Fixes the two collector-side root causes of #1601:
1. Claude per-profile credential reads were file-only, but on macOS Claude
Code stores the OAuth token for an isolated CLAUDE_CONFIG_DIR in a
per-directory Keychain item ("Claude Code-credentials-<sha256(dir)[0..8]>").
The .credentials.json file never exists, so every isolated profile was
parked with needsReauth:true forever. The reader now falls back to that
Keychain item (file-first, same security-CLI read the shipped global
fallback already performs; TTL-gated so it is not on every /summary).
2. Non-default profiles were cache-only forever, so they could never leave
the parked state even with valid credentials. getNativeAccountRows now
gives each surface ONE rotating live slot: the stalest eligible
non-default profile is refreshed per pass, skipping profiles inside
breaker/reauth cooldowns. Every account converges to real quota within a
few polls while the per-pass upstream budget stays constant (<= 2 calls
per surface regardless of profile count). Codex named profiles with valid
auth but sparse payloads now yield an active quota-less row instead of a
false needsReauth row.
Non-default rows keep paused:true (dimmed) even when freshly refreshed so
only the default renders active and rows do not flicker between polls.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>