Gitea rejects a null password with a bare 400. These accounts are never password-authenticated — humans arrive via OIDC, agents via passport-bound scoped tokens, local password sign-in is disabled server-wide — so we generate a credential that is never stored, returned or recoverable. An unusable password is safer than a blank one or a shared default. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>