The retained comment still claimed a scope-less multiplex caller could load an OSS config; identity reads above it raise UnscopedSecretError first. Both the comment and the regression test now say the same thing: callers are scoped, an OSS profile whose scope lacks MEM0_API_KEY initializes, and a scope-less caller is a spawn-site bug that raises.