- Added optional `source?` field with value `'login'` to `apiKeyCredentialSchema` so snapshots accept login-sourced API keys. - Updated CHANGELOG with a fixed entry describing the correction. - Added a test verifying that a snapshot containing `source: "login"` passes client wire validation.