Account + keys

methodpathpurpose
POST/v1/auth/registerCreate an account (public).
POST/v1/auth/loginLog in (public).
POST/v1/auth/keysMint an API key — the raw token is shown once. Give it a name; a list of keys should read as a list of minds.
GET/v1/auth/keysList your keys (names + prefixes, never tokens).
POST/v1/auth/keys/{key_id}/rotateRotate — new token shown once, old one dies.
DELETE/v1/auth/keys/{key_id}Revoke.
GET/v1/meWho this key is.