116ca1db1e
The stampede fix added a `stale_access_token` hint to resolve_nous_runtime_credentials() so a process whose bearer just 401'd adopts a token a sibling already rotated instead of re-POSTing the shared grant — but only the credential-pool caller passed it. The main agent's 401 path (run_agent._try_refresh_nous_client_credentials), the auxiliary client rebuild, and the proxy adapter all called force_refresh=True with no hint, so `_already_rotated_by_peer` could never fire: N subagents hitting hourly expiry still issued N serialized refreshes, each one invalidating the token a sibling had just adopted. Live 12-process A/B against a fake Portal: 12 refresh POSTs / 9 distinct final tokens before, 1 POST / 1 token after.