All Known Implementing Classes:
ApiKeyAuth, BasicAuth, BearerAuth

public sealed interface AuthSpec permits BearerAuth, BasicAuth, ApiKeyAuth
Sealed root for an HTTP source's authentication shorthand.

Authentication can always be expressed by hand as a raw header (for example headers: { "Authorization": "Bearer ${TOKEN}" }); these shorthands exist so the common schemes read clearly and so the connector — not the script author — owns the encoding (base64 for basic, the Bearer prefix, the header-vs-query placement for an API key).

Surface syntax (consistent with the json(…)/query(…) style):

   auth: bearer("${TOKEN}")
   auth: basic("${USER}", "${PASS}")
   auth: apikey("X-API-Key", "${KEY}")        // sent as a header (default)
   auth: apikey(query("api_key"), "${KEY}")   // sent as a URL query parameter
 

All string payloads may contain ${ENV} placeholders, so a secret never appears literally in the source. They are resolved when a query runs.