Everything under
kerne.admin requires an admin caller (secret key, or a JWT owner crossing into their own tenant) - never call these from a request an end user initiated themselves.adjustUsage() - the one to reach for
Offsets the counter by a signed delta in one atomic increment - safe to call concurrently with consume()/reportUsage() without racing them, because it never reads the current value first.
check() never surfaces it as a negative number, it folds the credit into the displayed limit instead.
idempotencyKey is optional and exists for safe retries: pass a stable key (e.g. the id of the correction you’re applying) and a retried call with the same key won’t apply the adjustment twice.
setUsage() - only when you need an exact value
consume()/reportUsage() (read-then-write). Prefer adjustUsage() unless you specifically need to pin an exact number.
value and delta are both whole numbers, like every counter in Kerne - meter in the smallest unit you bill.

