3b9a963b8e
Rework of the #88049 inline early-return per review: - resolve_xai_http_credentials gains an opt-in prefer_api_key flag that checks the explicit XAI_API_KEY first and falls back to OAuth. The key is read through tools.tool_backend_helpers.resolve_provider_secret (config -> profile secret scope -> env/.env -> credential pool) so the preferred path enforces the same scope policy as the existing fallback branch, including failing closed under a multiplexed gateway turn. - The preferred path's base URL honors HERMES_XAI_BASE_URL then XAI_BASE_URL behind hermes_cli.auth._xai_validate_inference_base_url, mirroring the OAuth branch (a foreign origin can't exfiltrate the key). - x_search's _resolve_xai_bearer now calls the shared resolver with prefer_api_key=True instead of re-implementing precedence inline (#88040). - tools/tts_tool.py _generate_xai_tts converted to the same flag — same root cause for /v1/tts 403s (#87045, supersedes the inline shape in #87081 by @enwaiax). - Regression tests retargeted at the tools.xai_http.get_env_value seam and the shared resolver; added coverage for the flag's OAuth fallback, HERMES_XAI_BASE_URL + origin validation, default-order stability, and a profile-scope-only key on the preferred path. - Docs: x-search authentication section now states the explicit API key wins (metered billing implication).