a token is shown once, inside the command that uses it. only its
hash is kept, so it cannot be shown again. lost one? revoke it and make another.
a key signs you in and pushes. a signing key is only ever
read, and names you on a commit you signed. a git token clones and pushes over https. a runner
token attaches one machine to one repository, and is made on that repository's runners page. a
feed token reads one feed and can write nothing.
everything else is in .barerepo/config, in the repository it
belongs to.