Replaces the scoped form's inline account-level access mode (blur overlay +
confirmation checkbox) with a proper legacy-token escape hatch, and tightens
expiry handling across both token forms.
- "Create legacy token" now switches the sheet to the classic form (name +
expiry only, with the classic account-wide warning) and creates the token
through the legacy endpoint; the two-step review is skipped. The link also
mentions the Supabase MCP server as a reason to need one.
- Restore the "Generate token for experimental API" split-button dropdown on
the scoped flow, extracted into a shared ExperimentalTokenDropdown used by
both the classic button and the scoped sheet.
- Cap custom expiry dates at one year from today: single shared
getMaxCustomExpiryDate() drives the scoped calendar bounds, zod validation,
and the classic dialog's maxDate. Calendars no longer page past the last
selectable month (scoped Calendar via startMonth/endMonth; shared DatePicker
derives them from minDate/maxDate).
- Add an MCP-unsupported warning to the review step (with a link back into
legacy mode) and the view-token sheet, sharing one set of copy constants.
- Copy: resource access card descriptions, "can't be updated after creation"
admonition, and inline links now use InlineLinkClassName.