# API routers. Route table stays minimal: the app defines ONLY
# /auth/login, /auth/callback, /auth/logout — never /login, /logout,
# /authorize, or /_grant at the root (those are id-auth's; PATTERN-B.md §1b).
