Register the workload
api.mountthor.com.
Run mthr principal create with a credential that holds the principals:write
and issuers:write scopes; a customer-admin browser session has them. The
--scope values above are the scopes the workload’s own sessions receive, not
the scopes required to register it.
Exchange a token
SetOIDC_TOKEN from the CI provider and TENANT_ID from
mthr api request /v1/admin/account.