Service scope, delivery models and party responsibilities.
Public endpoint with clear profile, limits and status.
API credentials or mTLS when the model requires it.
Private endpoint or dedicated TSU when actually supported.