Expanded capabilities
- Authenticate JWT/cookie identity for protected `/api/v1` routes
- Register public vs protected routes deliberately
- Attach request traces for structured errors
- Reject unauthenticated access to tenant command surfaces
- Forward credentials safely from the web BFF patterns




