Admin service connections
Admin quota reads and changes, provider balance observations, cost imports and payment refunds now use the backend services. Billing includes open holds and top-ups and handles organizations without a partner offer. Refund approvals include their original reason and preserve replay protection after the ordinary request-cache window. Connection errors provide a retry action. Optional allocation and recovery controls are shown only when the deployment advertises their services.
Admin sign-in now uses a verified Supabase session and a fixed two-account allowlist, without a second Cloudflare Access login.
Admin lists follow continuation pages. Quota controls show only writable limits, refund amounts reflect currently available purchased funds, and provider withdrawal preserves concurrent state changes.