Replaceable wholesale — not just configurable
The three providers above are implementations of one small trait, and an embedder can inject any other: your own PKI and certificate chain, an HSM or smartcard, a corporate identity service, an accreditation-mandated enrolment protocol. The module sits beside the data path, not inside it — replacing it changes nothing about the Noise handshake, the scheduler or the wire format.
The point is jurisdictional as much as technical: operators run the authorization scheme they want, or the one their organisation and accreditation oblige them to run, rather than the one a vendor happened to ship. If your programme mandates a specific identity infrastructure, that is an integration, not a fork.