build(release): bump version to 0.1.6
Capability-scoped (publishable) API keys: per-collection/op rules, origin
allowlist, per-key rate limit (429), expiry, and optional CAPTCHA on gated
ops; scoped keys are data-only (no collection/project management). Backward
compatible.