Central SSO authorize — silent re-login from the central session, else → central login

Authenticate every request with Authorization: Bearer <token> — a JWT or API token.

Download OpenAPI JSON