messages array for conversation state. Text-only messages use a string content;
multimodal messages use content parts.
privacy.class to protected_provider_route or stronger.
See privacy classes for the full taxonomy and what each class enforces. The
legacy privacy.mode: "mesh" form is still accepted and maps to private_gateway_route.