);
  }

  /* The user's row of buttons, on its own line and reachable without a
     sideways scroll. Full-width targets rather than three cramped ones. */
  .cred-table td.cred-actions {
    display: flex;
    flex-wrap: wrap;
    gap: 0.4rem;
    margin-top: 0.6rem;
    padding-top: 0.6rem;
    border-top: 1px solid var(--isd-border);
  }

  .cred-table td.cred-actions button {
    flex: 1 1 auto;
  }

  /*
   * The trigger fills the card's action row and says what it does. A bare ellipsis
   * is legible next to a row of columns; alone at the foot of a card it is a
   * mystery button.
   */
  .cred-menu-wrap {
    display: block;
    flex: 1 1 auto;
  }

  .cred-menu-btn {
    width: 100%;
    min-height: 2.25rem;
  }

  .cred-menu-btn::after {
    content: " Actions";
  }

  .cred-menu {
    left: 0;
    right: 0;
  }

  /* A viewer gets "View only" here, not buttons. The divider would be a rule
     separating nothing from a label. */
  .cred-table td.cred-actions--none {
    margin-top: 0;
    padding-top: 0;
    border-top: none;
  }

  .cred-table .cred-empty {
    padding: 0.5rem 0;
  }

  /* The inline scope editor spans the row and carries no label of its own. */
  .cred-table .cred-row-editor td {
    padding: 0;
  }

  /* The create row stacks: a full-width label, then the term and the action
     side by side so the primary button stays on the same line as its input. */
  .cred-create {
    align-items: stretch;
  }

  .cred-create input {
    flex: 1 1 100%;
  }

  .cred-create select {
    flex: 1 1 auto;
  }

  .cred-create .btn-primary {
    flex: 0 0 auto;
  }

  .cred-lookup-row {
    flex-wrap: wrap;
  }

  .cred-lookup-row input {
    flex: 1 1 100%;
  }

  /* A secret is long and monospace; on a narrow screen the field and its Copy
     button cannot share a line without shrinking the field to uselessness. */
  .cred-reveal-value {
    flex-wrap: wrap;
  }

  .cred-reveal-value input {
    flex: 1 1 100%;
  }
}

/*
 * Environment badge — shown only outside production, so an unlabelled header
 * always means live data. Sits next to the wordmark rather than in the nav,
 * where it survives the mobile collapse.
 */
.portal-env {
  display: inline-flex;
  align-items: center;
  margin-left: 0.6rem;
  padding: 0.15rem 0.45rem;
  border: 1px solid var(--isd-red);
  border-radius: var(--isd-radius);
  background: rgb(var(--isd-red-rgb) / 0.18);
  color: var(--isd-on-dark);
  font-family: var(--font-mono);
  font-size: 0.62rem;
  font-weight: 500;
  letter-spacing: 0.1em;
  text-transform: uppercase;
  white-space: nowrap;
}

/* —— Approved APIs and key scopes ——
 *
 * Two levels share one page, so they share one visual vocabulary: a pill states
 * what Iron Sheepdog approved for the company, and chips list what an
 * individual key is scoped to. A stale chip — scoped to an API the company has
 * since lost — is called out in red, because the key silently stops working and
 * nothing else on the page would explain why.
 */
.pill {
  display: inline-block;
  padding: 0.1rem 0.5rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius-pill);
  font-size: 0.78rem;
  line-height: 1.6;
  white-space: nowrap;
  color: var(--isd-muted);
}

.pill--on {
  border-color: var(--isd-ok-border);
  background: var(--isd-ok-fill);
  color: var(--isd-ok-ink);
}

.pill--warn {
  border-color: var(--isd-warn-border);
  background: var(--isd-warn-bg);
  color: var(--isd-warn-ink);
}

.pill--danger {
  border-color: var(--isd-danger-border);
  background: var(--isd-danger-bg);
  color: var(--isd-danger-ink);
}

.scope-chips {
  display: flex;
  flex-wrap: wrap;
  gap: 0.3rem;
}

.scope-chip {
  display: inline-block;
  max-width: 100%;
  padding: 0.08rem 0.45rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  background: var(--isd-wash);
  font-family: var(--font-mono);
  font-size: 0.72rem;
  /* Not `nowrap`. A chip carries a display label, and the longest in the
     catalog is 257px — an unbreakable chip wider than its column would spill out
     of a fixed-layout cell with nothing left to scroll. Labels have spaces, so
     normal wrapping only breaks one that genuinely cannot fit. */
  overflow-wrap: anywhere;
}

.scope-chip--stale {
  border-color: var(--isd-red);
  background: rgb(var(--isd-red-rgb) / 0.1);
  color: var(--isd-red);
}

.cred-create-block {
  margin: 0 0 1.25rem;
}

/*
 * "Expires" needs a visible label, unlike the label field beside it. The select
 * shows a term rather than a date, so with no label the row reads as an
 * unexplained duration — and the term is the one thing on this form a partner
 * has to think about.
 */
.cred-create-label {
  font-family: var(--font-mono);
  font-size: 0.72rem;
  letter-spacing: 0.06em;
  text-transform: uppercase;
  color: var(--isd-muted);
  margin-left: 0.35rem;
}

.cred-create select {
  /* 0.5rem, not the input's 0.55rem: a select's intrinsic box runs taller, and
     matching the padding left it standing 2px above the field beside it. */
  padding: 0.5rem 0.5rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  background: var(--isd-surface);
  color: var(--isd-ink);
  font: inherit;
}

.cred-create select:focus {
  outline: 2px solid var(--isd-red-subtle);
  border-color: var(--isd-red);
}

.cred-create-help {
  margin: 0.5rem 0 0;
  font-size: 0.85rem;
  color: var(--isd-muted);
  max-width: 46rem;
}

.scope-picker {
  display: flex;
  flex-wrap: wrap;
  gap: 0.35rem 1rem;
  margin-top: 0.6rem;
}

.scope-option {
  display: inline-flex;
  align-items: center;
  gap: 0.35rem;
  font-size: 0.9rem;
  cursor: pointer;
}

.cred-row-editor > td {
  background: var(--isd-wash);
}

.scope-editor p {
  margin: 0;
}

/*
 * The label editor lives in the Key cell, replacing the name it edits.
 *
 * The field takes the whole cell and the buttons go beneath it: the Key column is
 * 26% of the table, which is not room for a field and two buttons on one line.
 * The apiKey line below is left in place, so it stays visible which key is being
 * renamed.
 */
.label-editor input {
  border-color: var(--isd-border);
  background: var(--isd-surface);
}

.label-editor input:focus {
  outline: 2px solid var(--isd-red-subtle);
  border-color: var(--isd-red);
}

/*
 * The label is the control that edits it.
 *
 * A button carrying the name, so it is reachable by keyboard and announced as
 * an action, but set as text rather than as a control: a row of buttons where
 * every other table shows names would read as a toolbar. The affordance is the
 * hover state, which is why it needs one.
 */
/*
 * The label control and the field that replaces it share one box.
 *
 * Clicking the label used to grow its row by 34px and shove everything below it
 * down the page. 10px of that was the field simply being a bigger box than the
 * text it replaced. Declaring both together — same padding, same border width,
 * same line box — makes the swap height-neutral by construction rather than by
 * two numbers that happen to agree today. The button's border is transparent so
 * it costs the same 1px the field's visible one does.
 */
.cred-label-edit,
.label-editor input {
  display: block;
  box-sizing: border-box;
  width: 100%;
  padding: 0.1rem 0.2rem;
  margin: -0.1rem -0.2rem;
  border: 1px solid transparent;
  border-radius: var(--isd-radius);
  font: inherit;
  line-height: 1.4;
  /* One line in both states. A field never wraps, so a label that did — 70
     characters takes three lines in this column — collapsed the row by 41px the
     moment it was clicked. The full text is on the control's title and in its
     accessible name. */
  white-space: nowrap;
  overflow: hidden;
  text-overflow: ellipsis;
}

.cred-label-edit {
  background: none;
  color: inherit;
  text-align: left;
  cursor: text;
}

.cred-label-edit:hover {
  background: var(--isd-surface-sunken);
  box-shadow: inset 0 0 0 1px var(--isd-border);
}

.cred-label-edit:focus-visible {
  outline: 2px solid var(--isd-red-subtle);
  background: var(--isd-surface-sunken);
}

/* The row being edited is lifted so the field reads as active rather than as a
   stray input among static rows. */
.cred-row-editing > td {
  background: var(--isd-wash);
}

.cred-row-editor-actions {
  margin-top: 0.75rem;
  display: flex;
  gap: 0.5rem;
}

/* —— API settings console ——
 *
 * One card per endpoint. Deliberately plain: these are numbers an operator
 * changes rarely and needs to read accurately, not a dashboard.
 */
.settings-card {
  margin: 0 0 1.25rem;
  padding: 1rem 1.1rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
}

.settings-card h3 {
  margin: 0;
}

.settings-row {
  display: flex;
  flex-wrap: wrap;
  gap: 0.75rem 1.25rem;
  margin: 0.9rem 0 0.5rem;
}

.settings-field {
  display: flex;
  flex-direction: column;
  gap: 0.25rem;
  font-size: 0.85rem;
  color: var(--isd-muted);
}

.settings-field input,
.settings-field select {
  min-width: 11rem;
  padding: 0.4rem 0.55rem;
  border: 1px solid var(--isd-border);
  border-radius: var(--isd-radius);
  font-family: var(--font-mono);
  font-size: 0.9rem;
  background: var(--isd-surface);
  color: inherit;
}

.settings-actions {
  margin-top: 0.85rem;
  display: flex;
  gap: 0.5rem;
}

.settings-card--muted {
  border-style: dashed;
  opacity: 0.9;
}
