A storage step on the runner's own connection needs it before the
execution starts. The gate now takes any requirement the server marks as
paid from the vault (vaultBacked), with the key prefixes as a fallback,
so the S3 or PostgreSQL connection shows up beside the LLM credentials.
Adding one opens a form with the storage type's own fields, from
/storage/types - endpoint, bucket, keys, or host, database, user - and
saves them together as the JSON the server encrypts whole.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>