/api/*.
Every operation requires either the navigator_session cookie from the
OAuth flow at /auth/login or a JWT bearer token.
The MCP endpoint (/mcp, JSON-RPC over HTTP with a Google OAuth bearer
token) is out of scope for this document; MCP clients should consult the
MCP specification.